Skip to main content
In this quickstart, your platform creates a tenant for its first customer, then acts inside that tenant on the customer’s behalf. Along the way you use both clients a platform needs: a partner client that manages tenants, and a tenant client that works inside one.

Before you start

You need partner credentials from Namespace: a partner ID, an issuer, a key ID, and a private key in PEM format. Partner credentials explains each value.
No partner account yet? You can still build the parts of your platform that run inside a tenant by using your own workspace. See Build on your own workspace.

Getting started

1

Add a client library

2

Create a partner client

The partner client authenticates as your platform. It signs a short-lived partner token with your private key whenever it needs one.
Replace the partner ID, issuer, key ID, and key file with your own. Partner credentials explains each field.
3

Create a tenant

Create a tenant for your first customer. EnsureTenantForExternalAccount links the tenant to your own ID for the customer, here customer-1, and returns the existing tenant if you run it again.
Output
The tenant ID is Namespace’s ID for the tenant. You use it to issue tokens for the tenant in step 5.
4

List your tenants

List the tenants your platform owns. The new tenant appears in the list.
Output
This returns the first 100 tenants. List and find tenants shows how to page through more.
5

Issue a tenant token

So far, every call has acted as your platform. To work inside the customer’s tenant, issue a tenant token for it. The actor ID identifies who in your system the token acts for, here a user of Customer 1.
From here on, you act on Customer 1’s behalf. Everything created with this token belongs to Customer 1’s tenant, and no other tenant is reachable with it. The token expires after 15 minutes.
6

Create a tenant client

A tenant client authenticates with the tenant token.
7

Read the tenant's policies

Policies set what a tenant can use, such as how many instances it can run at once. The request has no tenant ID. It reads the policies of the tenant the token belongs to, which is why it needs the tenant client.
Output
A new tenant starts with an empty usage policy, so it has no limits of its own yet.
The tenant stays until you delete it. Delete tenants shows how.

Next steps

Partner and tenant clients

What each client is for.

Tenant policies

Set limits for the tenant.

Run an instance

Pass the tenant token to a Compute client to run an instance in the tenant.
Last modified on October 2, 2026