Skip to main content
Every example in the multi-tenancy docs starts from one of two clients. Both are ordinary Namespace SDK clients. What sets them apart is the credential they authenticate with, and that decides what each one can do.

Partner client

The partner client is your platform’s own client. It authenticates with partner tokens that your platform signs with its private key, and it acts across every tenant your platform owns. Use the partner client to: The partner client does not run workloads. To create instances or builds for a customer, issue a tenant token and use a tenant client.
Partner credentials shows how to build partnerTokenSource and create the partner client step by step.

Tenant client

A tenant client acts inside exactly one tenant. Everything it creates belongs to that tenant, and it cannot see or change any other tenant. Use a tenant client to: A tenant client can use any Namespace client, such as Compute or Builds, not only IAM. What a tenant token can do lists each one. There are two ways to create a tenant client. They differ only in where the token comes from.
In production, your platform acts for a customer with a tenant token. The partner client issues the token for the customer’s tenant, and the tenant client authenticates with it.
The tenant client acts in the tenant the token was issued for. Tenant tokens covers choosing an actor ID and a duration, defining bearerTokenSource in Go, and keeping tokens fresh in long-running services.

Next steps

Create tenants

Give each of your customers their own tenant.

Authentication

The credentials behind each client.
Last modified on October 2, 2026