# Tenancy

The X-Tenant-Id header and how keys are bound to one customer.

Every tenant-scoped call carries `X-Tenant-Id` = the id of the customer the key belongs to. The contract marks each operation with `x-tenant` (`customer`, `operator` or `any`), shown as a badge in the [reference](/reference).

- A customer API key is bound to exactly one customer. Another `X-Tenant-Id` is `403` [`tenant-forbidden`](/errors#tenant-forbidden).
- Ids of other customers are `404` [`not-found`](/errors#not-found): the API never reveals whether a resource of another tenant exists.
- Operators run many customers on one platform; each operator's data is isolated by row-level security in the database, so a key can never read another operator's or another customer's data even through a bug in a query.
