Skip to main content
Use this page to understand the kubeconfig files that Managed Auth generates for CoreWeave Kubernetes Service (CKS) clusters, including the fields in a generated file and common authentication errors. To create an API access token and download a kubeconfig file, see Manage API access tokens and kubeconfig files. For an overview of Managed Auth across CoreWeave, see Managed Auth.

Generated kubeconfig structure

Managed Auth generates kubeconfig files for your CKS clusters from the Cloud Console. These files follow the permissions configured for their related tokens and embed the API access token. The following example shows a kubeconfig file generated by Managed Auth:
Generated kubeconfig files contain the following values and might include additional values:

Authentication errors

The following errors can occur when you use a Managed Auth kubeconfig file. For help choosing an authentication method, see Introduction to authentication and access control.
The managed endpoint returns 403 Forbidden for token problems, not 401 Unauthorized. A 401 on a CKS cluster points to an OIDC or unmanaged authentication issue instead. If several users share one token, its expiration or revocation blocks all of them at once. Give each user their own token.
Last modified on October 2, 2026