Skip to main content
A tenant token lets your service act inside one tenant on behalf of a customer. Your platform issues it with partner credentials, uses it for a few minutes, and lets it expire. Anything created with the token belongs to that tenant. The examples use a tenant ID, such as one returned when you create a tenant.

What a tenant token can do

A tenant token works with every Namespace client, so your service can do anything inside the customer’s tenant that the customer could do themselves: Everything the token creates belongs to its tenant and is invisible to every other tenant. A tenant token cannot manage tenants: creating, updating, or deleting tenants, setting their policies, and issuing tenant tokens need partner credentials. By default, a token can use all of these. To limit a token to the actions it needs, see Narrow what a token can do.

Issue a tenant token

Your platform issues tenant tokens with its partner client.
1

Create a partner client

A partner client authenticates with a token source that signs partner tokens. Partner credentials shows how to build partnerTokenSource and explains each field.
2

Request the token

IssueTenantToken takes the tenant ID, an actor ID, and a duration.
The actor ID is a string you choose to identify who in your system the token acts for, such as the customer’s user or one of your services. Namespace embeds it in the token. Anyone holding the token can read it, so use a stable identifier from your own system, such as user:4821 or service:billing, rather than personal data like an email address.If you leave out the duration, the token lasts about 15 minutes.
3

Save the token to a file (optional)

If the token is used by a separate process, such as a script or the nsc CLI, write it to a token file. The file holds the token in a bearer_token field. Restrict it to the current user, because anyone who can read it can act inside the tenant.
The file stops working when the token expires.
Point the NSC_TOKEN_FILE environment variable at the file. The nsc CLI, and SDK clients that load default credentials, then authenticate as the tenant:
Tenant tokens cannot be revoked. Once issued, a token is valid until it expires, so keep durations short. If you need to end a credential’s access early, use a revokable token instead.

Create a tenant client

A tenant client acts inside the tenant the token belongs to.
1

Create the client from the token

Pass the token to any Namespace client. Here it creates an IAM client, which can read and manage things that belong to the tenant.
If you saved the token to a file, load it instead with loadDefaults() in TypeScript or auth.LoadDefaults() in Go. Both read the file named by NSC_TOKEN_FILE.For local development, loadDefaults() can also use your nsc login. See Build on your own workspace.The same token works with the Compute client, which is how your service runs instances inside the customer’s tenant.
2

Test the token

Reading the tenant’s policies is a read-only call that only works with a tenant token, which makes it a safe first request.
Output
A new tenant has one policy, an empty usage policy. Tenant policies explains what it controls.

Narrow what a token can do

By default, a tenant token can do anything inside its tenant. When a token only needs a few actions, grant just those with access. For example, a token for a dashboard that only displays a customer’s instances needs nothing beyond listing them:
This token can list the tenant’s instances, and any other call fails with a permission error. Each grant names a resource type, a resource ID or * for all, and a list of actions. The permissions reference lists every resource type and its actions.

Keep tokens fresh in long-running services

A token from fromBearerToken in TypeScript, or a fixed-token source in Go, stops working when the token expires. That is fine for a short task. A service that keeps a client for longer than the token’s lifetime should give the client a token source that issues a new tenant token on demand.
The TypeScript SDK reuses each token until fewer than five minutes of validity remain, then calls issueToken again. In Go, auth.TenantTokenSource issues a new tenant token for every request and does not set an actor ID. If you need either behavior to differ, implement your own IssueToken as in the TypeScript example.

Next steps

Revokable tokens

Long-lived tenant credentials you can revoke.

Tenant policies

Read and change a tenant’s limits.
Last modified on October 2, 2026