> ## Documentation Index
> Fetch the complete documentation index at: https://docs.lerian.studio/llms.txt
> Use this file to discover all available pages before exploring further.

# Manage partners in the Console

> Create a partner step by step, issue its credentials, change what it can reach, suspend it, and delete it from Settings in Lerian Console.

<Warning>
  This feature is available only in Staging for testing and is not yet available in Production.
</Warning>

This guide shows how to manage [partners](/en/platform/access-manager/features/partners/overview) from the Console. You create the partner, issue its credentials, and change or end its access later.

## Before you start

***

You need the `partners` permission with the `get` action to open the page. To create a partner's credentials, you also need the `applications` permission with the `post` action.

Collect this information before you start:

* The products the partner needs, and what it may do in each one.
* The IDs of the items the partner may reach: for Midaz, at least the organization ID. Copy the IDs from the product's own API or Console. The Console does not check that they exist.
* The network addresses the partner calls from, if you want to restrict them.
* The start and end dates of its access, if it has a time limit.

## Open the Partners page

***

<Steps>
  <Step title="Open Settings">
    Click the gear icon (<Icon icon="gear" />) in the top navigation bar.
  </Step>

  <Step title="Select Partners">
    Select **Partners** in the Settings sidebar. The subtitle reads "Give each customer its own credentials and limit what it can reach."
  </Step>
</Steps>

The page lists your partners. A partner that is not working shows a status badge: **Suspended**, **Expired**, or **Not yet valid**. With no partners yet, the page reads "You haven't registered any partners yet".

## Create a partner

***

Click **New partner**. A wizard opens with five steps: **Details**, **Products**, **Scope**, **Permissions**, and **Review**. **Next** opens only when the current step is complete. **Back** keeps what you entered.

<Steps>
  <Step title="Details">
    Type the partner's **Name**. Only your team sees this name, and it must be unique in your tenant.

    Under **Validity window**, fill in **Valid from** and **Valid until** if the access has a time limit. Leave **Valid from** empty to start now. Leave **Valid until** empty so it never expires.

    Under **Where it calls from**, choose one option:

    * **Use your organization's IP list**: the partner uses your tenant's IP allowlist.
    * **Give it its own list**: type the partner's addresses or CIDR ranges. Its own list replaces your tenant's list. An address that is only on your tenant's list does not work for this partner.
  </Step>

  <Step title="Products">
    Choose the products the partner can use. The list shows only what your tenant has.

    A product that cannot take partners yet is greyed out with the message "This product isn't ready for partners yet." You cannot select it.
  </Step>

  <Step title="Scope">
    Say where the partner can act in each product. A restriction that the product requires is already open. For Midaz, that is the organization.

    To narrow the access, click **Add restriction** and choose the item under **Restrict by**, for example a ledger or an account. Type one ID, or several IDs separated by commas.

    Once you restrict a type by ID, the partner cannot list or create items of that type.
  </Step>

  <Step title="Permissions">
    Check the resources and the actions the partner can call on each product. To give a different set of actions on other resources, add a line with the product's button, for example **Add another line on Midaz**.

    The Console offers only what your tenant can give. A line that cannot be saved shows its reason:

    * **Not allowed**: your tenant does not hold this permission.
    * **Outside the scope**: the write acts above the partner's scope. For example, creating ledgers acts on the whole organization, so a partner restricted to one ledger cannot get it.
    * **Granted twice**: another line already grants the same action on the same resource.
  </Step>

  <Step title="Review">
    Under "Check what this partner can and can't do", read the summary. **It can** lists the actions, the items, and the IP list. **It can't** lists what stays outside.

    Click **Save**. The Console creates the partner with no credentials. You issue them on its **Applications** tab.
  </Step>
</Steps>

If Access Manager refuses the partner, the Console shows "The Access Manager refused this change" and opens the step that holds the field to fix.

## Issue the partner's credentials

***

A partner without an application cannot call anything. Create one application per product.

<Steps>
  <Step title="Open the Applications tab">
    In the partner list, click the partner. Select the **Applications** tab.
  </Step>

  <Step title="Create the application">
    Click **New Application**. In the **New application** side sheet, choose the **Product**. Only products that the partner has permissions on are offered. Fill in **Description** and click **Create application**.
  </Step>

  <Step title="Copy the credentials">
    The dialog "Save the credentials" shows the client ID and the client secret. Copy both now. The client secret is shown only once. Click **I've saved them** to close the dialog.
  </Step>

  <Step title="Send the credentials to the partner">
    Send the client ID and the client secret to the partner through a secure channel. The partner's system uses them to request access tokens.
  </Step>
</Steps>

Partner applications do not appear in **Settings → Applications**. They follow the partner's permissions, scope, validity window, and IP list.

If a client secret is lost, delete that application and create a new one. A new application comes with a new secret. When you delete an application, the partner's program that uses it stops working at once.

## Change a partner

***

Open the partner from the list. The detail page has five tabs:

| Tab | What you do there |
| - | - |
| **Overview** | Rename the partner, change its **Validity window**, suspend or reactivate it, and delete it. |
| **Permissions** | Add or remove products, resources, and actions. |
| **Scope** | Add, change, or remove restrictions. |
| **IPs** | Give the partner its own list, change it, or go back to **Use your organization's list**. |
| **Applications** | Create and delete the partner's credentials. |

Saving on **Permissions** or **Scope** replaces the permissions and the scope together. A change applies from the partner's next request.

## Suspend or reactivate a partner

***

On the **Overview** tab, click **Suspend** and confirm. Every credential of the partner is refused from its next request, including tokens it already holds. Nothing is deleted.

To give the access back, click **Reactivate** and confirm. The partner's credentials work again from its next request. They are the same credentials as before.

## Delete a partner

***

You can delete only a partner without applications.

<Steps>
  <Step title="Delete its applications">
    On the **Applications** tab, delete each application of the partner.
  </Step>

  <Step title="Delete the partner">
    On the **Overview** tab, click **Delete partner** and confirm. The partner loses access at once. Its permissions, scope, and IP list are deleted too. You cannot undo this.
  </Step>
</Steps>

If the partner still has applications, the Console lists them and offers **Go to Applications**.

## Partners that use your tenant's IP list

***

On **Settings → Security**, the **IP allowlist** tab shows how many partners use your tenant's list. A change to that list also applies to those partners, from their next request. To make a partner independent of that list, give it its own list on its **IPs** tab.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.