Secure a Partner API
Partners may sell, refer, implement, operate, or integrate, but B5 remains authoritative for customer identity, security policy, licensing, entitlement, credential lifecycle, audit, evidence, and revocation.
Partner integration components
Authority boundaries
Implementation steps
Control details
Channel
The commercial channel changes who sells or operates the relationship, not the location of authoritative security and entitlement truth.
Delegation
Delegation is explicit, scoped, time-bound, reviewable, and revocable. A partner administrator is never a platform-wide administrator.
Entitlement
Partners can request or display entitlements, but authoritative issuance, signing, renewal, and revocation remain under B5.
Audit
Partner activity must preserve the partner organization, actor, delegated customer, application, scope, decision, correlation, and evidence references.
Delegate operation without delegating authoritative truth
POST /v1/trust/decisions
X-B5-Tenant-Id: partner-tenant-id
X-B5-Application-Id: partner-application-id
X-B5-Delegated-Customer-Id: customer-tenant-id
X-B5-Key-Id: key-id
X-B5-Timestamp: 2026-06-27T12:00:00Z
X-B5-Nonce: unique-random-value
Authorization: B5-HMAC-SHA256 <signature>| Partner may | B5 remains authoritative for |
|---|---|
| Refer, resell, implement, operate, or integrate within a grant | Customer identity, licensing, entitlement, credential lifecycle, audit, evidence, renewal, and revocation |
| Administer explicitly delegated customer resources | Cross-customer isolation, role boundaries, policy decisions, and incident containment |
Talk to a human.
Get architecture guidance, Test Mode access, integration review, or help choosing the right B5 identity and authorization pattern.