---
title: "STACKIT Notebooks"
description: "Managed JupyterLab environments running on isolated pods for interactive data exploration, analytics, and machine learning."
scfAsset:
  category: "service"
  managed: true
  marketplaceUrl: "https://marketplace.stackit.cloud/en/products"
  tags: ["Jupyter", "Data Science", "Python", "Data and AI", "Analytics"]
  maintainers:
    - user: "alexander.gabert"
source_url: "https://framework.stackit.cloud/data-and-ai/assetcontainer/stackit/stackit-service-notebooks/"
source_file: "docs/data-and-ai/assetcontainer/stackit/stackit-service-notebooks.mdx"
---

STACKIT Notebooks delivers ready-to-use JupyterHub/JupyterLab environments for data engineering, interactive analytics, and prototyping.

## Service Overview
- **Zero Administrative Setup**: Provision pre-configured Python environments in minutes.
- **Isolated Pod Execution**: Each session runs inside a secure, dedicated Kubernetes pod.
- **Integrated Tooling**: Pre-built support for Git integration, Spark jobs, and data science libraries.

## Technical Details
- **Access Control**: Role-based authentication integrated via OIDC.
- **Persistence**: Workspaces mount persistent storage volumes to preserve code and custom packages across sessions.
- **Data Sovereignty**: Operated inside certified German data centers in accordance with GDPR.

## Identity Provider

The values below come from the STACKIT documentation and update themselves.

> From the STACKIT docs: [Create and manage instances for Notebooks › External Identity Provider (IdP)](https://docs.stackit.cloud/products/data-and-ai/notebooks/how-tos/create-and-manage-instances-for-notebooks/#external-identity-provider-idp) (Source updated 27.03.2026, copied 05.10.2026)

As for now, Notebooks depends on an external Identity Provider for authentication, authorization and single-sign-on. It uses the OpenID Connect protocol. The following IdPs are supported:

- Azure
- Google
- Okta
- AWS Cognito
- Keycloak

To integrate an IdP, you need to provide the `Client ID`, the `Client secret`, the `Scope` and the `Discovery Endpoint`. You need to get these values from the respective provider.

The values for **Scope** are in most cases `openid email`, for EntraID it is `openid email User.Read`.

The format for a **Discovery Endpoint** is `https://\<provider-domain\>/.well-known/openid-configuration`.

## Limitations & Constraints
- **Restart Required for Scaling**: Changing instance sizes or attached GPUs requires stopping and restarting the notebook instance.
- **Ephemeral Root Storage**: Files saved outside the mounted persistent volume directory are erased upon pod restart.
- **No Headless Background Execution**: Sessions automatically shut down during inactivity, terminating long-running background training scripts.

<LinkCard title="STACKIT Notebooks Overview" href="https://docs.stackit.cloud" />
