AgentConfig.tenant option.
Quick Start
This host function receives an already authenticated identity, a host-owned storage driver, and a model.AgentFactory scopes memory and checkpoint storage; the run options carry the same identity to hooks and tools.
closeStorage: false prevents one request from closing a shared connection. Authenticate and authorize sessionId before invoking this function; the function does not validate session ownership itself.
Tenant-Scoped Storage
For a custom data namespace, wrap a storage driver explicitly:TenantScopedStorage prefixes namespaces with t:<tenantId>:. ScopedStorage, used by the factories, supports tenant and user scope. Both wrappers delegate close() to their underlying driver; the host should close a shared driver once. Use separate database accounts or storage instances when the application requires physical isolation.
Extracting Tenant ID
extractTenantFromHeaders() and extractTenantFromJwt() extract values; neither verifies signatures, authenticates a user, nor confirms organization membership. Read tenant claims only after your authentication middleware has verified them. Never accept an arbitrary X-Tenant-Id header as authorization.
Context Propagation
PasstenantId and userId in agent.run(input, options) when hooks and tools need them. Factory storage scope and run context are separate responsibilities. Application tools must still scope their own SQL, file, HTTP, and vector queries.
Use the owned-session API recipe to verify missing credentials, cross-user denial, and session reuse. For memory visibility rules, read memory isolation.