Manage AI and Software Artifacts at Scale
Ensure developers and agents have uninterrupted access to trusted,
governed artifacts to accelerate autonomous software delivery
Artifact management the way it should be
Manage every artifact and release
in a single place
60+ artifact types: packages, files, and AI assets
100s of ecosystem integrations
Multiple installation and deployment options
Pre-vetted IDE extensions, agent plugins, skills, and MCP servers
Effortlessly scale your SDLC
across multiple sites
Premium 99.99% in-region uptime SLA
Automated bi-directional repository sync
Synchronize policy, assets, and access across multiple sites
Project-based resource management
Fully managed SaaS, self-managed, multi-cloud, and hybrid support
Lay the foundation for a secure software supply chain
Proxy public registries and AI model hubs, preventing direct download from the internet
Robust RBAC and governance policies
Enterprise platform security (SSO, PrivateLink, etc.)
Identify and block vulnerable packages, IDE extensions, and AI assets from use
Improve build speeds and
accelerate CI/CD pipelines
Dependency and build caching
Open-source JFrog CLI
Rest APIs for nearly everything
Custom plugins with robust event triggers
Deliver enterprise performance while optimizing costs
Checksum optimized storage and replication
Automated cleanup and asset archival
Location based DNS routing
Manage every artifact and release
in a single place
60+ artifact types: packages, files, and AI assets
100s of ecosystem integrations
Multiple installation and deployment options
Pre-vetted IDE extensions, agent plugins, skills, and MCP servers
Effortlessly scale your SDLC
across multiple sites
Premium 99.99% in-region uptime SLA
Automated bi-directional repository sync
Synchronize policy, assets, and access across multiple sites
Project-based resource management
Fully managed SaaS, self-managed, multi-cloud, and hybrid support
Lay the foundation for a secure software supply chain
Proxy public registries and AI model hubs, preventing direct download from the internet
Robust RBAC and governance policies
Enterprise platform security (SSO, PrivateLink, etc.)
Identify and block vulnerable packages, IDE extensions, and AI assets from use
Improve build speeds and
accelerate CI/CD pipelines
Dependency and build caching
Open-source JFrog CLI
Rest APIs for nearly everything
Custom plugins with robust event triggers
Deliver enterprise performance while optimizing costs
Checksum optimized storage and replication
Automated cleanup and asset archival
Location based DNS routing
Over 6,500 DevOps Teams Trust JFrog
Create an unified agentic software supply chain
Proxy Hugging Face, Nvidia NGC, and other AI model sources
Manage private models with a simple SDK
Enterprise registries for MCP servers and agent assets
Automatically route AI coding agents through Artifactory for secure, governed access
Simplify auditing and governance across the SDLC
Immutable release context, tracking, and auditing
Security policy and promotion gating
Attestation and evidence capture
Supercharge secure developer and agent workflows
Powering enterprise software development lifecycles
Curated Artifacts, IDE Extensions, and AI Assets
The Trusted Source for
Curated Artifacts, IDE Extensions, and AI Assets
Enhance the Integrity, Reliability, and Speed of CI/CD
Ensure Constant Shared Access for Distributed Teams
Serve Components to Production Runtimes
Additional JFrog Artifactory Resources
Frequently Asked Questions
Artifactory is universal, meaning it supports a wide variety of package formats and file, including Maven (Java), npm (Node.js), PyPI (Python), Docker, Helm, NuGet (.NET), Debian, RPM, Terraform, ML Models, and many more.
The method for uploading depends on the package type. Typically, you'll use command-line tools specific to your package manager (like ‘npm publish’ for npm) configured to point to your Artifactory repository. Artifactory also provides a web interface for manual uploads.
Similar to uploading, downloading depends on the package type. Your build tools or package managers will be configured to resolve dependencies from your Artifactory repositories. For example, a Maven project will declare dependencies in its pom.xml file, and Maven will download those artifacts from the configured Artifactory repository.
Yes, Artifactory is designed to integrate seamlessly with popular CI/CD tools like Jenkins, GitHub Actions, Azure DevOps and many more. This integration allows for automated artifact resolution and deployment as part of your build and release pipelines.
Artifactory offers robust access security features, including user and group management, permission control (read, write, delete), and integration with external authentication systems (like LDAP or SAML). This allows you to control who can access and modify your artifacts. The JFrog Platform also provides end-to-end application and software supply chain security solutions natively integrated with Artifactory. With JFrog Artifactory security professionals have one place to security policies and govern the usage of software components across dev teams.
Artifactory helps streamline your software development process by providing a single source of truth for all your artifacts. This improves collaboration, ensures consistency, speeds up builds, and makes it easier to manage dependencies and track software releases.
Yes, JFrog SaaS provides our cloud-native platform as a hosted and managed service available on your choice of AWS, Azure and GCP regions.
Yes, Artifactory provides Docker and OCI registries that allows you to store and manage your container images securely. It also manages Helm Charts, Terraform/Open Tofu files, Ansible and more to make it easy to deploy to dynamic runtime environments.
Yes, Artifactory is an advanced Model Registry. It supports caching models from Hugging Face and also manages in-house built custom models.
Yes, all JFrog products including Curation, Xray, and JFrog ML are natively integrated with Artifactory as part of the JFrog Software Supply Chain Platform
Artifactory provides robust options to power automation across your pipelines including APIs across the platform, the JFrog CLI, and Terraform provider.
Yes, you can. Artifactory serves as a managed repository for IDE extensions and plugins, providing a powerful caching layer. With the added power of JFrog Curation, organizations can use automated policies to vet every extension, ensuring only secure, pre-approved tools are available and blocking those with known vulnerabilities or licensing issues.
The JFrog Platform and Artifactory is a highly available solution with a Premium Availability uptime SLA of 99.99%. Customers self-managing the JFrog Platform can deploy in HA clusters to achieve their desired level of resilience.
Yes, you can manage and version all your first-party Agent Skills in JFrog Artifactory with full role based access controls.
Artifactory manages AI/ML models, MCP servers, Agent Skills, Agent Plugins, and Agent Packages, each with role-based access, versioning, and integrated governance.
Agent Plugins repositories allow you to index, search, and securely store and distribute your organization's plugins. With plugins as a package type in Artifactory, versioning is enforced at the binary level and immutability and provenance are guaranteed.
Agent Package repositories are the Artifactory package type that backs APM (Agent Package Manager). They store agent primitives: skills, prompts, instructions, hooks, commands, scripts, and MCP server declarations as versioned, governed packages. Developers declare dependencies in apm.yml, and apm install resolves them from the repository with a lock file for reproducibility. See the JFrog blog on APM for more.
Agent Package Resolution, a feature of JFrog Plugins for AI coding agents automatically routes packages pulled by these agents through Artifactory, applying the same security and governance policies already in use for human developers. Available to all JFrog customers.