JFrog Artifactory

JFrog Artifactory is JFrog Ltd's universal software artifact repository, used as the single registry for Maven, npm, Docker, PyPI, NuGet, Go, Helm, Debian, RPM and Terraform packages, container images and machine learning models, with native support for over 50 package types. It comes in two deployment models with distinct licensing: managed by JFrog and charged by consumption, or installed on the customer's own infrastructure and charged per server.

Learn more about JFrog Artifactory

Request a Quote

What is JFrog Artifactory?

JFrog Artifactory is JFrog Ltd's universal software artifact repository, used as the single registry for everything engineering produces and consumes: Maven, npm, Docker, PyPI, NuGet, Go, Helm, Conan, Debian, RPM and Terraform packages, container images, Helm charts and machine learning models, with native support for over 50 package and file types, according to JFrog.

It solves two problems at once. The first is organizational: without a central point, each team adopts a tool per language and nobody can say which binary reached production or where it came . The second is external dependency: Artifactory proxies public registries, caching packages locally, which prevents build failures when the source goes down and creates the single point where curation and vulnerability analysis become applicable.

This page is the product overview. Artifactory is sold in two deployment models with different licensing metrics, and each has its own page covering editions, requirements and counting rules: JFrog Artifactory Cloud, managed by JFrog, and JFrog Artifactory Self-Hosted, installed on the customer's infrastructure.

Key features of JFrog Artifactory

  • Universal repository — over 50 native package types, with single URL resolution, covering the Java, JavaScript, Python, Go, .NET, C/C++ and infrastructure-as-code ecosystems.
  • Container registry — layer-based Docker and OCI image management that optimizes transfer and scanning, with public Docker Hub pulls through the platform.
  • ML Model Registry — machine learning model versioning with Hugging Face proxying, treating AI assets as versioned artifacts.
  • Checksum-based storage — writes each file or image layer once, even when it appears across several repositories in the organization.
  • Artifact Federation — synchronization across federated repositories in different sites, available in the enterprise editions.
  • Enterprise access control — identity integration via SAML, SCIM, OIDC, OAuth and LDAP, with granular RBAC permissions per project.
  • Automation — REST API, Artifactory Query Language (AQL), JFrog CLI and a Terraform provider for artifact publishing and promotion.
  • Foundation of the JFrog Platform — it is the prerequisite for JFrog Xray, JFrog Curation, JFrog ML and JFrog Connect, which all operate on the same repository.

Benefits of JFrog Artifactory

Predictable builds because external dependencies stay cached: if the public registry goes down, the build resolves the local copy instead of failing.

Storage kept in check by checksum-based storage, which eliminates duplicate copies of the same binary across different repositories.

Governance written once because a single service covers every ecosystem — access policy and auditing stop being replicated in one tool per language.

A path open to supply chain security because vulnerability analysis and package curation happen inside the repository itself, with no need to export artifacts to an external tool.

Who JFrog Artifactory is for

Artifactory serves platform, DevOps and release engineering teams that own the build chain and the CI/CD environment, plus IT leaders who need to consolidate scattered registries and answer for release traceability.

In practice, the recurring trigger is the organization that grew with one registry per language — one for npm, another for Maven, another for Docker — and reached the point where auditing what runs in production means checking three or four systems with independent access policies.

Cloud or Self-Hosted: how to choose

The choice between the two models defines the licensing metric and therefore precedes any quote.

The managed model makes sense when the priority is reducing infrastructure operations: JFrog takes on patching, scaling and high availability, and the customer picks provider and region — there are two São Paulo regions, one on AWS and one on Azure. It is the usual path for a new purchase.

The self-managed model makes sense when the requirement is control: local retention policy, a network with no internet egress, or ownership of the database, filestore and upgrade window. It is also the model supporting air-gapped operation.

The two topologies coexist: the enterprise editions upwards, a managed instance connects to on-premise installations in the same logical environment, with artifact synchronization across sites.

Requirements and supported environments

In the managed model, access is through a browser and the command line, with no server requirement on the customer side, running across roughly 30 locations spread over AWS, Microsoft Azure and Google Cloud. In the self-managed model, Artifactory runs on RHEL 8 and 9, Ubuntu 22.04 and 24.04, Debian 11 and 12 and Windows Server 2022, installed via Helm, Docker, Docker Compose, RPM, Debian package, Linux Archive or Ansible, over PostgreSQL 13 to 17, Oracle, MySQL 8, Microsoft SQL Server or MariaDB. JFrog states a minimum of 8 GB RAM in production.

Named integrations cover Jenkins, GitHub Actions, GitLab, Azure DevOps, Kubernetes and Helm. JFrog CLI and the IDE plugins run on Windows, Linux and macOS.

JFrog Artifactory editions

Editions vary by deployment model. In self-managed, OSB Software supplies Pro X, Enterprise X and Enterprise +; in managed, Enterprise X and Enterprise +, all on annual contracts.

What changes between them is the number of servers or included consumption base, high availability, Artifact Federation, Access Federation, edge nodes, project count and support level. The full matrix sits on each model's page. JFrog also offers free non-commercial licenses, such as JFrog Container Registry and Artifactory OSS, which include neither integrated security nor support and fall outside corporate supply.

How much does JFrog Artifactory cost?

It depends on the deployment model, because the two licensing metrics are different — and that is the first question in any sizing exercise:

  • Artifactory Cloud — licensed by consumption, which JFrog defines as storage and data transfer combined, in GB, with a base included per edition. Detail and rules on the JFrog Artifactory Cloud page.
  • Artifactory Self-Hosted — licensed per server, with a server base included per edition and its own counting rule for high availability clusters. Detail on the JFrog Artifactory Self-Hosted page.

In both cases the model is an annual subscription, with a multi-year option on the enterprise editions, and the investment depends on sizing: chosen model, edition, contracted volume, additional security and governance modules, term and whether it is a new purchase or a renewal. To buy JFrog Artifactory in Brazil, OSB Software maps that scope with you, sends the commercial proposal, issues the Brazilian invoice and delivers the licenses — request a quote to get the exact figure for your scenario.

Frequently asked questions about JFrog Artifactory

What is the difference between Artifactory Cloud and Self-Hosted? Cloud is operated by JFrog on AWS, Azure or Google Cloud and charged by consumption; Self-Hosted is installed on the customer's infrastructure and charged per server. The choice changes the metric, the requirements and the quoting process.

Which package formats does Artifactory support? Over 50 natively, among them Maven, npm, Docker, OCI, PyPI, NuGet, Go, Helm, Conan, Debian, RPM and Terraform, plus machine learning models.

Do I need Artifactory to use JFrog Xray? Yes. Xray analyzes artifacts stored in Artifactory, and the same applies to JFrog Curation, JFrog ML and JFrog Connect — all operate on the platform and none is sold standalone.

Does Artifactory replace the registry built into my cloud provider? It can replace or coexist. The difference is breadth: provider registries cover a slice of formats, while Artifactory unifies every ecosystem under a single access and audit policy.

Why buy JFrog Artifactory OSB Software?

OSB Software is an official JFrog Ltd partner in Brazil and supplies 100% genuine JFrog Artifactory licenses to companies, with Brazilian invoicing, local contracting in Portuguese and full legal compliance — the safe way to buy imported software under a Brazilian corporate entity, with no risk of irregular licensing.

When you buy JFrog Artifactory OSB Software, you get:

  • Consultative, specialist support — specialists who size your consumption or per server licensing to your actual operation, avoiding over- or under-buying.
  • Fast, secure processes — purchase order to delivery of genuine licenses, traceable at every step.
  • Dedicated commercial follow-up — quote to delivery and renewal, with advance notice before your license expires.
  • Invoicing that fits your company — Brazilian invoicing and terms adapted to your corporate procurement process.
  • Proven track record — thousands of customers served across Brazil.

If you are looking for where to buy JFrog Artifactory in Brazil with legal certainty and properly licensed imported software, request a quote: OSB Software delivers reliable technology, qualified support and a simple, transparent purchase.

You don't know what software you need or you haven't found what you were looking for?

You don't know what software you need or you haven't found what you were looking for? We have a team ready to help you choose the right software for your company.