Skip to main content
When you build a platform on Namespace, your service works on behalf of many customers. Each customer gets its own tenant, and your service needs two kinds of credentials: one that manages all of your tenants, and one that acts inside a single tenant.
No partner account yet? Build on your own workspace with your nsc login while it is set up.

Partner credentials

Your platform is registered with Namespace as a partner. It proves its identity by signing a short-lived token with a private key that only your platform holds. Partner credentials manage tenants: you use them to create, list, update, and delete tenants, set their policies, and issue credentials for them. They do not run workloads themselves. Set up partner credentials

Tenant credentials

A tenant credential acts inside exactly one tenant. Everything created with it, such as instances, builds, and volumes, belongs to that tenant and is invisible to every other tenant. There are two kinds, and they differ in how long they live and how you end their access: Most platforms only need tenant tokens. Your service issues one whenever it acts for a customer and lets it expire. Reach for a revokable token when a credential leaves your service and you need a way to cut off its access. Issue tenant tokens · Create revokable tokens

Which credential does each operation need?

Next steps

Build on your own workspace

Build on your own workspace with your nsc login.

Partner credentials

Sign partner tokens and create a partner client.

Tenant tokens

Act inside a tenant with short-lived tokens.

Revokable tokens

Long-lived tenant credentials you can revoke.
Last modified on October 2, 2026