Partners — an agent for each of your customers
Updated 2026-09-28
ghosty partner is for when your product wants to give an assistant to each of its customers. You have a partner space; each business using your product is a tenant (identified by your own externalId) and each person writing to that business is an end user (groupId).
- There is one shared agent, in solo-MCP mode: no machine, no disk; its only tools are those of your HTTPS MCP servers.
- Every turn carries a short-lived token that Ghosty passes to your MCP. It never goes into the prompt, memory or logs.
- Memory is per tenant and end user: one business never sees another's.
Your partner space
The space owner runs these, signed in (ghosty login).
createprintsGHOSTY_PARTNER_KEY=gpk_…andGHOSTY_PARTNER_SECRET=gps_…. Store them on your server right away: the secret is not shown again.rotate --grace MINkeeps the old secret valid for that many minutes (default 60) so you can switch your server without downtime.credsis an alias ofcredentials;revokecan also be spelledrm.- If you own more than one partner space, pick one with
--workspace <slug>on any command.
The shared agent
agent.json carries only what you want to change:
HTTPS MCP servers only. Headers take no fixed keys: only the ${turn.token} and ${tenant.externalId} placeholders. If nothing changed, no new version is created.
Tenants
A tenant is config only (name, tone, timezone, locale, notes): it has no machine of its own. The first turn for a new externalId also registers it.
Try a turn
--groupis the end user (defaultcli); each one gets its own conversation.--turn-tokenis the token Ghosty will pass to your MCP as${turn.token}. Here--tokenworks too and means the same (it is not your session).- With
--jsonit prints one line per turn event (chunk,tool,error…).
Test as your server
With the credential in the environment, the CLI signs every request the way your backend will (HMAC of ${ts}.${keyId}.${body}):
That works for agent, tenants and try. ls, enable, credentials and audit always use your session: a credential cannot mint other credentials.