Your packages. Your server. Your rules.
NuGetKeep is a self-hosted, enterprise NuGet server with supply-chain quarantine, SSO, and isolated feeds — shipped as a single Docker image you run anywhere, even air-gapped.
curl -fsSL https://nugetkeep.com/install | bash NuGetKeep is installed and running. Everything an enterprise feed needs
And a lot more — see all 18 features.
Trusted publishing Enterprise
Keyless, OIDC-based pushes from CI — no long-lived API keys to leak.
Docs: Trusted publishingSymbols server
Push .snupkg symbol packages and step into your own libraries — portable PDBs indexed and served to your debugger.
Supply-chain quarantine Enterprise
Every pushed package is OSV-scanned; vulnerable versions are quarantined before anyone can restore them.
Docs: Supply-chain quarantineHealth insights & dependency graph
Per-package health grades, transitive dependency graphs, and feed-wide risk and download totals — see trouble before it ships.
Multiple isolated feeds Enterprise
Separate teams and trust boundaries into independent, access-controlled feeds.
Docs: Multiple isolated feedsMCP tools for AI Enterprise
Model Context Protocol tools for AI assistants: read tools for everyone (search, health, secure versions), plus gated write tools like request_publish for Publisher/Admin keys.
Docs: MCP tools for AISecurity that runs where your code does
Gate every upload through an OSV supply-chain scan, keep packages on your own infrastructure, and run fully air-gapped. No data leaves your network — licensing is offline too.
How the security gate worksSee it running
The same admin UI you'll ship — not a mockup.
A full admin experience
Licensing, supply-chain health, trusted publishing, scoped keys, MCP, and multi-feed — all in the same fast UI.