> ## Documentation Index
> Fetch the complete documentation index at: https://namespace.so/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Partner and Tenant Clients

> The two clients a platform uses: a partner client that manages tenants, and a tenant client that works inside one.

Every example in the multi-tenancy docs starts from one of two clients.
Both are ordinary Namespace SDK clients. What sets them apart is the credential they authenticate with, and that decides what each one can do.

| | Partner client | Tenant client |
| - | - | - |
| Authenticates as | Your platform | One tenant |
| Used for | Managing all of your tenants | Working inside a single tenant |
| Credential | [Partner credentials](/docs/platform/authentication/partner-credentials) | A tenant token, or your `nsc login` during development |
| Example variable | `partnerClient` | `tenantClient` |

## Partner client

The partner client is your platform's own client.
It authenticates with partner tokens that your platform signs with its private key, and it acts across every tenant your platform owns.

Use the partner client to:

* [Create](/docs/platform/tenants/create), [list](/docs/platform/tenants/list), [update](/docs/platform/tenants/update), and [delete](/docs/platform/tenants/delete) tenants.
* [Set a tenant's policies](/docs/platform/tenants/policies).
* [Issue tenant tokens](/docs/platform/authentication/tenant-tokens#issue-a-tenant-token), which create tenant clients.

The partner client does not run workloads. To create instances or builds for a customer, issue a tenant token and use a tenant client.

<CodeGroup>
  ```typescript TypeScript theme={null}
  import { createIAMClient } from "@namespacelabs/sdk/api/iam";

  const partnerClient = createIAMClient({ tokenSource: partnerTokenSource });
  ```

  ```go Go theme={null}
  partnerClient, err := iam.NewClient(ctx, partnerTokenSource{privateKey})
  if err != nil {
  	log.Fatal(err)
  }
  defer partnerClient.Close()
  ```
</CodeGroup>

[Partner credentials](/docs/platform/authentication/partner-credentials) shows how to build `partnerTokenSource` and create the partner client step by step.

## Tenant client

A tenant client acts inside exactly one tenant.
Everything it creates belongs to that tenant, and it cannot see or change any other tenant.

Use a tenant client to:

* Run [instances](/docs/platform/instances/quickstart), builds, and other workloads.
* Use [storage](/docs/platform/storage), such as cache volumes, the container registry, and secrets.
* [Read the tenant's policies](/docs/platform/tenants/policies#read-a-tenants-policies).
* Create, list, and revoke [revokable tokens](/docs/platform/authentication/revokable-tokens).

A tenant client can use any Namespace client, such as Compute or Builds, not only IAM.
[What a tenant token can do](/docs/platform/authentication/tenant-tokens#what-a-tenant-token-can-do) lists each one.

There are two ways to create a tenant client. They differ only in where the token comes from.

<Tabs>
  <Tab title="From a tenant token">
    In production, your platform acts for a customer with a tenant token.
    The partner client issues the token for the customer's tenant, and the tenant client authenticates with it.

    <CodeGroup>
      ```typescript TypeScript theme={null}
      import { createIAMClient } from "@namespacelabs/sdk/api/iam";
      import { fromBearerToken } from "@namespacelabs/sdk/auth";

      const { bearerToken } = await partnerClient.tenants.issueTenantToken({
        tenantId: "tenant_lqrj7qre0ts32",
        actorId: "user:4821",
      });

      const tenantClient = createIAMClient({
        tokenSource: fromBearerToken(bearerToken),
      });
      ```

      ```go Go theme={null}
      issued, err := partnerClient.Tenants.IssueTenantToken(ctx, &iamv1beta.IssueTenantTokenRequest{
      	TenantId: "tenant_lqrj7qre0ts32",
      	ActorId:  "user:4821",
      })
      if err != nil {
      	log.Fatal(err)
      }

      tenantClient, err := iam.NewClient(ctx, bearerTokenSource(issued.BearerToken))
      if err != nil {
      	log.Fatal(err)
      }
      defer tenantClient.Close()
      ```
    </CodeGroup>

    The tenant client acts in the tenant the token was issued for.
    [Tenant tokens](/docs/platform/authentication/tenant-tokens) covers choosing an actor ID and a duration, defining `bearerTokenSource` in Go, and keeping tokens fresh in long-running services.
  </Tab>

  <Tab title="From your nsc login">
    During development, you can create a tenant client from your `nsc login` instead, without a partner account.

    <CodeGroup>
      ```typescript TypeScript theme={null}
      import { createIAMClient } from "@namespacelabs/sdk/api/iam";
      import { loadDefaults } from "@namespacelabs/sdk/auth";

      const tenantClient = createIAMClient({
        tokenSource: await loadDefaults(),
      });
      ```

      ```go Go theme={null}
      tokens, err := auth.LoadDefaults()
      if err != nil {
      	log.Fatal(err)
      }

      tenantClient, err := iam.NewClient(ctx, tokens)
      if err != nil {
      	log.Fatal(err)
      }
      defer tenantClient.Close()
      ```
    </CodeGroup>

    The tenant client acts in the workspace you picked when you logged in, not in a customer's tenant.
    Use this for local development only. [Build on your own workspace](/docs/platform/authentication/local-development) walks through it.
  </Tab>
</Tabs>

## Next steps

<Columns cols={2}>
  <Card title="Create tenants" icon="building-2" href="/docs/platform/tenants/create">
    Give each of your customers their own tenant.
  </Card>

  <Card title="Authentication" icon="key-round" href="/docs/platform/authentication">
    The credentials behind each client.
  </Card>
</Columns>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.