# Verified organizations

URL: https://chainguard-docs-preview-git-tpguardener-image-suggestions-docs.chainguard.app/platform/administration/iam-organizations/verified-orgs.md
Last Modified: September 28, 2026
Tags: Chainguard Console, Conceptual

An overview of how to verify your organization and the implications

The Chainguard platform organizes resources in a hierarchical structure called IAM organizations. A customer typically uses one root-level organization to manage its Chainguard resources.
About verified organizations A verified organization is a root-level organization whose name Chainguard has confirmed and reserved for you. Only one organization on the Chainguard platform can hold a given verified name. Because of that, you can use the name anywhere you would otherwise use the organization&rsquo;s unique ID.
Verifying your organization lets you:
Pull container images from a readable path, such as cgr.dev/example.com/python, instead of cgr.dev/&lt;org_id&gt;/python. Log in through your custom identity provider by entering your organization name. This works in chainctl, the Chainguard Console, and the Terraform provider, so users don&rsquo;t need your identity provider&rsquo;s ID. Request new container images in the Chainguard Console. Currently, Chainguard verifies customer organizations manually, typically while setting up your organization during onboarding. If you want to try Chainguard Containers before becoming a customer, refer to Chainguard Catalog Starter.
Check whether your organization is verified You can check whether your organization is verified using chainctl. The following command uses jq to filter the JSON output down to each organization&rsquo;s name and verification status.
chainctl iam organization ls -o json | jq &#39;.items[] | {name, verified}&#39;A verified organization has the field &quot;verified&quot;: true. The output for an unverified organization doesn&rsquo;t include the verified field, so jq prints null.
{ &#34;name&#34;: &#34;example.com&#34;, &#34;verified&#34;: true } { &#34;name&#34;: &#34;example-unverified-org&#34;, &#34;verified&#34;: null }If your organization isn&rsquo;t verified, ask your Chainguard account team or support to verify it.
Log in with your organization name If you&rsquo;ve configured a custom identity provider and your organization is verified, you can select your identity provider by entering your organization name when you log in.
When authenticating with chainctl, pass the --org-name flag. This example uses the organization name example.com.
chainctl auth login --org-name example.comAs an alternative, you can set the organization name by editing the chainctl configuration file with the following command.
chainctl config editThis command opens your system&rsquo;s default text editor, where you can edit the local chainctl configuration. Add the following lines to this file.
default: org-name: example.comYou can also set this with a single command using the chainctl config set subcommand, as in this example.
chainctl config set default.org-name example.comAfter you set the organization name, chainctl auth login uses the configured identity provider automatically.
When you log in to the Chainguard Console, the Console detects your organization name from your email address in most cases. If your organization name doesn&rsquo;t match your email domain, enter it manually to select your custom identity provider.
Pull images by organization name If your organization has access to Chainguard Containers, its container images are in a private repository within the Chainguard registry. You can pull them from cgr.dev/&lt;org_id&gt;/&lt;image_name&gt;, where &lt;org_id&gt; is your organization&rsquo;s unique ID. After Chainguard verifies your organization, you can use its name in place of the ID. For example, if your verified organization is named example.com, you can pull private images with a command like docker pull cgr.dev/example.com/&lt;image_name&gt;.
Restrictions for verified organizations A verified organization&rsquo;s name works interchangeably with its unique ID. Changing the name can break image pulls from your organization&rsquo;s repository within the Chainguard registry, and it can break authentication for users who log in to your custom identity provider by organization name. For that reason, you can&rsquo;t rename a verified organization yourself. To rename it, contact support.

