> ## Documentation Index
> Fetch the complete documentation index at: https://onecli.sh/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Docker Hub Integration: Repositories & Images for Agents

> Agents can list and manage Docker Hub repositories, tags, and organizations. Connect with your username and a personal access token.

## Overview

OneCLI connects AI agents to [Docker Hub](https://hub.docker.com) with your username and a personal access token. Agents can browse and manage repositories, tags, and organizations. The gateway injects the credentials into every request, so your agent never sees them.

Connecting takes about a minute.

<a id="self-hosted" style={{ scrollMarginTop: "8rem" }} />

## Connect Docker Hub

<Steps>
  <Step title="Create a personal access token in Docker">
    Open [app.docker.com](https://app.docker.com), then **Account settings** > **Personal access tokens**, and click **Generate new token**. Name it `OneCLI`, choose the **access permissions** (Read-only, or Read & Write if agents should change repositories), and copy the token right away. Tokens start with `dckr_pat_`.
  </Step>

  <Step title="Enter it in OneCLI">
    In the OneCLI dashboard, open **Connections** > **Docker Hub**, enter your **Username** and the **Personal Access Token**, and click **Connect Docker Hub**.

    <Frame caption="The Docker Hub connect window in OneCLI.">
      <img src="https://mintcdn.com/chartdbinc/L4k9tYUENUtEpMY8/images/integrations/docker/onecli-connect-docker.png?fit=max&auto=format&n=L4k9tYUENUtEpMY8&q=85&s=f2169e73a1c1be542372964ef4c873a3" alt="OneCLI connect window for Docker Hub, showing the setup guide link, the Username and Personal Access Token fields, and the Connect Docker Hub button." width="1056" height="1452" data-path="images/integrations/docker/onecli-connect-docker.png" />
    </Frame>

    OneCLI signs in to Docker Hub when you connect and rejects wrong credentials right away.
  </Step>
</Steps>

## What agents can do

| Area | What agents can do |
| - | - |
| **Repositories** | List and read repositories. Create, update, and delete repositories |
| **Tags** | List tags and delete a tag |
| **Account** | Read your user, namespaces, and organizations |

## Controlling access

[Grant](/docs/guides/agent-access) the connection to each agent that needs it, and choose per tool what runs freely, what needs approval, and what's blocked. **Delete repository** and **Delete tag** can't be undone, so put them behind approval. Organization [rules](/docs/guides/rules) add guardrails on top. A blocked request never reaches Docker Hub.

To disconnect, remove the connection in **Connections** > **Docker Hub**, then delete the token in Docker under **Personal access tokens**.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.