1. NGC User Guide#

This document is a comprehensive guide to NVIDIA GPU Cloud (NGC), providing detailed instructions on setting up, managing, and optimizing your cloud environment, including creating accounts, managing users, accessing pre-trained models, and leveraging NGC’s suite of AI and HPC tools.

1.1. What is NVIDIA NGC?#

NVIDIA NGC™ is a cloud platform providing fully managed services, including NVIDIA AI Enterprise, NVIDIA DGX™ Cloud, and NVIDIA Riva Studio for Natural Language Understanding (NLU) and speech AI solutions. AI practitioners can leverage DGX Cloud for model training, NVIDIA AI Enterprise to obtain the latest NVIDIA NIM™ models, and the NGC Private Registry for securely sharing proprietary AI software. NGC also hosts a catalog of GPU-optimized AI software, SDKs, and Jupyter Notebooks to accelerate AI workflows and offers support through NVIDIA AI Enterprise.

Enterprises access their AI cloud services through a dedicated virtual NVIDIA Cloud Account (NCA) linked to the NGC organization where their services are enabled.

1.2. Why NGC Software#

NGC provides software to meet the needs of data scientists, developers, and researchers across various levels of AI expertise.

All software hosted on NGC undergoes thorough scans for common vulnerabilities and exposures (CVEs), crypto, and private keys.

In addition to security scanning, NGC software is tested against a wide range of GPU-enabled platforms. These platforms include public cloud instances, workstations, and OEM servers designed for data center or edge deployments. Supported GPUs include H100, V100, A100, T4, Jetson, and the RTX Quadro.

NGC software is tested and assured to scale across multiple GPUs and, in some cases, across multiple nodes, ensuring users can fully utilize their GPU-powered servers out of the box.

For select containers, NVIDIA offers NGC Support Services to run software on DGX platforms or certified OEM servers. The service gives enterprise IT direct access to NVIDIA subject matter experts to address software issues and quickly minimize system downtime.

1.3. NGC Organizations and Teams#

An NGC organization (org) is where administrators manage users, teams, and access to NGC services. Each NGC org maps one-to-one to a linked NVIDIA Cloud Account (NCA) membership record, and both share the same account number.

Users can access an NGC org in the following ways:

  1. Sign-Up through the NGC Portal: A user can sign up for a free NGC org through the NGC sign-in portal. NGC creates the linked membership record and enables the org with NGC Catalog access (public artifacts only).

  2. Entitlement Certificate Email: NVIDIA grants entitlement to a service delivered in NGC through a purchase order, early trial program, or other commercial offer. NVIDIA then sends an entitlement certificate email, which includes a certificate PDF, to the entitled company or person. The recipient opens the PDF and follows the link in it to begin the entitlement registration flow and activate the service in the NGC org.

  3. NGC Org Invitation: An NGC org owner or user admin invites users from the NGC Org Users page and assigns their NGC roles and service access. If the org is linked to an external identity provider (IdP), the owner or user admin can instead manage membership through IdP membership rules mapped to the NGC org. Only enterprise orgs support additional NGC users.

Users who sign up through the NGC sign-in portal receive an individual NGC org that is automatically enabled with NGC Catalog access. An individual org supports a single org owner. Use an enterprise NGC org to add users and assign NGC access.

NVIDIA grants a premium cloud service subscription, such as NVIDIA AI Enterprise or NVIDIA DGX Cloud, through a purchase, an early access program, or the NGC Activate Subscription portal. NVIDIA enables subscriptions on enterprise NGC orgs. An enterprise org supports additional users, NGC teams, and role-based access rules.

1.3.1. NVIDIA Cloud Accounts and NGC#

NVIDIA Cloud Accounts (NCA) provide the membership service that an NGC org checks against. Each NGC org maps one-to-one to an NCA membership record, but NCA does not grant NGC roles or service access.

The following diagram shows how NCA, NGC orgs, and teams relate.

NGC Organizations and Teams

Use the NGC Org user-management experience to add users, assign roles, promote, demote, and remove users. NGC automatically updates the linked membership record.

The following screenshot shows the NGC Add User pane.

NGC Add User Step 1

You also assign NGC roles and service access from the NGC Org UI, including access to services such as NVIDIA AI Enterprise and NVIDIA DGX Cloud.

Use NCA only for account-level tasks that are separate from NGC user management, such as:

  • Setting up an account recovery email (recommended)

  • Managing billing

  • Entering company information

  • Configuring IdP federation when required

Removing a user from an NGC org revokes all of that user’s NGC roles and service access. The user remains a member of the linked NCA but can no longer access NGC services through that org.

Important

Do not use the NCA UI to add, remove, promote, or demote users for NGC. NCA cannot grant NGC roles or service access, so changes that you make in NCA do not grant NGC access.

For NGC user management, use the NGC Org UI.

1.3.2. NGC Teams#

NGC organizations (orgs) serve as the top-level container for enterprise deployments. Within an org, administrators can create teams to implement role-based access control and segment private registry resources by department or project.

Teams provide isolated registry namespaces, ensuring members can share containers, models, and resources within their team while maintaining separation from other teams in the organization.

The following roles control who can manage users:

  • Org owners and org-level user admins: Create teams and manage users across all teams

  • Team-level user admins: Manage users within their assigned team only

Note

NVIDIA does not provide user management services; customers are responsible for all user provisioning

To create an NGC team, follow these steps:

  1. Log in to your NGC org.

  2. Select Organization from the user account menu.

    NGC User Account Menu Organization
  3. On the dashboard or in the left navigation, select Teams.

    NGC Organization Teams Menu
  4. On the Teams page, click Create Team on the upper right corner.

    New NGC Create Team
  5. Enter a team name and description. Note that names must be all lowercase.

  6. Click Create Team to finish.

1.3.3. NGC Org Owner and Other Org Users#

When an NGC org is created, NGC creates a linked NCA membership record. The initial org owner manages users, roles, and NGC service access from the NGC Org UI.

An individual org is accessible only by the org owner. Additional users are not supported. To verify the type of org you manage, sign in to NGC. Under the user account menu, select Organization, then select Organization Profile under Identity & Access in the left navigation.

Organization Type Enterprise

The org owner has the highest administrative privileges in an NGC org. In an enterprise org, the owner can use the NGC Org UI to add and remove teams and users, and to assign NGC roles. The owner assigns the organization-level or team-level access that each user needs.

An org supports up to three org owners. Only an org owner can add or invite additional org owners. All org owners must share the same email domain.

For example, if the users’ email addresses are john@intelligence.ai, jane@intelligence.ai, and peter@intelligence.ai, then all three can be added as org owners because their email address domains match. In contrast, if Peter’s email address were peter@artificial.ai, Peter could not be added as an org owner.

Follow the steps in the next section to add a new org owner or additional users with different access permissions.

1.3.3.1. Adding NGC Users to an Org#

Only NGC org owners and user admins can perform user management operations. NVIDIA cannot manage users on behalf of a customer.

To add a new org owner or a user with different access permissions, complete the following steps.

  1. Sign in to NGC. Select the NCA account linked to the NGC org that you want to manage, and click Continue.

    Sign In NCA Resized
  2. Select Organization from the user account menu.

    NGC User Account Menu Organization

    On the dashboard or in the left navigation, select Users from the Identity & Access menu.

    Organization Users Navigation
  3. Click Invite New User in the top-right corner.

    Important

    If your org is linked to an external identity provider (IdP) or single sign-on (SSO) service, NVIDIA recommends that you manage user membership with NGC IdP Membership Rules. If your IdP does not support groups, use the NGC add user service.

    NGC Users Invite
  4. In the User Invitation section, do the following:

    • Enter the user email address, making sure that the domain matches your email domain.

    • Customize the invitation email to explain the purpose of the invitation (optional).

    • Set an expiration for the invitation link (default: 24 hours).

    • Click Next: Assign Roles.

    NGC Invite New User Email
  5. On the Assign Roles step, assign roles based on the type of user that you are adding.

    1. Adding an Org Owner

      To make the user an org owner:

      • Select Organization Owner from the Roles list. Since this is an organization-level role, you do not need to choose a scope.

      • Click Add Role to finish.

        Organization User Update Step 2
    2. Adding Other Users

      To assign controlled permissions to a user:

      • Roles without the Default scope allow a Custom Scope, so you can choose either Organization or one or more Teams to customize access.

      • Assign a role for each NGC application, depending on the level of access that you want to grant the user.

      • Click Add Role to assign each role.

        Organization User Update Step 2 Controlled Permissions

      In this example, the user has the User role for NGC Private Registry. This role limits the user to viewing and pulling artifacts from the NGC Catalog, and to pushing and pulling artifacts in the org’s private registry.

      To learn more about NGC product roles, refer to the documentation for each product.

      Note

      The Public API Endpoints User role controls access to NVIDIA API Catalog NIM endpoints. Assign this role to NGC org users who need to generate an NGC Personal Key for the API Catalog. For more information, refer to Assigning Services to Your Personal API Key. To update user roles, refer to Updating User Roles.

    3. Assigning Team Roles

      Assigning permissions at the Team level grants the user access only to the resources, such as containers and models, that are shared with that specific team. To grant a user access to resources across the entire org, assign roles at the Organization level.

  6. The user receives an NCA invitation email and accepts the invitation to access the NGC org.

After all three org owner slots are filled, any org owner can replace another org owner when needed. To remove an org owner, go to the Users list and select Remove User.

NGC Remove User

When an org owner is removed, NGC sends an email notification to the remaining active owners. To invite a replacement owner, use the same steps described earlier.

1.3.3.2. Updating User Roles#

A user’s roles determine which NGC services and resources the user can access. Assign and remove roles in the NGC Org UI, because the NCA UI cannot grant NGC roles or service access.

To update a user’s roles, complete the following steps.

  1. Sign in to NGC. Select the NCA account linked to the NGC org that you want to manage, and click Continue.

    NVIDIA Cloud Account and team selection dialog with the Continue button
  2. Select Organization from the user account menu.

    Organization option in the NGC user account menu

    On the dashboard or in the left navigation, select Users from the Identity & Access menu.

    Users option in the Identity and Access navigation and on the Organization dashboard
  3. To locate the user, click Filter, select User, enter the email address or name, and then click Apply Filter.

    Open Filter control on the organization Users page with the Apply Filter button
  4. Click the user that you want to modify. On the Roles tab, click Edit Role Assignments.

    Edit Role Assignments button on the Roles tab of a user page
  5. Under Choose Roles, select the role to add to the user, and then click Assign. A confirmation message appears.

    Edit Role Assignments page with a role selected under Choose Roles and the Assign button
  6. To remove a role, click the X on the assigned role, or select the role under Choose Roles and click Remove.

    Edit Role Assignments page with the X on an assigned role and the Remove button

    A confirmation dialog appears.

1.3.3.3. Removing a User from an NGC Org#

Only an org owner or an organization-level user admin can remove a user from the org.

To remove a user from an NGC org, complete the following steps.

  1. Select Organization from the user account menu.

    NGC User Account Menu Organization

    On the dashboard or in the left navigation, select Users from the Identity & Access menu.

    Organization Users Navigation
  2. Use the filtering bar to find the email address of the user that you want to remove.

    NGC Organization User Filter
  3. Click the Actions ellipsis and select Remove User.

    NGC Organization User Remove

Removing a user from an NGC org revokes all of that user’s NGC roles and service access in that org. The user remains a member of the linked NCA, where user tenancy is managed. Remove NGC users in the NGC Org UI, because the NCA UI cannot grant or revoke NGC roles or service access.

1.3.3.4. Securing the Owner Account with Multi-Factor Authentication#

When you create your owner account, you receive an NVIDIA identity account that is protected by a password you set at the time of owner account creation. You can further secure access to your owner account by setting up multi-factor authentication using the directions below:

  1. Go to NVIDIA and click the sign-in icon.

    Secure Organization Owner NVIDIA Account
  2. Sign in with the credentials you set up during the org owner account setup.

  3. From your NVIDIA user profile page, navigate to the bottom, click Security settings, then Update.

    Secure Organization Owner Security Update
  4. You will be prompted to enter your password again to access security settings.

  5. Navigate to the Multi-factor Security settings.

    Secure Organization Owner Multi-Factor
  6. You can now configure your identity account for two-factor authentication. Go to the NVIDIA N-factor help page for details on how to set it up.

1.3.3.5. Contacting your Org Owner#

If you need to contact the organization owner to request a new service subscription or add a new user, use the Contact Admin option in your user account menu.

  1. Sign in to the NGC application with your organization, then click your user ID in the top-right corner to access the user account menu.

    NGC Organization Owner Contact Admin
  2. Select Contact Admin to open the email editor dialog.

    NGC Organization Owner Contact Templates

    Within this editor, you can choose from the following email templates:

    • Product Request: Use this template when requesting a specific product for your <org-name> organization. For example, “I’d like to request the [product name] product for the <org-name> organization.”

    • Team Access Request: Select this template if you need to request access to the org or a particular team, such as “[team-name],” within your <org-name> organization.

    Both templates come with pre-populated message content, but you can edit or delete portions of the message to create a customized message to send to your organization owner.

    NGC Organization Owner Contact Admin Dialog
  3. When you are ready to send the message, click Send.

    The organization owner will receive an email from noreply-ngc@nvidia.com that will include your email address. The following is a sample email message:

    NGC Organization Owner Contact Email

    By following these steps and using the Contact Admin option, you can easily initiate communication with your organization owner.

1.3.3.6. External User Groups#

As an NGC organization owner or administrator, if you need to share NGC resources with users outside your organization, use External User Groups. Adding external users as regular account members can grant broader account access than intended. External User Groups grant permissions to a group instead of adding those users directly to your NGC organization.

The External User Groups page has tabs for Managed External User Groups, Delegated External User Groups, and API Keys. Use Managed External User Groups when your NGC organization creates and manages group membership. Use Delegated External User Groups when an external company administrator manages membership and your NGC organization controls the permissions.

Create Managed External User Group

External User Groups are supported for NGC applications such as Private Registry and Catalog. An organization can have up to 500 external user groups, and each group can include up to 1,000 users.

For managing access in your organization, NGC recommends the following approach:

  • For your company’s internal users: Add them as account members through the Users management page or use your enterprise IdP to grant access with IdP groups.

  • For external users with email domains outside your company or IdP: Use External User Groups.

1.3.3.6.1. Managed External User Groups (mEUG)#

A Managed External User Group (mEUG) is created, owned, and managed by an NGC organization owner or authorized user administrator. Use a managed group when your NGC organization needs direct visibility into the group membership and wants to add or remove external users itself.

Managed external user groups are designed for secure collaboration with external users while keeping their tenancy separate from the main NGC organization. External users receive only the permissions granted to the group and do not receive the broader access that internal account members can have.

NGC organization owners and user administrators are not automatically granted management access to a managed external user group. To manage the group’s members, an owner or administrator must be explicitly added to the group by the group owner.

1.3.3.6.1.1. Creating a Managed External User Group#
  1. Sign in to NGC and open the NGC organization you want to manage.

  2. From the user account menu, select Organization.

    User Account Menu
  3. In the left navigation or on the main panel, select External User Groups.

    Create Managed External User Group
  4. On the Managed External User Groups tab, click Create Group.

  5. Enter the group name and description.

    Create Managed External User Group
  6. Create the group, then assign permissions for the NGC resources the external users should access.

1.3.3.6.1.2. Inviting Users to a Managed External User Group#
  1. Open the Managed External User Groups tab.

  2. Select the managed external user group you want to update.

  3. Invite the external users who should join the group.

  4. Assign the appropriate group role to each user you invite to the group.

  5. Ask invited users to check their inbox for the invitation email. If they do not see the invitation within a few minutes, ask them to check their junk or spam folder.

1.3.3.6.1.3. Managing Managed External User Group Permissions and Membership#
  1. From the Managed External User Groups tab, open the group you want to manage.

  2. Add or remove group permissions to control which NGC resources the group can access.

  3. Add or remove group members as external collaboration changes.

  4. Review access regularly to make sure group permissions still match the intended collaboration.

1.3.3.6.1.4. Guide for External Users: Accepting a Managed External User Group Invitation#
  1. Open the invitation email from NVIDIA NGC.

  2. Click Accept Invitation.

  3. Sign in with an existing NVIDIA account or create an account if prompted.

  4. After accepting the invitation, sign in to NGC to access the resources shared with the managed external user group.

1.3.3.6.1.5. API Access for Managed External User Group Users#

To access shared NGC resources programmatically, a managed external user must generate a Personal API Key in their NGC account.

The permissions on the key are derived from the managed external user group’s access grants. External users cannot expand these permissions themselves.

Depending on the permissions granted to the group, the key can allow viewing and listing shared artifacts, pulling artifacts, or pushing artifacts.

1.3.3.6.2. Delegated External User Groups (dEUG)#

A Delegated External User Group (dEUG) allows an NGC organization owner or administrator to grant an external company access to specific NGC resources without adding those users directly to the NGC organization. The NGC organization controls which resources the group can access, while the external company’s administrator manages the group membership.

Delegated external user groups support three personas:

  • NGC organization owner or administrator: Initiates the delegation, assigns access permissions, and monitors or manages the delegated group.

  • External dEUG administrator: Accepts the invitation, creates the delegated group, and manages membership in the NVIDIA UCS Team portal.

  • External group user: Accepts membership in the delegated group as a member, administrator, or operator and can access the shared NGC resources assigned to the group.

1.3.3.6.2.1. Persona 1: NGC Organization Owner or Administrator#

The NGC organization owner or user administrator initiates the delegated EUG invitation, assigns access permissions, and monitors or manages the delegated group.

1.3.3.6.2.2. Initiating a Delegated EUG Invitation#
  1. Navigate to the Delegated External User Groups tab in your NGC organization settings.

    Initiate Delegated EUG Invitation
  2. Enter the email address of the individual who will create and manage the external user group.

    Create Delegated EUG Invitation
  3. Assign the permissions for the group. All users added to the group by the external group administrator inherit the access level you define here. You can set permissions at the organization level or at the NGC team level.

    Assign Delegated EUG Permissions

    Only subscriptions that support external group sharing are available for selection. Subscriptions that do not support external sharing appear disabled with a tooltip explaining why they are unavailable.

  4. Review the invitation settings, including the email subject line and message preview, then confirm to send the invitation and assign access.

    Review Delegated EUG Invitation
  5. If the invitee reports not receiving the email, ask them to check their junk or spam folder.

1.3.3.6.2.3. Tracking and Monitoring Delegated EUGs#

After the invitation is sent, it appears in the Delegated External User Groups list with a Pending status. The invitation can be tracked or revoked from this view.

Delegated EUG List

After the external administrator accepts the invitation and creates the group, its status changes to Accepted. You can open the group details to view the group administrator name, group name, and group ID. Member lists are not visible to the NGC organization owner or administrator.

1.3.3.6.2.4. Advanced Security and Management for Delegated EUGs#

To suspend access for an existing delegated EUG, suspend role permissions in the NGC UI. A confirmation prompt helps prevent accidental changes.

After suspension, all members and administrators of the group lose access to the NGC organization’s shared resources within a maximum of 30 minutes.

You can restore access by updating the group’s roles.

To revoke access associated with an external user’s Personal API Key, navigate to External User’s Personal Keys in the NGC UI. Search by personal key ID or key value, then deactivate.

1.3.3.6.2.5. Persona 2: External dEUG Administrator#

The external dEUG administrator receives the invitation from the NGC organization, creates the delegated group, and manages all user membership within it.

1.3.3.6.2.6. Accepting the Invitation and Creating the Group#
  1. Check your inbox for an invitation email from NVIDIA NGC. If you do not see it, check your junk or spam folder.

  2. Click the link in the email to open the invitation.

    Accept Delegated EUG Invitation
  3. Complete account setup if prompted, including password creation or terms acceptance.

  4. Click Accept Invitation to create the delegated external user group.

  5. To access NGC resources, go back to your email message and click Log In To NGC Org after accepting and creating the group.

From the NGC org UI, you can navigate back to your external user group to manage additional users.

Manage External User Group Profile Menu
1.3.3.6.2.7. Managing Delegated Group Membership#

As the group administrator, you control all user membership within your delegated EUG in the NVIDIA UCS Team portal. The NGC organization owner manages the access permissions granted to the group.

Manage Delegated Group Membership

Note

Roles are assigned at the invitation level. All users included in a single invitation batch receive the same role. To assign different roles, send separate invitations for each role group.

  • Admin is the highest-privilege role and can add or remove Admins, Members, and Operators.

  • Operator can add and remove Members only. Operators cannot manage other Operators or Admins, modify the group name or description, delete the group, change their own role, or change group assignments.

  • Member can access shared resources but does not have user-management privileges.

Users invited with the Member role are redirected to NVIDIA NGC and can begin accessing the shared NGC resources after accepting the invitation.

Users invited with the Admin or Operator role are redirected to NVIDIA NGC after accepting the group invitation. To manage group users, they should open the NGC organization application and then use the NVIDIA UCS Team link to access External User Groups in the UCS Team portal.

1.3.3.6.2.8. Monitoring and Resending Invitations#
  1. Use the Pending Invitations tab to track invitations that have not yet been accepted.

  2. After a user accepts an invitation, they move to the Confirmed Users tab.

  3. You can resend expired invitations. Resent invitations keep the same validity period as the original invitation.

1.3.3.6.2.9. Persona 3: External Group User#

External group users receive an invitation to join an existing delegated EUG and access the NGC resources shared with that group.

1.3.3.6.2.10. Accepting the Group Membership Invitation#
  1. Check your inbox for the invitation email. If you do not see it, check your junk or spam folder.

  2. Click Accept Invitation in the email.

  3. If you were assigned the Member role, you are redirected to the NGC sign-in page to access your assigned resources.

  4. If you were assigned the Admin or Operator role, you are directed to NGC to access your assigned resources. From the NGC organization application, you can access the UCS Team portal to manage users in the delegated external user group.

1.3.3.6.2.11. API Access for Delegated External User Group Users#

To access shared NGC resources programmatically, generate a Personal API Key in your NGC account.

  1. Navigate the NGC UI to discover the artifacts shared with your group.

  2. Go to your NGC account settings and generate a Personal API Key.

The permissions on the key are derived from the delegated external user group’s access grants. These permissions are set by the NGC organization owner and cannot be edited by the external user.

Depending on the permissions granted to the group, the key can allow viewing and listing shared artifacts, pulling artifacts, or pushing artifacts.

1.3.3.6.3. Managing External Users’ Personal API Keys#

The API Keys tab under External User Groups lets an NGC organization owner or administrator review and manage Personal API Keys that external users generate for access to shared resources.

External User Groups API Keys Tab

Use this tab when you need to revoke or restore API-key access for an external user without changing the whole group membership.

  1. Search for the key by entering the personal key ID or key value.

  2. If the key is active and has permissions to the shared organization, deactivate it to revoke current permissions to the shared assets.

  3. If the key is deactivated, reactivate it only when access should be restored.

  4. If the key has no permissions to your shared resources, the system confirms that no action is available.

Refer to the NGC API keys documentation for general API key information.

1.3.3.6.4. Setting Up API Access#

To access shared organization resources through CLI or API, you’ll need to generate a personal key:

  1. On the API Keys page, click Generate Personal Key.

    Important

    If the Generate Personal Key button is inactive, follow these steps:

    1. Create an NVIDIA Cloud Account (NCA) where you are an active member.

    2. Create and activate an NGC organization in that account. This organization will authorize your personal key for the shared organization where you are an external user.

    3. Return to generate your key.

    To create your NCA and NGC organization:

    1. Click Create NVIDIA NGC Org and authenticate with your NVIDIA Cloud Account credentials.

      External User Group Setup API Key NGC Organization
    2. Enter a name for your NCA and click Create NVIDIA Cloud Account.

      Create NCA Dialog
    3. Click Continue to return to the NGC Personal Key management page.

  2. Configure your personal key:

    1. Key Name: Enter a descriptive name that identifies the key’s purpose.

    2. Expiration: Choose a preset period, set a custom date, or select “never expire”.

    3. Services Included: Select the services this key will access.

    4. User Organization: Select an NGC organization you belong to (required for key authorization).

    Generate Personal Key

    Click Generate Personal Key.

    Warning

    Copy and store your key immediately; it will only be shown once.

    For additional information:

1.3.4. Transferring Your Product Activation Invitation#

When you receive an NGC product activation email and want to activate the product in an account you don’t own, you must transfer the product activation invitation to the account owner. Follow the steps below to transfer.

Note

The account selector supports activation invitation transfers only for invitations received directly from NGC. For “NVIDIA entitlement certificate” activations, contact your org owner.

  1. To transfer a product, at the Activate Product page, click View All NVIDIA Cloud Accounts. This displays accounts you are a member of but do not own; those without the ‘owner’ tag are not owned by you. Review carefully to identify the account associated with the desired NGC organization before starting the transfer process.

    NGC Activate Product Step 2
  2. Click the Transfer Product Activation link under the Actions column.

  3. Review the pop-up indicating that the transfer cannot be undone and confirm that you are certain about proceeding with the transfer.

    NGC Transfer Product Activation Confirm
  4. Check the default email template for accuracy, then click Transfer Product Activation. Editing is optional if the content is correct.

    NGC Transfer Product Activation Email Template

1.4. Accessing NGC Org#

Activating an NVIDIA NGC product depends on how you obtained the product activation message. This chapter provides comprehensive instructions for activating your NGC product, regardless of whether you received an NGC email invitation from NGC (noreply-ngc@nvidia.com), an NVIDIA commercial entitlement certificate (noreply@nvidia.com), or you registered for a free individual NGC organization. It outlines the steps to create and link your NVIDIA Identity account and NVIDIA Cloud Account to your NGC organization, and details the activation process required to access NGC products.

1.4.1. Activating Your NGC Product from an NGC Email Invitation#

Customers can try upcoming NVIDIA NGC AI products through NVIDIA Developer or by engaging directly with the NVIDIA product team. After approval, you will receive a welcome email from NVIDIA NGC, similar to the image shown below, guiding you on how to begin your onboarding process and activate the software. To access NGC, you need to be a tenant of an NVIDIA Cloud Account used to manage access to NGC for you and additional users. The following sections explain how to use your NVIDIA NGC welcome email.

NGC Early Access Welcome Email

If you’re already an NVIDIA NGC user, go directly to NGC Product Activation by Invitation - Existing User.

1.4.1.1. NGC Product Activation by Invitation - New User#

This section describes the steps necessary to activate a new NGC product as a new user on NVIDIA NGC.

  1. Go to your inbox to find the email “Welcome to NVIDIA NGC”. Click the Accept invitation and sign-in button.

    NGC Early Access Welcome Email
  2. To create your NVIDIA sign-in identity account, type in a password and confirm it (must meet the complexity check), review the NVIDIA account Terms of Use and Privacy Policy, and click Create Account to accept and proceed with your identity account creation.

    NGC Create Account New
  3. A verification email is sent to your email address.

    NGC Verify Email Code
  4. Open the email, copy the code, paste it in the Verify Your Email screen, and click Continue.

    NGC Verification Code Email NGC Verification Code Enter

    An additional browser page can open to validate the creation of your user account. Close this page and return to the browser page you started on.

  5. In the Almost done! dialog, select your communication preferences, and then click Submit.

    NGC Almost Done New
  6. You must now complete the creation of your new NVIDIA Cloud Account. Provide a meaningful name (spaces are not allowed) that helps you identify it easily against other accounts you own or are a member of.

    Note

    Creating a new NCA will generate a new NGC org where your product will be activated. The NGC org is directly linked to this NCA.

    NGC Create NCA Test
  7. You’ve now activated your NGC product, and you will be redirected to the NGC org subscription page where you can verify your product is active.

    NGC Organization Subscriptions Activate

That’s it! You’re all set up with your product.

Optional: You should have received a welcome email from your NVIDIA Cloud account. You can choose to complete the setup of your account now or at a later time.

Complete the steps in Setting up your NCA Account to configure your NCA account. The users you add to your NGC org are automatically added to the NCA account. To remove users or update NCA-related tenancy settings for a user, you need to take these actions in NCA.

Note

You cannot access NGC and NGC permissions cannot be assigned in NCA. NCA only manages user tenancy membership. To add users and assign NGC permissions, perform these actions in Adding NGC Users to an Org.

1.4.1.2. NGC Product Activation by Invitation - Existing User#

This section describes the steps to activate a new NGC product invitation when you already have an NVIDIA NGC organization.

  1. Go to your inbox to find the email “Welcome to NVIDIA NGC”. Click the Accept invitation and sign-in button.

    NGC Early Access Welcome Email
  2. Sign in to your NVIDIA identity account.

    NGC Login JDOE NGC Login NVIDIA Account JDOE
  3. Review the product details you want to activate on the Activate Product page, select the account under which the product should be activated, and click Activate Product. By default, only the accounts eligible to activate the product are displayed. Alternatively, you can activate the new product under a new account and NGC organization by clicking Activate with a new NVIDIA Cloud Account.

    NGC Activate Product Step 2 Existing User

    Note

    If you want to activate the product in an account you do not own, transfer the product activation invitation to the owner. Refer to Transferring Your Product Activation Invitation for the transfer steps.

  4. You’ve now activated your NGC product, and you will be redirected to the NGC org subscription page where you can verify your product is active. Click the Launch button for the service you want to access.

    NGC Organization Subscriptions Activate

That’s it! You’re all set up with your product.

Optional: You should have received a welcome email from your NVIDIA Cloud account. You can choose to complete the setup of your account now or at a later time.

Complete the steps in Setting up your NCA Account to configure your NCA account. The users you add to your NGC org are automatically added to the NCA account. To remove users or update NCA-related tenancy settings for a user, you need to take these actions in NCA.

Note

You cannot access NGC and NGC permissions cannot be assigned in NCA. NCA only manages user tenancy membership. To add users and assign NGC permissions, perform these actions in Adding NGC Users to an Org.

1.4.2. Activating NGC Product from an NVIDIA Commercial Entitlement Certificate#

When you procure a software subscription for an NVIDIA product, you’ll receive an entitlement certificate attachment in an email with instructions on how to claim your entitlement. The following steps guide you through the entitlement registration process.

  1. Find the Entitlement Certificate Email

    Open your email inbox and locate the email titled “NVIDIA Entitlement Certificate - Ref” containing your entitlement certificate attachment.

    Here is a sample entitlement certificate email:

    NGC Entitlement Certificate Email

    The entitlement certificate is provided as a PDF attachment. The following is an example:

    NGC Entitlement Certificate 1

    The PDF also includes instructions for using the certificate. Here is an example:

    NGC Entitlement Certificate 2
  2. Login or Register

    • If you’re an existing NVIDIA customer, click Already have an entitlement? Please Login.

    • If you’re a new NVIDIA customer, click register to begin claiming your entitlement.

  3. Sign In

    Enter your username. If you are using an NVIDIA user account, your username will be your email address. If you are signing in through your corporate single sign-on portal, use your company username. After entering your username, click Sign In.

    Commercial Entitlement Login Resized
    • Existing NVIDIA customers: Enter your password, and then click Login.

    • New customers: Create a new identity user account by setting a password.

  4. Select or Create an NVIDIA Cloud Account (NCA)

    Follow the steps below for returning or new customers.

    • For returning customers:

      The registration page displays different options for product activation.

      Commercial Entitlement Select NCA
      • Option A: Use an existing NCA

        1. In the NCA pane, select View Eligible NVIDIA Cloud Accounts to review available accounts that you own.

        2. Check the associated NGC org and active product subscriptions for each account.

        3. Select the desired account and click Continue.

      • Option B: Create a separate org

        1. Click Create new NCA to activate your product in a separate NGC org.

        2. Follow the steps below for creating new accounts.

      • Option C: Use an account you don’t own

        If you need to activate the product in an account you’re a member of that is owned by someone else (under View Other NVIDIA Cloud Accounts):

        1. Cancel the current registration process.

        2. Contact the account owner to request product activation.

        3. Refer to Contacting your Org Owner for more details.

    • For new or returning customers choosing to create a new account:

      You will be prompted to create a new NCA.

      1. Choose a meaningful account name for easy identification.

      2. Click Create NVIDIA Cloud Account when done.

      Commercial Entitlement Create NCA Resized
  5. Complete Entitlement Registration

    After selecting or creating an NCA, you will be directed to the entitlement registration page. Fill out the required fields and click Register.

    Commercial Entitlement Register Resized

    Required Information:

    • Primary Contact Information
      • First Name

      • Last Name

      • Email Address

    • Primary Contact Details
      • Location (Country)

      • Address

      • Phone

      • Job Role

  6. Email Confirmation and Access

    After a successful registration, you’ll receive an email from NVIDIA Application Hub:

    Click Log In to go to the hub.

    Commercial Entitlement Welcome Email Resized
  7. Click the NVIDIA NGC card to access your software subscription in NGC.

    Commercial Entitlement App Hub

    When you are in NGC, you can add additional users so they can access NGC by following the steps in Adding NGC Users to an Org.

    Your registration is now complete!

Optional: You can log in to NVIDIA Cloud Accounts to set up your recovery email.

Note

You cannot access NGC and NGC permissions cannot be assigned in NCA. NCA only manages user tenancy membership. To add users and assign NGC permissions, perform these actions in Adding NGC Users to an Org.

1.4.3. Signing Up for a Free Individual NGC Org#

This section describes the steps to sign up for an individual NGC org to access NGC Catalog artifacts gated by authentication. While setting up the NGC org, an NVIDIA Cloud Account is also created.

  1. Go to the NGC sign-in page from your browser, enter your email address, and then click Continue.

    Login New Organization
  2. To create your NVIDIA sign-in identity account, type in a password and confirm it (must meet the complexity check), review the NVIDIA account Terms of Use and Privacy Policy, and click Create Account to accept and proceed with your identity account creation.

    NGC Create Account New
  3. A verification email is sent to your email address.

    NGC Verify Email Code
  4. Open the email, copy the code, paste it in the Verify Your Email screen, and click Continue.

    NGC Verification Code Email NGC Verification Code Enter

    An additional browser page can open to validate the creation of your user account. Close this page and return to the browser page you started on.

  5. In the Almost done! dialog, select your communication preferences, and then click Submit.

    NGC Almost Done New
  6. Give your NVIDIA Cloud Account (NCA) a name that will help you identify it easily the next time you sign in.

    Create NVIDIA Cloud Account
  7. Complete your user profile at the Set Your Profile screen, agree to the NVIDIA GPU Cloud Terms of Use, and then click Submit.

    Set Your Profile

    Your NVIDIA account is created, and you are automatically redirected to your individual NGC org.

    NGC Default Landing Page

    Your registration is now complete.

Optional: From the NCA email, complete the steps in Setting up your NCA Account to configure your NCA account. The users you add to your NGC org are automatically added to the NCA account. To remove users or update NCA-related tenancy settings for a user, you need to take these actions in NCA.

Note

You cannot access NGC and NGC permissions cannot be assigned in NCA. NCA only manages user tenancy membership. To add users and assign NGC permissions, perform these actions in Adding NGC Users to an Org.

1.4.4. Setting up your NCA Account#

To finish setting up your NVIDIA Cloud Account, find your NCA invitation email message in your inbox and click Log In Now.

  1. Your NVIDIA Cloud Account (NCA) provides the services to set up a recovery email address in case your existing one becomes unavailable, manage access for additional users (subscription required), and set up billing information to purchase consumption-based NVIDIA cloud products.

    NGC NCA Welcome Email
  2. Enter your email address to log in and click Continue.

    NCA Login Email
  3. Enter the credentials you created for your NVIDIA identity account.

    NGC NVIDIA Account Sign In
  4. On the NCA landing page you can find the details of your account. Here you can set up a recovery email address that can be used to regain access if the email address you used to create your account becomes unavailable. Go to Setting Up NCA Recovery Email for steps on how to set up your recovery email.

1.4.4.1. Setting Up NCA Recovery Email#

To set up your NVIDIA Cloud Account (NCA) recovery email, follow these steps.

  1. Click Edit on the Account Details pane under the Account Management > Details page.

    NCA Details
  2. On the Edit - Details dialog, enter the email address that you want to use for account recovery. This email address must be different from the address used to create the account. You can optionally set a description for this account. Click Save.

    NCA Details Edit
  3. Confirm that the recovery email status on the Account Details pane changed to Pending.

    NCA Details Recovery Pending
  4. Go to your recovery email inbox, search for the NVIDIA message with the title “NVIDIA Cloud Account, Verify Your Recovery Email”, and click Verify.

    NCA Recovery Email
  5. You should see that your email has been verified.

    NCA Email Verified
  6. Go back to your NCA console and check that the recovery email status has been updated with the address you assigned.

    NCA Details Recovery Complete

1.4.5. Accepting an NCA Invitation to Access NGC#

Follow these steps to accept an invitation to join an NVIDIA Cloud Account and access NGC.

  1. Check your email inbox for a message titled “You’ve been invited to an NVIDIA Cloud Account.” Open the email and click Login to proceed.

    NCA Invitation Email
  2. If you are new to NVIDIA, you are prompted to create an NVIDIA identity account. Create a password that is at least 9 characters long and uses a mix of uppercase and lowercase letters, numbers, and special characters. If you already have an NVIDIA identity account, enter your password to continue. You can skip to Step 6 below.

    Create Identity Account

    You will be asked to verify your email address in a confirmation email.

    Verify Email Identity Account
  3. Check your email inbox for a message titled “NVIDIA Accounts”. Open the email and click Verify Email Address.

    Email Verification Identity Account

    The email confirmation message will display in your browser.

    Email Verified Identity Account
  4. NVIDIA would like permission to send you the latest news related to our software and products, as well as learn more about how you use our websites to make sure we send you information relevant to you. Select your options and click Submit.

    Almost Done Identity Account
  5. You are prompted by NVIDIA Cloud Accounts to accept the invitation to join your company’s account. Click Accept Invitation to continue joining.

    Invitation Details Identity Account
  6. Enter your password (required for security).

    NGC Sign In Existing User Dark
  7. Accept the terms of use and privacy policy to access your software subscription.

    Terms of Service Identity Account

    You can now access the NGC org.

1.5. Using an External SSO for Enterprise Platform Authentication#

An enterprise org can federate its external SSO or IdP with NVIDIA to centralize user authentication and manage access to NVIDIA cloud services. The following table lists the NVIDIA services involved when you federate.

NVIDIA Services and Access#

Service

Access

NVIDIA NGC

Access to NGC Catalog, Private Registry, and other NVIDIA AI services

NVIDIA Application Hub

Access to NVIDIA Licensing, Enterprise Support, NGC, and NVIDIA Partner Network portals

NVIDIA Registration Web Application

Access to register your NVIDIA software product entitlement certificates

NVIDIA Cloud Accounts

Access the tool used by NGC to manage user org account membership

Important

For NVIDIA to detect deletion or deactivation of a user managed by the external IdP, integrate your IdP user management service with the NVIDIA identity federation system. Use System for Cross-domain Identity Management (SCIM) or Security Event Tokens, and allow user update events to flow to NVIDIA. NVIDIA uses these events so that deleted enterprise user accounts are reflected across NVIDIA services. Credential assets owned by the removed user, such as API keys, are revoked when NVIDIA receives the deletion or deactivation event.

During the federation process, NVIDIA shares the IdP federation document titled “Synchronization of users and group changes.” NVIDIA records a written acknowledgment of receipt, such as email. NVIDIA also records whether you will implement the security event integration.

Some NVIDIA products (like NGC) provide a UI option for customers to manually disable, deactivate, or disenroll users within the NVIDIA application and trigger the revocation of credential assets by deleting the user. For example, NGC supports removing a user from an NGC org, and this event automatically triggers the revocation of user-owned NGC API keys.

However, application-specific removal does not remove the user from other NVIDIA applications unless you remove them at the NCA account level. If the user had access to other NVIDIA services that grant credential assets, these assets would remain as active dangling assets against those services because the user account remains “active” in our central identity service and NCA.

To ensure a user account is removed across all NVIDIA services, integrate user event sharing with the NVIDIA IdP federation service and follow NVIDIA’s recommended de-provisioning operations.

To begin IdP onboarding, refer to Federating IdP with NVIDIA Cloud Services.

1.5.1. Federating IdP with NVIDIA Cloud Services#

To begin onboarding your Identity Provider (IdP), associate your domain with at least one NVIDIA NGC org. That org must have an active enterprise product subscription, such as NVIDIA AI Enterprise.

NGC ID Federation Subscription
  1. To request to onboard your external IdP, go to NVIDIA Cloud Accounts and enter your email to sign in. Use the email address whose domain you will use for your IdP configuration.

    NGC ID Federation NCA Login

    Enter your password.

    After signing in, you will land in the NVIDIA Cloud Account portal. Navigate to the SSO integration option and click Start the SSO integration process.

    NGC ID Federation NCA SSO Integration
  2. Complete the request form with the following information:

    NGC ID Federation NCA SSO Integration Form
    • Company name: Enter your company name.

    • Additional domains: Enter any additional domains your users will use to sign in to NVIDIA. The request tool automatically detects and populates the domain from the email you used to sign in.

    • Technical contacts: Add additional technical contact email addresses for delegates who will help with integration during onboarding.

  3. Click Submit.

    NGC ID Federation NCA SSO Integration Submit
  4. Record the Ticket ID in case you need to open a support ticket, then click Go to Identity Federation Portal.

  5. At the login prompt, sign in with the email account you used to submit the onboarding request. After you log in, you will see the initial screen of the IdP onboarding tool. Complete the required fields and click Next.

    • Your company name: NVIDIA will ask to verify ownership of your company domain.

    • Your identity management system: Select your IdP (for example, Azure AD, Okta) from the dropdown.

    • Your email domains: Enter the domains managed by your IdP.

    NGC ID Federation Create Account
  6. Onboarding Wizard

    You will be guided through a configuration wizard based on the IdP system you selected (Azure AD, OpenID Connect, or SAML). The wizard provides step-by-step guides for your chosen IdP type.

    NGC ID Federation Onboarding Guides

    Note

    After the ticket ID is generated (Step 4), detailed configuration guides are also available at the NVIDIA Identity Federation portal.

    For the OpenID Connect option, the wizard can display the following screen:

    OpenID Connect Provider

    NGC ID Federation OpenID
  7. Perform a Login Test

    After completing the IdP onboarding configuration, follow the instructions to test the login process.

    • Read the Login test instructions and click Next.

      NGC ID Federation Login Test
    • Review your login test results. If successful across all login services, click Confirm. If not, troubleshoot your IdP system and retest.

      NGC ID Federation Login Test Result
  8. (Optional) Seek Support or Reassign Task

    Use the “Help” button to access support options.

    NGC ID Federation Help

    You can reassign the IdP configuration task to a colleague.

    NGC ID Federation Reassign
  9. Complete the IdP onboarding

    After completing the login test, you will see a success message.

    NGC ID Federation Success

    The NVIDIA team will typically finalize the onboarding within one business day, and you will receive a confirmation email.

    NGC ID Federation Complete

Important

After your IdP is federated, NVIDIA cloud platforms are not automatically enabled to authenticate users through your external IdP. Your company can have users who still access NVIDIA cloud platforms with NVIDIA-based identity accounts. Contact ngc-sso@nvidia.com to identify those users, communicate upcoming changes, and plan the migration of enterprise entitlements to IdP-based identity accounts.

1.5.2. Authenticating and Managing User Access#

This section describes how users authenticate through an enterprise SSO or IdP, how to add new users, and how to manage user permissions and roles.

After your company’s IdP is onboarded and federated with NVIDIA, users signing in to NGC with those domains authenticate through your enterprise IdP. NGC then redirects them back after a successful sign-in.

To add new users to an org federated to an external SSO or IdP provider, the org owner follows the steps described in Adding NGC Users to an Org.

If your IdP provides OIDC or SAML group membership claims, NGC can map those claims to NGC org, team, and role assignments. Refer to NGC IdP Membership Rules for more details.

Note

NGC orgs no longer manage user tenancy directly; users and/or groups are assigned “permissions” to access NGC org resources and are tenants of the NVIDIA Cloud Account (NCA) linked to the NGC org. Users and groups are now added to the NVIDIA Cloud Account.

If you are managing user memberships using IdP-based group tags (claims), you will add these groups in the NCA and assign access permissions for NGC under “External IdP > IdP rules.”

To ensure access to the NCA account and NGC org is never lost, even if the IdP service is rendered inaccessible, configure a “Recovery email address” under the NCA account. This email address will be used to authenticate you outside of your IdP. For more information about email recovery, refer to Setting Up NCA Recovery Email.

1.5.3. NGC IdP Membership Rules#

When your organization’s IdP is federated with the NVIDIA identity federation service and your NGC org is linked to that federated account, the org owner can create membership rules from the Organization > Enterprise IdP configuration page.

Important

Only the org owner or users with the user_admin role at the organization level can manage IdP rules.

If you are an org owner, even if you are a member of a group configured in an IdP rule, the rule will not update your roles. By default, the org owner inherits admin privileges across all enablements and services in the owned org, and these role assignments are immutable.

NGC IDP Create Rule

If the NGC org is not linked to an enterprise-owned SSO IdP provider, the Enterprise IdP option is disabled and a message states that the org is not linked to an IdP. To link your org, sign in to NVIDIA Cloud Accounts as described in Using an External SSO for Enterprise Platform Authentication.

NGC IDP Organization External

The membership rules feature uses OpenID Connect (OIDC) or SAML group claims containing the user’s membership attributes.

To make sure your IdP is sending the group claim values correctly, ensure that your “test login” results reflect the group values you expect during testing. Refer to the “Perform a Login Test” step in Federating IdP with NVIDIA Cloud Services.

An org owner or organization-level user_admin creates membership rules by mapping the IdP groups claim name to NGC org roles and permissions. Users assigned to those groups in the enterprise AD service receive the roles and permissions assigned to the group name in the NGC IdP rules.

1.5.3.1. Example#

In this example, we are using Okta as the enterprise-owned SSO IdP provider. It is assumed the same person managing Okta also has NGC org owner permissions.

Okta Settings

  1. First, the NGC org gets linked as a client application to the Okta IdP service.

    NGC IDP Okta 1
  2. On Okta, managed users get assigned to the NGC client application, enabling them to sign in to NGC using their Okta SSO account.

    At this point, users have not been assigned to a ‘group’.

    NGC IDP Okta 2
  3. On Okta, secure AD groups are created, and users can be assigned to a group or a set of groups.

    NGC IDP Okta 3
  4. In this example, Adam and Amy are assigned to the NGC_AIE_PR_Admin group. Note that this is being done manually using the Okta user management feature, but this is typically managed automatically by using an enterprise active directory integrated into the IdP provider.

    NGC IDP Okta 4
  5. At this point, Adam and Amy can sign in to NGC, but there isn’t an IdP rule that assigns them NGC org roles and permissions. The next section covers creating the NGC IdP membership rules that will grant Adam and Amy their roles.

1.5.3.2. Configuring NGC#

Now that the IdP groups are created and users are assigned to secure AD groups on the Okta IdP side, the administrator (org owner) is ready to configure NGC IdP membership rules. Do this from the Organization > Enterprise IdP configuration page.

  1. Create a rule and name it as follows:

    1. Click Create Rule.

    2. In the Rule Name field, enter a name that describes the purpose of the rule.

  2. Create an Identity Provider (IdP) group:

    1. Click Create IdP Group to open a popup window.

    2. In the popup, in the IdP Group Equals to field, type the group name exactly as it appears in your IdP.

    3. In the popup, in the Role for IdP Group field, select Member.

    4. Click Create IdP Group to close the popup.

      NGC IDP Rule Details
  3. Select the team and NGC access roles that the rule applies to:

    1. Select Assign to Organization to apply this rule to the entire NGC org.

    2. Select roles for each cloud service that group members will be granted. In this example, select NVIDIA AI Enterprise Viewer and Private Registry Admin.

  4. Finish creating the rule by clicking Create IdP Rule.

    NGC IDP Active Confirm
  5. After saving your rule, you must click the Activate Rules button to apply the rule-based membership roles to your IdP users. This will occur per user when they sign in.

The org owner or organization-level user_admin can create multiple rules to support multiple group claim values from the IdP. An example of multiple IdP membership rules created can be seen below.

NGC IDP Enterprise Rules

Important

The NGC IdP membership rules do not go into effect until they are “activated”. Users’ accounts that were added using the manual method will continue to use NGC role permissions assigned through ‘Users’ invite user membership configurations.

When you click Activate Rules, the org owner or organization-level user_admin is prompted to confirm activation of the IdP rules. When the rules are activated, the NGC IdP rule system reviews user memberships previously added to the org using the “user invitation” method. It checks whether each user account maps to an IdP membership rule. If a match is found, the previous account membership is removed and a new user account membership is created with the same email address and IdP association. The permissions and roles assigned to the new account membership are based on the IdP groups claim attribute.

Note

Previous user accounts that do not map to an IdP rule remain as active user accounts under Users account memberships. An org owner or organization-level user_admin can remove these users if the org should only be accessible by members mapped to IdP rules.

1.6. Activating Your Subscription (Offer Dependent)#

This section describes activating a subscription and linking it to your NGC Account.

Note

These steps are only required for customers who have been given an activation code as part of the purchase of a GPU or DPU.

  1. Access the activation page through Activate Subscription.

  2. Sign in to NGC with your email address and password if prompted. If you have not created an NGC account, create one now.

  3. On the Activate Subscription page, enter your Business Information using your company’s headquarters address and the serial number or activation code described by the specific offer. If entering multiple serial numbers or activation codes, use a comma to separate each.

  4. Click Activate Subscription.

    Activate Subscription
  5. After the system validates the serial numbers, review the information displayed and click Request Activation.

    Request Subscription
  6. The Subscriptions page will display for your organization with the active NVIDIA AI Enterprise subscription.

  7. Use the left navigation and click Enterprise Catalog to access the NVIDIA AI Enterprise software suite.

    Enterprise Catalog Menu

1.7. Switching Orgs or Teams After Logging into NGC#

This section describes switching to a different org or team after logging in.

In the top menu bar, click your user account icon. Then, select your org menu to expand the view to other available orgs. If you manage many orgs, you can use the search field to find the specific org you want to select. Select the desired org by clicking it once.

NGC Switching Organization Team

Depending on the org or team you select, your current page can also refresh.

1.8. NGC API Keys#

NVIDIA NGC API keys are required to authenticate with NGC services using NGC CLI, Docker CLI, or direct API requests.

NGC provides two types of API keys: personal keys and service keys.

Personal Keys

Personal keys have the following characteristics:

  • Any NGC org user can generate a personal key.

  • An NGC org user can grant a personal key up to the permissions assigned to them in the NGC org.

  • A personal key is linked to the user’s NGC org lifecycle.

    • If the user’s permissions change, the available permissions that can be or are assigned to the personal key also change.

    • If the user is removed from the NGC org, the key’s validity is revoked.

  • Supports updating permissions, rotation, and deletion (immediate revocation).

    • Org owners and organization-level user_admins can revoke any member’s key on demand.

  • Each user can generate up to 32 personal keys across all organizations they are a member of.

Use personal keys to begin using NGC services within your sandbox. Personal keys are best suited for individuals working on early development and testing code before moving to pre-production and production releases.

To learn how to authorize the services you have access to in the org and generate a personal key, go to Generating a Personal API Key.

Important

Use the legacy NGC API Key for cross-org authorization. NVIDIA encourages you to use the Personal Key, but if you need to continue using the legacy API key, go to Generating a Legacy NGC API Key to find out where to create a new one. Also, your current NGC API key will continue to work.

Service Keys

Service keys have the following characteristics:

  • The lifecycle of service keys is linked to the NGC org account, not associated with an individual user.

  • Only NGC org owners and organization-level user_admins can manage service keys.

  • A service key can be scoped to access only the permissions and services required, or full access to the services enabled in the org.

  • Supports scoped permissions, updating permissions, on-demand revocation, rotation, and deletion.

  • An NGC org can have up to 64 service keys.

Use service keys when you require automated communication between machines and need to deploy to pre-production and production environments where you do not want to depend on a user’s membership status in the NGC org.

Note

Service keys currently do not support listing artifacts in NGC CLI or Docker CLI. This functionality will be added in the future. In the meantime, use a Personal API key to list artifacts.

Examples using NGC API Keys

Here are some examples of using NGC API keys to authenticate with NGC CLI and Docker CLI:

NGC CLI

$ ngc config set

Paste your key value at the API_KEY prompt:

[Enter API key [****API-Key]. Choices: [<VALID_APIKEY>]

Important

Always use the latest NGC CLI version to access the newest features, bug fixes, performance improvements, and security updates. Check for the latest versions at NGC CLI Installers or run ngc version list to view the latest releases, then upgrade using the following command:

ngc version upgrade

Docker CLI

docker login nvcr.io --username '$oauthtoken'

For the username, enter '$oauthtoken' exactly as shown. It is a special name that indicates that you will authenticate with an API key. Paste your key value at the Password prompt.

1.8.1. Supported NGC Applications and API Key Types#

The NVIDIA NGC applications/services that support Personal and Service Keys are listed below:

NGC Applications and Services#

NGC Application/ Services

Service Description

NVIDIA NGC Catalog

Grants your key permission to access or download containers and artifacts from the NGC Catalog. The permission level matches your account’s permissions for the catalog.

NVIDIA NGC Private Registry

The key is authorized to perform actions on your organization’s private registry service, such as pulling, retrieving, creating, or deleting containers and artifacts. The permission level assigned to the key matches the permission level of your user account. Therefore, your user account must have permissions for the Private Registry.

NVIDIA Cloud Functions

This authorization allows your key to perform actions on your organization’s cloud functions service. If your organization has private functions published by NVIDIA, or if your cloud functions service enables you to create, deploy, and run your own functions, your personal key will have the same permissions as your user account for the cloud functions service. Therefore, it’s important that your user account has the necessary permissions for Cloud Functions.

NVIDIA Public API Endpoints

Grants permission for your key to access NVIDIA NIM inference endpoints listed in the NVIDIA API Catalog. Therefore, your user account must have Public API Endpoints permissions.

NVIDIA Secrets Manager

Authorizes your key to perform actions on the NVIDIA Secrets Manager service, which is used to store and manage secrets. Your key will have the same permission level as your user account, so your user account must possess Secrets Manager permissions.

1.8.2. Generating NGC API Keys#

Generating API keys is essential for authenticating with NGC services using the NGC CLI, Docker CLI, or direct API requests.

1.8.2.1. Generating a Personal API Key#

  1. Sign in to the NGC website. From a browser, go to the NGC sign-in page and then enter your email and password.

  2. Click your user account icon in the top-right corner and select Account Settings.

    NGC User Profile Menu Setup
  3. Scroll to the bottom and click Generate API Key under API Keys.

    API Key Generate
  4. On the Account > API Keys page, click + Generate Personal Key on the menu or the pane.

    API Key Generate Page
  5. In the Generate Personal Key dialog, fill in the required information for your key.

    API Key Generate Personal Key Dialog
    • Key Name: Enter a unique name for your key.

    • Expiration: Choose the expiration date for the key.

      API Key Generate Personal Key Expiration
    • Services Included: Choose from the available services the key is permitted to access. Refer to Assigning Services to Your Personal API Key to learn more about each service and when to assign service access to your Personal Key.

  6. Click Generate Personal Key when finished.

  7. Your API key appears in the following dialog.

    NGC does not save your key, so store it securely. You can copy your API Key to the clipboard by selecting Copy Personal Key or using the copy icon to the right of the API key.

    API Key Generate Personal Key Confirm

    You can generate up to 32 personal keys and manage them from the Account > API Keys dashboard. The vertical ellipsis menu allows you to rotate or delete a personal key.

    API Key Generate Personal Key Dashboard
1.8.2.1.1. Assigning Services to Your Personal API Key#

The services you can assign to a personal API key depend on two factors:

  • The services enabled for the NGC org where you generate the API key.

  • The service roles assigned to you by your NGC org owner or administrator.

For example, consider an NGC org with the following services enabled:

NGC Organization Subscriptions

An NGC user account might have the following access roles assigned:

NGC User Account Example

In this scenario, the NGC org has enabled NVIDIA Microservices, Private Registry, NVIDIA AI Enterprise, and Cloud Functions (NVCF). The user account has been granted access roles for all these services. Therefore, a personal API key can be generated with permissions to access one or all of them.

NGC Generate Personal Key Dialog

If a service is unavailable for assignment to the API key, it indicates that the org owner or administrator has not granted the user the necessary role for that service.

For details about each service listed above and its function, refer to the table Supported NGC Applications and API Key Types.

1.8.2.1.2. Generating a Legacy NGC API Key#

Important

Legacy API keys are the original key type available in NGC since its inception. This type supports only one active key per user account. When a new key is generated, the previous one is automatically revoked and cannot be rotated. NVIDIA will continue to support this key type for services that have not yet transitioned to the next-generation API keys. However, we strongly recommend migrating to our next-generation Personal or Service API keys whenever possible for improved security.

To generate a legacy API key, go to Setup > API Keys and click + Generate Legacy Key in the Legacy Keys drop-down.

API Key Legacy Key

In the Generate Legacy Key dialog, click + Generate Legacy Key.

API Key Generate Legacy Key

1.8.2.2. Generating a Service API Key#

  1. Sign in to the NGC website. From a browser, go to the NGC sign-in page and then enter your email and password.

  2. Select Organization from the user account menu on the upper right.

    NGC Catalog User Account Menu Organization
  3. Select Service Keys on the organization dashboard.

    NGC Organization Dashboard Service Keys
  4. On the Organization > Service Keys page, click + Create Service Key to create a key.

    API Key Create Service Key Page
  5. In the Create Service Key dialog, you can select one or more services to authorize for the service API key, and configure scoped permissions that apply to either all entities or a specific subset accessible through those services. Begin by entering the required configuration details.

    API Key Create Service Key Form
    1. Service: Select a service. Service keys currently support a range of services, including NVIDIA Cloud Functions, NIM API endpoints, NGC Catalog, and Private Registry.

      API Key Create Service Key Service
    2. Scope: Specifies the exact permissions or actions the key can perform for a selected NGC service. Examples for Private Registry and NGC Catalog include “Get Container”, “Get Container list”, “Get Artifact”, and “Get Artifact list”. Other services list the scopes (actions) that can be assigned to the key.

      API Key Create Service Key Scope

      Note

      Select only the permissions you need (least privilege). Refer to Least-Privilege Service Key Recipes for more information.

      Important

      When generating a key for Private Registry or NGC Catalog services and granting access to containers, assign the scopes Get Container and Get Container list to your service key. For other artifact types, assign Get Artifact and Get Artifact list. These are the minimum scopes required to discover artifacts that need to be managed. Refer to the NGC Catalog User Guide and Private Registry User Guide for more information.

    3. Entity Type: An entity is a resource that can be managed with the appropriate permissions and access controls. In Private Registry, an entity can be a container or a collection of containers that, depending on the permitted scopes, can be downloaded, updated, or deleted. In NVIDIA Cloud Functions, an entity is an “inference function” that can be listed, invoked, or deleted based on the scopes assigned to the service key.

      API Key Create Service Key Entity Type

      Note

      Choose the smallest unit that matches your use case. Refer to Least-Privilege Service Key Recipes for more information.

    4. Entity Value: Specifies whether the key has access to all entities in the NGC org and teams, or only to a single entity or a defined list of entities within the org.

      API Key Create Service Key Entity Value

      Important

      If a service key requires access to all organization-level and NGC team-level entity types, define two entity values for the key.

      NGC Catalog Containers Entity Types

      The example above shows the Entity Value configuration required for the service key to access all entities at the organizational level and across all NGC teams. For additional examples, refer to Configuring Access to NGC Catalog Artifacts.

  6. Click Next Step to review your key configuration.

    API Key Create Service Key Form Next Step
  7. After you have verified the configuration, click Confirm to generate your service key. Your service key appears in the next dialog.

    API Key Create Service Key Confirm
  8. NGC does not save your key, so store it securely. You can copy your API Key to the clipboard by clicking the copy icon to the right of the API key or the Copy Service Key button.

    API Key Create Service Key Copy Key

    Make sure to copy the key value before leaving this page. After you navigate away, the key value cannot be retrieved, and replacing it will require generating a new key.

1.8.2.2.1. Configuring Access to NGC Catalog Artifacts#

To configure a service key for NGC Catalog access, you must specify the path where each artifact is published. Include all required paths, as artifacts are published under different NVIDIA-managed NGC organizations depending on type.

Here are some examples:

  • NVIDIA NIMs are published in the nim NGC org (for example, nim/*/*).

NGC NIM org
  • The NVIDIA GPU Operator and other artifacts are published in the nvidia NGC org (for example, nvidia/*/*).

NGC NVIDIA org
1.8.2.2.1.1. Setting the Path for Specific Artifacts#

To access a specific artifact, check its publishing details (for example, by examining the GET path information).

  • For artifacts within the nim NGC organization, the service key must be set up to permit access to the relevant repository. Although the configuration below provides access to all NVIDIA NIM artifacts, you can restrict the key’s access by specifying the path to a particular artifact in the Entity Value field (for example, nim/<team>/<artifact>).

    NGC NIM org
  • If you need to access artifacts in a different NVIDIA-managed NGC org, such as the nvidia org (for artifacts like the NVIDIA GPU Operator), add that specific path to your service key configuration (for example, nvidia/*/*).

    NGC NVIDIA org
1.8.2.2.1.2. Comprehensive Access Configuration#

To grant a service key access to all entities (artifacts) available in both primary NVIDIA-managed orgs, include both wildcard paths. For example:

  • nim/*/*

  • nvidia/*/*

This configuration grants the service key access to all entities published in the root and all subfolders of the NVIDIA-managed nim and nvidia orgs.

Important

Access to certain restricted artifacts in the catalog, such as those requiring NVIDIA AI Enterprise, depends on active subscriptions. If your NGC organization does not have the necessary subscription, a service key can be denied access to specific artifacts even if the permissions are configured as described above. Always check the access requirements for each product listed in the NGC Catalog.

1.8.2.2.2. Configuring Service Keys for NVIDIA Cloud Functions#

To configure a service key for NVIDIA Cloud Functions (NVCF), select the Scopes, Entity Types, and Entity Values for the operations the key must perform. Scopes are the actions the key can perform. Entity Types are the resources those actions apply to. The following entity types are available for NVCF:

  • All Functions: all functions in this org.

  • Function: a single function, specified by function ID.

  • Function Version: a single function and a specific version of that function.

  • All Clusters: cluster and GPU infrastructure information.

  • All Entity: all resource types in the org. Required by certain org-level scopes. Refer to the important note that follows.

Refer to the NVCF Service Keys Documentation for the full list of scopes, compatible resource types, and troubleshooting guidance.

Important

The following scopes only work with the All Entity resource type. Selecting any other resource type will result in a 403 error: Manage Registry Credentials, Manage Telemetries, Read GPU Quota Rule, and GPU Capacity.

1.8.2.2.3. Managing Service API Keys#

NGC supports multiple Service API keys, which are managed from the Organization > Service Keys dashboard.

To activate or deactivate a key, click the Active toggle. The Actions (ellipsis) menu allows you to rotate or delete a service key.

API Key Create Service Key Dashboard
1.8.2.2.4. Least-Privilege Service Key Recipes#

Here are some examples of least-privilege service key recipes:

  • Private Registry: List, push and pull only containers

    • Service: Private Registry

    • Entity Type: All Containers

    • Entity Value: <org name>/* and <org name>/*/*

    • Scope: List Container, Upload Container, Download Container

    Note

    In the entity value, <org name>/* includes all org-level entities, while <org name>/*/* includes all team-level entities across the org.

  • NGC Catalog: Read-only pull for a single model

    • Service: Catalog

    • Entity Type: Specific Model

    • Entity Value: nvidia/ace/nemovision-4b-v2-instruct

  • NVCF: Invoke-only (production inference client)

    • Service: Cloud Functions

    • Scope: Invoke Function, Queue Details

    • Entity Type: Function → <function-id> (or All Functions for access to all functions)

  • NVCF: Manage function lifecycle

    • Service: Cloud Functions

    • Scope: Register Function, Deploy Function, List Functions, List Function Details, Update Function, Delete Function

    • Entity Type: All Functions → Account-owned Functions

1.8.3. Troubleshooting API Key Errors#

Below are errors you might encounter, with guidance on how to troubleshoot and resolve each one.

  • 401 Unauthorized

    A 401 Unauthorized response indicates that you aren’t properly logged into nvcr.io. Verify correctness of your authentication secret or try docker logout and logging back in.

  • 403 Forbidden

    A 403 Forbidden response indicates that either a required scope is missing or the entity type and value are not correctly configured for the resource the API is trying to access. You likely need to select Update Authorizations and reconfigure the service key.

  • Recently updated keys

    After you modify a Service Key’s scopes or entity type/value, it can take up to 15 minutes for the changes to propagate. Requests made before propagation completes continue to be evaluated against the previous authorization policy and can return an error.

1.9. Secure Sharing Service#

NGC Secure Share is a security-focused service designed to help NGC users share sensitive credentials and secrets with each other. This service eliminates risky credential-sharing practices such as sending passwords or API keys through email, chat, or public forums.

Important

Exchanging credentials in clear text or through unprotected channels can result in the compromise of both user artifacts and the hosted services in NGC. Always utilize Secure Share to distribute sensitive information.

Secure Share enables secure, auditable, and ephemeral sharing of secrets, including API keys, usernames/passwords, and tokens, between NGC users and collaborators. Instead of transmitting credentials in an unsafe medium, users generate a secure, time-limited Secure Share link that is strictly controlled by access policies.

Secure Share provides the following capabilities:

  • End-to-end encryption for all shared secrets

  • Recipient restriction: limit access to specified organization

  • Burn-after-read: each link will expire after a single access

  • Short link lifespan: customizable expiration (5 min to 24 hours)

  • No secrets stored after access: secrets are unrecoverable after viewing or expiration

Typical uses include:

  • Safely hand off API keys between team members

  • Securely provide one-time passwords or recovery codes to partners or support

  • Distribute model secrets or other credentials during project onboarding

1.9.1. Securely Sharing Secrets#

Follow these steps to securely share credentials using NGC Secure Share:

  1. Log in and access Secure Share Service.

    • If not already signed in, log in to the NGC web portal using your NVIDIA credentials.

    • In the top right corner, click your profile and go to Account Settings, then click Secure Share.

    • Alternatively, you can open the Secure Share page.

  2. Enter secret content by pasting or typing the credential or secret (for example, API key, username/password) you want to share.

  3. (Optional) Configure additional share details:

    • Set the recipient organization.

      • For organizations you belong to, pick from the list.

      • For an external organization, you must enter the exact NGC organization name provided by the recipients. This is needed to ensure proper access controls. If your recipient needs help finding their organization name, they can refer to the Finding your Organization Name section.

    • Set the expiration time for the link: from 5 minutes to 24 hours.

    • Set a display name to help you track the share.

  4. Click Create Link.

    NGC Secure Share Dialog
  5. Click Copy Link to copy the link to your clipboard before closing.

    NGC Secure Share Copy Link
  6. Provide the link directly to the intended recipient, for example through email or direct chat.

1.9.3. Finding your Organization Name#

If you need to confirm or provide your organization name so a Secure Share link opens only for your NGC organization, use the Secure Share service UI.

To find your NGC organization name, follow these steps:

  1. Open the Secure Share page.

  2. Click Request Content.

  3. If you belong to multiple organizations, locate the correct one and click Create Link.

    NGC Secure Copy Organization Name
  4. Review the pre-configured share link, then click Copy Link.

    Send this link to the person who will share secure content with you. When they open it, your organization will be pre-selected, allowing them to encrypt and send their data securely.

    Important

    For security, always verify you are entering or selecting the correct organization to avoid access issues or failed link attempts. If you are unsure or you cannot find your organization name, contact your NGC administrator.

    Note

    You cannot receive shares to organizations in which you are an external user.

1.10. Notification Services#

The NGC Notification Services feature enables NGC users to subscribe to email notifications to receive service change events. By subscribing to notifications, users can stay updated with the latest changes and developments in the NGC cloud platform and its services.

NGC customers can be informed of the following types of changes:

  • Customer-impacting service enhancements (release notes)

  • Security vulnerabilities (CVEs) and scanning reports

  • Software end-of-life announcements

  • Scheduled web portal maintenance to an NGC property

NGC customers can verify their notification subscription settings by viewing their NGC user Account Settings page:

Notification Email Preferences Account

1.11. Appendix#

1.11.1. NVIDIA NGC Network Protocols#

The following table lists the required network protocols and port configurations for communication with NVIDIA NGC services.

To enable access, ensure that these ports are open in your web proxy, which connects your network to external services.

Required Network Protocols#

Location

Description

URL

Port

NGC

Authentication URL

https://authn.nvidia.com

443

NGC

Container Registry URL

https://nvcr.io

443

NGC

Container Registry URL

https://layers.nvcr.io

443

NGC

Helm Chart Registry

https://helm.ngc.nvidia.com

443

NGC

API URL

https://api.ngc.nvidia.com

443

NGC

Telemetry URL

https://prod.otel.kaizen.nvidia.com

8282

NGC

Catalog

https://files.ngc.nvidia.com

443

NGC

Catalog

https://xfiles.ngc.nvidia.com

443

NGC

Catalog

https://xlfiles.ngc.nvidia.com

443