# Pull Gradle dependencies from CloudRepo

> Point Gradle at CloudRepo with a repository token, resolve dependencies from it, keep your own groups off other repositories, and fix a 401, 403 or 404.

Gradle reads CloudRepo as a Maven repository: the same URL, and a repository token for the credential. This page is for the person whose build pulls from a repository. To put artifacts there, see [Publish Maven artifacts](/docs/formats/maven.html).

You need a Maven repository and a repository token that reaches it. If you have neither yet: [create a repository](/docs/manage/repositories.html#creating-a-repository) and [create a token](/docs/authenticate/repository-tokens.html). A token that is **Read only** is enough to pull.

## Point Gradle at the repository

1. Keep the credential in `~/.gradle/gradle.properties`, outside your project, so it is never committed. The username is the email address of the account that created the token, and the password is the token.

   `~/.gradle/gradle.properties`

   ```properties
   cloudrepoUsername=you@example.com
   cloudrepoToken=YOUR_REPOSITORY_TOKEN
   ```

2. Declare the repository and a dependency in your build script, reading the credential from those two properties.

   `build.gradle.kts`

   ```kotlin
   plugins {
       `java-library`
   }


   repositories {
       maven {
           url = uri("https://your-org.mycloudrepo.io/repositories/your-repo")
           credentials {
               username = providers.gradleProperty("cloudrepoUsername").get()
               password = providers.gradleProperty("cloudrepoToken").get()
           }
       }
       mavenCentral()
   }


   dependencies {
       implementation("com.example:my-library:1.0.0")
   }
   ```

   The repository URL is `https://<organization>.mycloudrepo.io/repositories/<repository>`: your organization’s name, then the repository’s name as the admin portal shows it. A Groovy build script takes the same block:

   `build.gradle`

   ```groovy
   repositories {
       maven {
           url = "https://your-org.mycloudrepo.io/repositories/your-repo"
           credentials {
               username = findProperty("cloudrepoUsername")
               password = findProperty("cloudrepoToken")
           }
       }
       mavenCentral()
   }


   dependencies {
       implementation "com.example:my-library:1.0.0"
   }
   ```

3. Build.

   **Terminal**

   ```bash
   gradle build
   ```

   Expected: `BUILD SUCCESSFUL`, with `my-library` resolved from your CloudRepo repository.

## In CI

Keep the credential in your CI’s secret store, and hand it to Gradle through the environment. Gradle turns an environment variable named `ORG_GRADLE_PROJECT_` plus a property name into that project property, so no file is written:

**Terminal**

```bash
export ORG_GRADLE_PROJECT_cloudrepoUsername="you@example.com"
export ORG_GRADLE_PROJECT_cloudrepoToken="$CLOUDREPO_TOKEN"
gradle build
```

## Keep your own groups off other repositories

A dependency whose name exists on Maven Central and on your repository is fetched from whichever repository Gradle asks first. If a group of yours must come only from CloudRepo, tell Gradle that this repository holds it exclusively:

`build.gradle.kts`

```kotlin
repositories {
    exclusiveContent {
        forRepository {
            maven {
                url = uri("https://your-org.mycloudrepo.io/repositories/your-repo")
                credentials {
                    username = providers.gradleProperty("cloudrepoUsername").get()
                    password = providers.gradleProperty("cloudrepoToken").get()
                }
            }
        }
        filter {
            includeGroup("com.example")
        }
    }
    mavenCentral()
}
```

Gradle then looks for artifacts of `com.example` only in that repository, and never asks it for any other group. See [Gradle’s documentation on exclusive content](https://docs.gradle.org/current/userguide/declaring_repositories.html#declaring_content_exclusively_found_in_one_repository).

## When Gradle answers 401, 403 or 404

Gradle reports the status it received. Check these in order:

- **401 Unauthorized.** The credential was refused. The username must be the email address of the account that created the token, and the password the token itself. A token that is expired or revoked fails the same way: the **Repository Tokens** page in the admin portal shows its status. In the Kotlin form above, a property that Gradle cannot find fails before any request, with Gradle’s own message.
- **403 Forbidden.** The token does not reach this repository. A token reaches only the repositories ticked when it was created, so use one that includes it.
- **404 Not Found.** The path is wrong: check the organization and repository names in the URL, and the group, artifact and version of the dependency. A proxy repository that the token does not reach also answers `404`, not `403`.

More: [Repository tokens](/docs/authenticate/repository-tokens.html), for every client’s credential; [Proxy repositories](/docs/consume/proxy-repositories.html), to pull Maven Central or another public repository through CloudRepo.

---

The page: https://www.cloudrepo.io/docs/consume/gradle.html
