Direct access token exchange
To exchange a CoreWeave API access token directly for temporary AI Object Storage credentials, you need the
Object Storage Admin role or an organization access policy that grants cwobject:CreateAccessKey.iam:[ORG-ID]:groups condition key for group-based access control.
- Duration: Keys are ephemeral and refresh automatically through the AWS container credentials provider. The keys are valid for 30 minutes.
- Identity format:
coreweave/[UID].
Workload Identity Federation
CoreWeave recommends Workload Identity Federation (WIF) for production workloads. Instead of storing long-lived credentials, your applications obtain tokens from your existing identity provider (IdP) and exchange them for short-lived Access Keys that automatically expire. OpenID Connect (OIDC) is the default for new WIF integrations. CoreWeave offers Security Assertion Markup Language (SAML) by request for organizations with an existing SAML requirement.Workload Identity Federation with OIDC
OIDC is the recommended method for cloud-native and Kubernetes workloads. It uses short-lived tokens from your identity provider, such as GitHub Actions, a Kubernetes service account, or any OIDC-capable IdP, and exchanges them for temporary Access Keys with a 30-minute lifespan. OIDC is the standard approach for machine-to-machine authentication in cloud environments. To generate keys with OIDC tokens, submit API requests toCreateAccessKeyFromOIDC. The endpoint accepts a GET request that includes the Organization ID and uses the token as the authorization header.
- Duration: Keys are temporary with a 30-minute lifespan.
- Identity format:
role/[ISSUER-URL]:[SUBJECT-USER-ID].
Workload Identity Federation with SAML
CoreWeave offers SAML by request to organizations with an existing SAML requirement. Before you use this method, contact your CoreWeave account team. SAML integrates with enterprise identity providers such as Active Directory Federation Services. To generate keys with SAML assertions, submit API requests toCreateAccessKeyFromSAML. These keys have the following characteristics:
- Duration: Keys are temporary with a maximum lifespan of 12 hours.
- Identity format:
role/[SAML-ROLE]. - Requirements: You must create a valid
configIdfrom a Workload Identity Federation configuration and pass it to the API request. For more information, see Using Workload Identity Federation with SAML.
Static access keys
Creating static access keys requires the
Object Storage Admin role or an organization access policy that grants cwobject:CreateAccessKey.CreateAccessKeyFromJWT. These keys have the following characteristics:
- Duration: Keys can be persistent, or they can be time-limited for up to 12 hours.
- Identity format:
coreweave/[PRINCIPAL-UID]. - Requirements: The API access token used to create the Access Key must have
writepermissions for Object Storage so users can upload data. For details, see Create a CoreWeave API access token.
Identity formats
You can use the Access Key format to audit and diagnose access. To find out how an Access Key was created, examine its identity format:Types of access keys
Access Keys fall into two categories based on creation method: Static keys come from an API access token and are intended for development, testing, and manual operations:- Permanent keys: Don’t expire. Require manual rotation.
- Temporary keys: Expire after a set duration of up to 12 hours.
- OIDC-generated keys: 30-minute lifespan. Your application automatically refreshes them.
- SAML-generated keys: CoreWeave offers these keys by request for existing SAML integrations. They have a lifespan of up to 12 hours.
Manage your access keys
This section covers the full lifecycle of access key management:- Create access keys: Generate new keys for users and workloads.
- Revoke access keys: Remove keys that are no longer needed.