Realms

Realms

Realms define a Nexus Repository user's authentication source. To manage realms, the user requires the nx-settings privilege. Manage realms under the Settings, Security view.

Note
In Nexus Repository Cloud, Sonatype manages Realms. The Realms configuration is not accessible to Cloud users.

The order in which you have your active realms determines what authentication realm is given priority for granting a user access in the event of a name clash between authentication realms.

Available Realms

The table below provides details about each available security realm in the Nexus Repository.

Note
Sonatype pre-configures realms for SaaS deployments. Users need not configure realms in Sonatype Cloud.

Realms Details On-Prem Availability Cloud Availability
Ansible Galaxy Bearer Token Realm
AnsibleGalaxyToken
This realm is required for validating the Ansible collections. See Ansible documentatation.
Conan Bearer Token Realm
ConanToken
This realm is required for uploading to Conan repositories and produces tokens in response to the conan user command.
See Conan's documentation.
Crowd Realm
Crowd
This realm identifies external configuration in an Atlassian Crowd system.
See Atlassian Crowd Support.
Default Role Realm
DefaultRole
This realm appends a specific role to use by default for all users once they are authenticated.
See Default Role.
Docker Bearer Token Realm
DockerToken
This realm is required to access Docker repositories through a Docker client or other container image manager.
It is also required to allow anonymous pull access to Docker repositories.
See Docker Authentication
HuggingFace Bearer Token Realm
HuggingFaceToken
Starting with 3.95, Hugging Face bearer token realm can be used for authentication
See Hugging Face Repositories
LDAP Realm
LdapRealm
This realm identifies external storage in an LDAP identity provider.
See LDAP
Local Authenticating Realm
NexusAuthenticatingRealm
This realm is required to use the built in user management. They allow Nexus Repository to manage authentication without an external identity provider.
Keep the Local Authenticating realm at the top of the active list. In the event of system recovery, restoration is difficult when this realm is lower in order or removed.
npm Bearer Token Realm
NpmToken
This realm permits users with previously generated bearer tokens to publish npm packages. It also allows users to establish the authentication to a repository with the npm adduser (npm login is an equivalent alias) command.
See npm Security
NuGet API-Key Realm
NuGetApiKey
This realm is required for deployments to NuGet repositories.
See NuGet Repositories
OAuth2 Realm
OAuth2Realm
Authenticates users via OAuth2 JWT tokens from a configured OpenID Connect provider, syncing group claims as roles.
See Open ID Connect documentation
OCI Bearer Token Realm
OciBearerToken
This realm is necessary for configuring OCI authentication. See OCI Repositories.
Pub Bearer Token Realm
PubTokenRealm
Validates Dart or Flutter tokens for Pub package operations
See Pub / Flutter documentation
Rut Auth Realm
rutauth-realm
This realm allows the use of any external security system that passes the user details through HTTP headers for requests to Nexus Repository.
See Authentication via Remote User Token
SAML Realm
SamlRealm
This realm uses an external Identity Provider (IdP) to handle authentication.
See SAML
Terraform Realm
TerraformToken
This realm validates base64-encoded or encrypted tokens embedded in Terraform URLs.
See Terraform documentation
#### User Token Realm
User-Token-Realm
This realm is to enable user tokens as a method for authentication that would normally require passing your username and password in plain text.
See Security Setup with User Tokens