Authenticating as a federated user
You can use a federated account to work with Nebius AI if your company has an identity federation set up.
Note
To authenticate on a server with no GUI, you need to install a browser with X11 forwarding set up
If you cannot install a browser, use a service account instead of a federated account.
If you do not have the Nebius AI command line interface, install it.
To authenticate using a SAML-compatible identity federation:
-
Get your federation ID from your administrator.
-
Launch the profile creation wizard:
ncp init \ --endpoint api.ai.nebius.cloud:443 \ --federation-endpoint console.nebius.ai \ --federation-id <federation ID>
-
Select the profile you want to set up authentication for or create a new one.
Welcome! This command will take you through the configuration process. Pick desired action: [1] Re-initialize this profile 'default' with new settings [2] Create a new profile
-
The CLI prompts you to continue authentication in the browser. Press Enter to continue.
You are going to be authenticated via federation-id 'aje1f0hsgds3a********'. Your federation authentication web site will be opened. After your successful authentication, you will be redirected to 'https://console.nebius.ai'. Press 'enter' to continue...
On successful authentication, the IAM token is saved in the profile. This token is used to authenticate each operation until the token expires. After that, the CLI again displays a prompt to authenticate in the browser.
-
Go back to the command line interface to finish creating the profile.
-
View your CLI profile settings:
ncp config list
Result:
endpoint: api.ai.nebius.cloud:443 federation-id: aje1f0hs6oja******** ...