Where to manage what
The following table shows where each task belongs:
Each platform bills for its own products and has a separate billing page, so a Forge invoice doesn’t include CoreWeave infrastructure usage. For the full billing orientation, see CoreWeave Infrastructure and Forge billing.
How the two identities relate
Each platform authenticates its own users:- CoreWeave IAM authenticates users for platform resources and authorizes them through IAM Access Policies.
- Forge authenticates users through its own identity layer. Forge and
wandb.aishare one account and one user store, so a Weights & Biases user signs in to Forge with their existing account.
Administer access in both systems
The following sections describe how administration works across the two systems. This behavior is subject to change.Grant and revoke Forge access in Forge
You can view and assign Forge access in the Forge Console, including which Forge products a user can reach and what Forge roles they hold. CoreWeave IAM roles, including IAM Admin, govern the CoreWeave platform only and don’t grant a Forge role or Forge product access. To change a user’s Forge role, change it in Forge. You can blockforge.coreweave.com on your network to prevent users on that network from reaching Forge.
Configure Forge authentication methods
Forge supports Security Assertion Markup Language (SAML), OpenID Connect (OIDC), and passwords, each configured inside Forge. CoreWeave IAM doesn’t govern any of them. SAML single sign-on (SSO) on the CoreWeave side covers the Cloud Console only. If you want one identity provider behind both platforms, configure it in each one. For the CoreWeave side, see SAML SSO and Login methods.Manage programmatic access in each platform
Create and manage API keys and access tokens separately in each platform. Each credential is scoped to the platform that issued it. A CoreWeave API access token grants access on the CoreWeave platform, and a Forge API key grants access in Forge. Rotate and revoke each credential in the platform that issued it.Review and deprovision in both systems
To review a person’s complete access, check both systems. Rotate a user’s credentials in both systems, and deprovision a departing user separately in each system.Multi-tenant Forge deployments
This page describes multi-tenant Forge. W&B Dedicated and W&B Self-Managed deployments keep their existing identity configuration and sign-in pages. See Deployment options.Related
The following pages cover related identity and access topics:- Which access controls apply to your work: Understand which system governs a given resource.
- Identity and access management (IAM): Authenticate and authorize access to CoreWeave platform resources.
- Forge access management: Change a user’s Forge role or product access.
- CoreWeave Infrastructure and Forge billing: Understand which types of charges belong in which billing system and where each billing task belongs.
- What moved in CoreWeave Forge: Find projects, settings, and account locations in Forge if you already use Weights & Biases.