
VoltageGPU CLI
Confidential VMs (Intel TDX) and standard GPU pods from your terminal or from Python
What it does
The CLI is a thin client of the public Volt API. It deploys two kinds of machine: Confidential VMs, Intel TDX trust domains with an NVIDIA GPU where only your SSH keys are installed and the attestation is generated and verified by you, and standard pods, whole GPU machines without an enclave for workloads that are not sensitive.
Billing is per second. The first hour is charged when you deploy; when you stop a standard pod, the unused part of that hour goes back to your balance.
Quick Start
pip install voltagegpu-cli voltagegpu login # paste a key from voltagegpu.com/api-keys (hidden, checked, saved 0600) voltagegpu ssh-keys add # uploads ~/.ssh/id_ed25519.pub voltagegpu machines --standard # cheapest first, with the price you are charged voltagegpu deploy standard --machine <machine_id> --wait voltagegpu ssh <pod_id> voltagegpu pods stop <pod_id> # billing stops, unused prepaid seconds refunded
Create your API key at voltagegpu.com/api-keys. The command is voltagegpu; volt is kept as an alias.
Features
Deploy
- Standard pods by machine id, or
--cheapest - Confidential VMs by tier, with hard stop and inbound ports
- Price shown and confirmed before any charge
Connect and stop
voltagegpu pods waituntil SSH answersvoltagegpu sshruns ssh for you, no shell involvedvoltagegpu pods stopreports the refund
Verify
voltagegpu verify bundle.jsonruns voltage-verify- Intel TDX quote and NVIDIA GPU attestation, checked on your machine
Script it
--jsonon every list,--yeson deploy and stop- Exit codes: 0 success, 1 API error, 2 usage error
- Typed Python SDK in the same package
Installation
pip install voltagegpu-cli pip install "voltagegpu-cli[verify]" # also installs voltage-verify for `voltagegpu verify`
From source
git clone -b release/1.3 https://github.com/VoltageGPU/VOLTAGEGPU-CLI.git cd VOLTAGEGPU-CLI pip install -e ".[dev]" pytest
Requirements
- Python 3.10 or newer (tested on 3.10 to 3.14)
- An OpenSSH client for
voltagegpu ssh
Configuration
# Interactive: prompts (hidden), checks the key with the API, writes ~/.volt/config.ini (mode 0600) voltagegpu login # CI and scripts: environment variable (wins over the file) export VOLT_API_KEY=volt_... # Where does the key come from? (masked) voltagegpu config # Remove the stored key voltagegpu logout
Commands
Machines and templates
voltagegpu machines # Confidential VM tiers, then standard machines voltagegpu machines --standard --gpu A6000 # filter by GPU model voltagegpu machines --standard --max-price 1 --json voltagegpu machines --confidential voltagegpu templates # images for standard pods (PyTorch by default)
Deploy a standard pod
voltagegpu deploy standard --machine <machine_id> voltagegpu deploy standard --cheapest --gpu 4090 --wait voltagegpu deploy standard --machine <machine_id> --template <template_id> \ --ssh-key <key_id> --jupyter --ports 3 --auto-terminate 8 --yes
A standard pod is a whole machine without an enclave. If your account has several SSH keys, pick one with --ssh-key. Same call by REST: Standard Pods.
Deploy a Confidential VM
voltagegpu deploy confidential --tier rtx6000b-small --wait voltagegpu deploy confidential --tier h100-small --hardstop 4 --port 8000 --port 8443/tcp
Every SSH key on your account is bound to the VM at creation and a VM cannot be given a key later, so add yours first. The sudo password is printed once and kept nowhere. The output also lists the commands that produce the attestation bundle inside the VM. Inbound ports work on single-GPU tiers. See Confidential VM.
Pods and SSH
voltagegpu pods list voltagegpu pods show <pod_id> voltagegpu pods wait <pod_id> # until SSH answers voltagegpu ssh <pod_id> # interactive shell voltagegpu ssh <pod_id> -- nvidia-smi -L # one command voltagegpu ssh <pod_id> -o StrictHostKeyChecking=accept-new -- nvidia-smi # scripts voltagegpu ssh <pod_id> --print # print the ssh command only voltagegpu pods stop <pod_id> # release: billing stops, the disk is deleted
SSH keys
voltagegpu ssh-keys list voltagegpu ssh-keys add # ~/.ssh/id_ed25519.pub by default voltagegpu ssh-keys add --name laptop --file ~/.ssh/id_rsa.pub voltagegpu ssh-keys add --name ci --key "ssh-ed25519 AAAA..." voltagegpu ssh-keys delete <key_id>
Balance
voltagegpu balance voltagegpu balance --json
Verify a Confidential VM
voltagegpu verify bundle.json --offline voltagegpu verify bundle.json --challenge <hex-you-issued> --gpus 1 voltagegpu verify quote quote.bin
voltagegpu verify runs voltage-verify, which checks the Intel TDX quote up to Intel's root and the NVIDIA attestation tokens without trusting us.
Scripting
POD=$(voltagegpu deploy standard --cheapest --max-price 1 --yes --json | jq -r .deploy.pod_id) voltagegpu pods wait "$POD" voltagegpu ssh "$POD" -o StrictHostKeyChecking=accept-new -- nvidia-smi voltagegpu pods stop "$POD" --yes
Python SDK
from volt.sdk import VoltageGPUClient
with VoltageGPUClient() as client: # VOLT_API_KEY or ~/.volt/config.ini
machine = client.list_machines("standard")[0] # cheapest first
result = client.deploy_standard(machine.id, name="my-pod")
pod = client.wait_until_reachable(result.pod_id)
print(pod.ssh_command)
print(client.release_pod(result.pod_id).prepaid_refund)| Method | Description |
|---|---|
list_machines(kind) | "all", "standard" or "confidential", with the price charged |
list_templates() | Images for standard pods |
deploy_standard(machine_id, name, ...) | Deploy a standard pod |
deploy_confidential(tier, name, ...) | Deploy a Confidential VM; returns the one-time sudo password |
list_pods() / get_pod(id) | Your running pods |
wait_until_reachable(id) | Poll until the SSH command is usable |
release_pod(id) | Stop and release; returns the refunded prepaid amount |
list_ssh_keys() / add_ssh_key() / delete_ssh_key() | SSH keys |
get_balance() | Balance and running pod count |
Environment Variables
| Variable | Description | Default |
|---|---|---|
VOLT_API_KEY | Your API key (VOLTAGEGPU_API_KEY also works) | - |
VOLT_BASE_URL | API base URL, https only | https://api.voltagegpu.com/api |
VOLT_DEBUG | 1 shows tracebacks | - |
Upgrading from 1.2
volt cc inventoryandvolt cc deploy: Confidential containers were retired on 2026-10-01. Usevoltagegpu machines --confidentialandvoltagegpu deploy confidential --tier <tier>.volt pods stopnow releases the pod and prints the refund;pods deleteandpods getstill work as aliases.volt account balanceis nowvoltagegpu balance.- Python 3.10 or newer is required.
Links
Deploy, connect, verify, from your terminal
Made by the VoltageGPU Team