set up nats jwt-based accounts for multi-tenant isolation using the operator, account, and user hierarchy

domain: docs.nats.io · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Use the nsc tool to create an Operator identity, then create one Account per tenant to isolate each tenant's subject space.
  2. Issue User JWTs under each account with nsc, scoping permissions and limits such as connections, data limits, and subjects per tenant.
  3. Push account JWTs to a JWT resolver, such as nats-account-server or the built-in resolver, so nats-server nodes can validate them at connection time.
  4. Configure the server config's operator and resolver settings to trust the operator's public key and fetch account JWTs dynamically.
  5. Test that a client authenticated under one account cannot publish or subscribe to another account's subjects, confirming isolation.

Known gotchas

Related routes

Set up Pulsar multi-tenancy with tenant and namespace isolation including authentication and authorization
pulsar.apache.org · 5 steps · unrated
Design and implement a virtual account hierarchy under an FBO omnibus account using Increase ledger accounts for sub-tenant fund segregation
ledger/Increase · 6 steps · unrated
Implement a Modern Treasury VirtualAccount hierarchy for FBO sub-tenant receipt routing and auto-ledgering
banking-general · 6 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans