> ## Documentation Index
> Fetch the complete documentation index at: https://namespace.so/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Authentication for Platforms

> How a platform authenticates to Namespace as a partner, and how it acts on behalf of each of its customers.

When you build a platform on Namespace, your service works on behalf of many customers.
Each customer gets its own [tenant](/docs/platform/tenants), and your service needs two kinds of credentials: one that manages all of your tenants, and one that acts inside a single tenant.

<Tip>
  No partner account yet? [Build on your own workspace](/docs/platform/authentication/local-development) with your `nsc login` while it is set up.
</Tip>

## Partner credentials

Your platform is registered with Namespace as a partner.
It proves its identity by signing a short-lived token with a private key that only your platform holds.

Partner credentials manage tenants: you use them to create, list, update, and delete tenants, set their policies, and issue credentials for them.
They do not run workloads themselves.

[Set up partner credentials](/docs/platform/authentication/partner-credentials)

## Tenant credentials

A tenant credential acts inside exactly one tenant.
Everything created with it, such as instances, builds, and volumes, belongs to that tenant and is invisible to every other tenant.

There are two kinds, and they differ in how long they live and how you end their access:

| | Tenant tokens | Revokable tokens |
| - | - | - |
| Issued by | Your platform, with partner credentials | A tenant, with a tenant token |
| Lifetime | Minutes. The default is about 15 minutes. | Up to one year |
| Ending access early | Not possible. The token expires on its own. | Revoke it at any time |
| Typical use | Your service acting for a customer | Handing a customer a credential for their CI system or integration |

Most platforms only need tenant tokens.
Your service issues one whenever it acts for a customer and lets it expire.
Reach for a revokable token when a credential leaves your service and you need a way to cut off its access.

[Issue tenant tokens](/docs/platform/authentication/tenant-tokens) · [Create revokable tokens](/docs/platform/authentication/revokable-tokens)

## Which credential does each operation need?

| Operation | Credential |
| - | - |
| Create, list, update, and delete tenants | Partner |
| Set or update tenant policies | Partner |
| Read tenant policies | Tenant token |
| Issue tenant tokens | Partner |
| Create, list, and revoke revokable tokens | Tenant token |
| Run instances, builds, and other workloads | Tenant token or revokable token |

## Next steps

<Columns cols={2}>
  <Card title="Build on your own workspace" icon="laptop" href="/docs/platform/authentication/local-development">
    Build on your own workspace with your nsc login.
  </Card>

  <Card title="Partner credentials" icon="key-round" href="/docs/platform/authentication/partner-credentials">
    Sign partner tokens and create a partner client.
  </Card>

  <Card title="Tenant tokens" icon="ticket" href="/docs/platform/authentication/tenant-tokens">
    Act inside a tenant with short-lived tokens.
  </Card>

  <Card title="Revokable tokens" icon="ban" href="/docs/platform/authentication/revokable-tokens">
    Long-lived tenant credentials you can revoke.
  </Card>
</Columns>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.