Connections

Connect both clouds in minutes.

CloudOptify connects to Azure and AWS with read-only access, verifies every connection before saving it, and starts analyzing automatically. No agents to install, nothing deployed into your environment.

Microsoft Azure

Connect one or more Azure tenants through a standard Microsoft consent flow that grants read-only access to cost data and resource metadata. Verify with one click, then choose exactly which subscriptions CloudOptify analyzes.

AuthenticationMicrosoft Entra app consent — secrets held server-side, encrypted at rest
Access levelRead-only: billing & cost data, resource metadata, utilization metrics
Scope controlPer-subscription selection — analyze only what you choose
Multi-tenantConnect multiple tenants and filter across them with the global filter

Amazon Web Services

Connect AWS with read-only access and discover the accounts in your AWS Organization automatically. Two authentication methods are supported — including a keyless option where no long-lived secret exists at all.

IAM Role RecommendedA cross-account role you create and control, protected by a unique External ID. No secret is ever stored — access is short-lived credentials, revoked instantly by deleting the role.
Access keysRead-only IAM user keys, AES-256 encrypted at rest and never shown again after saving
Access levelRead-only: Cost Explorer, resource metadata, CloudWatch utilization
OrganizationsMember accounts discovered automatically — pick the ones to analyze
Optional · go deeper

Connect a billing export for the accurate cost backbone.

The connections above work from day one on the live cost APIs. For teams that want billing-invoice accuracy, deeper history, and no rate limits, CloudOptify can also read directly from a billing export delivered to storage you own — AWS Cost & Usage Reports (CUR) in S3, or an Azure Cost Management exportin a storage account.

AWS Cost & Usage Report

Deliver a CUR (Data Export) to an S3 bucket you own; the same read-only role you already granted gets one additional permission to read it.

DeliveryYour own S3 bucket — CloudOptify never hosts or copies your billing data
HistoryAWS backfills up to ~12 months automatically; CloudOptify pulls all of it on first connect
GranularityExact, per-resource, per-region cost across every linked account — with tags
UnlocksReal Cost Explorer drill-down, tag-based allocation, Cost by Region, Top Resources, AWS usage types

Azure Cost Management Export

Deliver a scheduled export to a storage account you own; CloudOptify can even create the export and back-fill history for you, using the connection you already verified.

DeliveryYour own Azure Storage account — a container CloudOptify only ever reads
HistoryCloudOptify provisions up to 12 months of one-time historical export runs automatically
GranularityExact, per-resource, per-region cost across every subscription — with tags
UnlocksReal Cost Explorer drill-down, tag-based allocation, Cost by Region, Top Resources

Fully optional — every connection above already works without it. Step-by-step setup for both live in the documentation:AWS CUR setup · Azure Cost Export setup

Every connection, the same rules.

Read-only by default

Every connection method grants read access only, and CloudOptify never touches your workload resources. The single exception is one you opt into: automatic setup of a billing export, created only when you explicitly ask for it.

Verified before saved

Every connection is tested end-to-end against your cloud before it is persisted — a misconfiguration fails immediately with a clear message.

Revocable instantly

Remove consent, delete the role, or revoke the key on your side and access ends immediately. You stay in control.

Discovery built in

New subscriptions and accounts that appear in your cloud are discovered automatically on every sync — nothing drifts out of view.

Connected in minutes, insight on the first scan.

Step-by-step setup guides for both clouds live in thedocumentation.