> ## Documentation Index
> Fetch the complete documentation index at: https://docs.tokenfactory.nebius.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Set up access

> Create credentials, select a project, verify Sandboxes access, and find a base image.

Complete these steps before running the Python, CLI, or REST examples.

## Create an API key and find the project ID

1. Open the Token Factory [API keys page](https://tokenfactory.nebius.com/project/api-keys), create a key in the project that will run Sandboxes, and save the value when it is shown. The value cannot be opened again later.
2. Open **Project settings** in Token Factory and copy the project ID shown under the project name. [Organizations and projects](/team-access/org-projects) explains project scope; [Groups and access management](/team-access/groups) explains how project membership grants access to resources.

Keep the API key outside source files and sandbox inputs.

## Verify access with the CLI

This diagnostic step is optional for Python and REST users. It gives a quick way to distinguish an accepted credential from a missing Sandboxes permission.

Install [uv](https://docs.astral.sh/uv/getting-started/installation/) if needed, then install CLI 0.9.4 and register a profile:

```bash theme={null}
uv tool install "contree-cli==0.9.4"
export NEBIUS_API_KEY="YOUR_API_KEY"
export NEBIUS_AI_PROJECT="YOUR_PROJECT_ID"
contree auth -y
contree auth ls
```

The profile status distinguishes several setup failures:

| Status | Meaning | Next action |
| - | - | - |
| `ok` | The profile probe succeeded and the required Sandboxes permission is present. | Continue to image discovery. |
| `inactive` | The token was accepted, but the required Sandboxes permission is missing. The project may need Sandboxes activation or the caller may need access. | Ask the project administrator to verify both project activation and the caller's authorization. Contact [contree@nebius.com](mailto:contree@nebius.com) when activation is required. |
| `timeout` | The two-second profile probe did not finish. | Check network access and the configured service URL, then retry. |
| `error` | The probe failed, including invalid credentials or another API error. | Recheck the key and project, then register the profile again. |

For activation help, send the project ID and profile status to [contree@nebius.com](mailto:contree@nebius.com). An `inactive` profile can mean either missing project activation or missing caller permission; do not send the API key.

## Use the correct project variable

| Surface | API key | Project ID | When read |
| - | - | - | - |
| CLI profile registration | `NEBIUS_API_KEY` | `NEBIUS_AI_PROJECT` | `contree auth` reads the values and saves a profile. |
| Python SDK 0.3.6 | `NEBIUS_API_KEY` | `NEBIUS_PROJECT_ID` | The SDK reads the variables when it creates the client. |
| REST examples | `NEBIUS_API_KEY` | `NEBIUS_PROJECT_ID` | The shell expands them into the `Authorization` and `Project` headers. |

For SDK or REST work, export the runtime project variable explicitly:

```bash theme={null}
export NEBIUS_API_KEY="YOUR_API_KEY"
export NEBIUS_PROJECT_ID="YOUR_PROJECT_ID"
```

## Find an image UUID

List images available to the selected project:

```bash theme={null}
contree images
contree images --prefix=alpine
```

The first column is the immutable image UUID. A `tag:NAME` reference is easier to discover, but a tag can later point to another image. Use the UUID in recorded experiments and REST examples.

The Python quickstart uses `alpine:3.19`, and the CLI quickstart uses `ubuntu:latest`. If either tag is absent, select an available image from `contree images` and record its UUID. Replace `"alpine:3.19"` in the Python example with that UUID, or pass the UUID to `contree use` in the CLI example. Choose an image with `/bin/sh` and the commands used by the example.

## Continue

* [Python quickstart](/sandboxes/start/python-quickstart)
* [CLI quickstart](/sandboxes/start/cli-quickstart)
* [Choose an interface](/sandboxes/start/choose-an-interface)
