> ## Documentation Index
> Fetch the complete documentation index at: https://namespace.so/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Multi-tenancy

> Give each of your customers an isolated tenant, and manage those tenants from your platform.

If you run a platform on Namespace, your customers should never see each other's work.
Tenants make that separation part of the infrastructure: each customer gets their own tenant, and everything they run lives inside it.

## What is a tenant?

A tenant is an isolated space in Namespace that owns resources: instances, builds, volumes, caches, secrets, and the credentials that access them.
The rest of Namespace calls the same thing a [workspace](/docs/platform/workspaces).

Tenants are isolated from each other:

* Resources created in one tenant are invisible to every other tenant.
* A tenant's credentials only work inside that tenant.
* Limits, such as how many instances can run at once, apply to each tenant separately.

A typical platform creates one tenant per customer, so each customer's data and workloads stay separate from every other customer's.

## How your platform and its tenants work together

Your platform manages tenants with [partner credentials](/docs/platform/authentication/partner-credentials). With them, it can:

* [Create a tenant](/docs/platform/tenants/create) for each new customer.
* [List and find](/docs/platform/tenants/list) the tenants it owns.
* [Update](/docs/platform/tenants/update) a tenant's name and labels.
* [Set policies](/docs/platform/tenants/policies) that limit what a tenant can use.
* [Delete](/docs/platform/tenants/delete) a tenant when a customer leaves.
* Issue [tenant tokens](/docs/platform/authentication/tenant-tokens) that act inside a tenant.

Work inside a tenant happens with a tenant credential. Your platform uses one to act for a customer, and it can give customers their own. With a tenant credential you can:

* Run [instances](/docs/platform/instances/quickstart), builds, and other workloads.
* Use [storage](/docs/platform/storage), such as cache volumes, the container registry, and secrets.
* Read the tenant's policies.
* Create [revokable tokens](/docs/platform/authentication/revokable-tokens) for systems outside your platform.

In code, these two roles are a partner client and a tenant client. [Partner and tenant clients](/docs/platform/tenants/clients) explains how to create each one.

## What a tenant looks like

```json theme={null}
{
  "id": "tenant_lqrj7qre0ts32",
  "createdAt": "2026-09-29T13:58:19.121800Z",
  "visibleName": "Customer 1",
  "externalAccountId": "customer-1",
  "labels": [{ "name": "plan", "value": "pro" }]
}
```

| Field | Description |
| - | - |
| `id` | Namespace's ID for the tenant, starting with `tenant_`. You use it to update, delete, and issue tokens for the tenant. |
| `externalAccountId` | Your ID for the customer, such as the account ID from your own database. Each ID maps to at most one tenant, and it cannot be changed after creation. |
| `visibleName` | A display name shown in Namespace interfaces such as the dashboard. |
| `labels` | Name and value pairs for your own metadata, such as a customer's plan or region. |
| `createdAt` | When the tenant was created. |

## Next steps

<Columns cols={2}>
  <Card title="Quickstart" icon="play" href="/docs/platform/tenants/quickstart">
    Create a tenant and act inside it with a tenant token.
  </Card>

  <Card title="Authentication" icon="key-round" href="/docs/platform/authentication">
    The credentials your platform and its tenants use.
  </Card>
</Columns>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.