# Shadow > Shadow is a French cloud computing company founded in 2015 and chaired by OVHcloud founder Octave > Klaba. It streams complete high-end Windows desktops (Shadow PC, Shadow PC Pro), sells > Nextcloud-based storage as Shadow Drive, and sells sovereign GPU compute as Shadow GPU. Shadow GPU > is the only programmable product, and it is programmable only through the standard OpenStack API: > a curated OpenStack 2024.1 deployment across seven regions in France, Germany, the United States > and Canada. Shadow publishes no OpenAPI, no AsyncAPI, no first-party SDK or CLI, no MCP server and > no A2A agent card. GENERATED by API Evangelist on 2026-08-17 from the Shadow public developer surface. Shadow does not publish an llms.txt of its own — https://gpu-instances.shadow.tech/llms.txt returns HTTP 200 but the body is an HTML language-redirect shell, not an llms.txt. ## What is programmable - [Shadow GPU (OpenStack API)](https://gpu-instances.shadow.tech/en/): GPU instances (NVIDIA RTX 2000 Ada, RTX A4500) driven through OpenStack service APIs — Nova (compute), Neutron (networking), Octavia (load balancing), Designate (DNS), Cinder (block storage), Glance (images), Placement, Barbican (secrets), CloudKitty (usage rating). Dashboards are Skyline and, on FRSBG01, Horizon. - Authentication is OpenStack Keystone, not OAuth. The identity endpoint answers anonymously with an Identity API v3.14 version document at `https://auth..os.shadow.tech/v3`. Everything past that needs a token from a domain-scoped password (`user#domain`) or an Application Credential. - The rest of the service catalog is returned only inside an authenticated token response, so per-service endpoints are not publicly enumerable. ## Identity endpoints (probed 2026-08-17, HTTP 200, Keystone v3.14) - FRSBG01 Strasbourg, France: https://auth.frsbg01.os.shadow.tech/v3 — TLS certificate EXPIRED 2026-07-01; a strict-TLS client cannot connect - FRSBG02 Strasbourg, France (Edge): https://auth.frsbg02.os.shadow.tech/v3 - FRDUN02 Dunkirk, France: https://auth.frdun02.os.shadow.tech/v3 - DEFRA01 Frankfurt, Germany: https://auth.defra01.os.shadow.tech/v3 - USWDC01 Washington DC, USA: https://auth.uswdc01.os.shadow.tech/v3 - USPOR01 Portland, USA: https://auth.uspor01.os.shadow.tech/v3 - CAMTL01 Montreal, Canada: https://auth.camtl01.os.shadow.tech/v3 Each region is an independent deployment with its own dashboard. There is no global endpoint and no cross-region API. Credentials are region-scoped. ## Docs - [Shadow GPU documentation](https://gpu-instances.shadow.tech/docs/) - [Getting started](https://gpu-instances.shadow.tech/docs/getting-started/) - [Platform architecture (which OpenStack services are in scope)](https://gpu-instances.shadow.tech/docs/getting-started/architecture/) - [OpenStack CLI configuration](https://gpu-instances.shadow.tech/docs/cli-guide/configuration/) - [Security measures and Application Credentials](https://gpu-instances.shadow.tech/docs/getting-started/security-measures/) - [Project and user management](https://gpu-instances.shadow.tech/docs/getting-started/project-management/) - [User management with the CLI (Adjutant)](https://gpu-instances.shadow.tech/docs/cli-guide/user-management/) - [Regions and endpoints (portal URLs)](https://gpu-instances.shadow.tech/docs/advanced/regions/) - [Storage classes (Wood / Silver / Gold)](https://gpu-instances.shadow.tech/docs/advanced/storage-classes/) - [Instance statuses and the lock mechanism](https://gpu-instances.shadow.tech/docs/advanced/instances-statuses/) - [Feature limitations](https://gpu-instances.shadow.tech/docs/advanced/limitations/) - [Kubernetes Cluster API on Shadow](https://gpu-instances.shadow.tech/docs/gpu-paas/cluster-api/) - [FAQ](https://gpu-instances.shadow.tech/docs/faq/) - Upstream API reference Shadow points at: https://docs.openstack.org/api-ref/ and https://docs.openstack.org/2024.1/user/ ## Commercial - [Pricing and cost simulator](https://gpu-instances.shadow.tech/en/#pricing) — Pay as you go (per-minute), Monthly plan (fixed, quota overage billed), Enterprise (negotiated quotas and SLAs). RTX 2000 Ada from €0.29/h (≈ €220/month); RTX A4500 from €0.35/h (≈ €250/month). Spot / On Demand / Dedicated 24/7 availability models. - No self-service signup. Access is requested through a "Talk to an expert" form; the page advertises 24h activation. An autonomous agent cannot onboard itself. - [Terms of use](https://shadow.tech/us/terms-of-use/) - [Privacy policy](https://shadow.tech/us/privacy-policy/) ## Operations - [Status page (Status.io)](https://status.shadow.tech/) — RSS at https://status.shadow.tech/pages/5bbcb1b0b0936904c004bbeb/rss. Tracks Shadow PC, Shadow Drive, the shared web services and the data centres; it has NO Shadow GPU / OpenStack component. - [Help centre (Zendesk)](https://support.shadow.tech/hc/en-us) - No public SLA, no changelog or release-notes page, no deprecation policy, no error-code reference. ## API Evangelist artifacts in this repository - apis.yml — the APIs.json profile - authentication/shadow-authentication.yml — Keystone password + Application Credential model, roles, identity endpoints - conventions/shadow-conventions.yml — services in scope, instance state machine, storage classes, what is NOT documented - conformance/shadow-conformance.yml — standards assessed with evidence - lifecycle/shadow-lifecycle.yml — status page, versioning, SLA posture, retired surfaces - plans/shadow-plans-pricing.yml — the three billing models and per-configuration prices - rate-limits/shadow-rate-limits.yml — quota model; no published request-rate limits - packages/shadow-packages.yml — zero first-party SDKs; the upstream OpenStack packages Shadow's docs tell you to install - cli/shadow-cli.yml — the documented command surface (upstream openstack CLI, not first-party) - mcp/shadow-mcp.yml — searched absence of any MCP server - well-known/shadow-well-known.yml — the /.well-known probe, including two false-positive traps - security/shadow-domain-security.yml — TLS/HSTS/DNS probe ## What Shadow does not publish - No OpenAPI, Swagger, GraphQL SDL or AsyncAPI document on any host - No first-party SDK in any language, and no GitHub organisation - No MCP server (hosted or stdio) and no A2A agent card - No llms.txt, no /.well-known/api-catalog, no security.txt of its own - No error-code reference, no request-rate limits, no idempotency contract - The former developer portal at developers.shadow.tech now 403s and redirects to the help centre; business.shadow.tech returns 401