PASTKEYS credential broker for AI agents

Let your AI agents act on your cloud without ever holding a secret.

Store your provider tokens (Cloudflare, GitHub, AWS, Postgres, any HTTP API) sealed to a broker you run. We cannot read them. Your agent asks the broker to perform an operation; the broker checks a default-deny policy, uses a short-lived scoped credential, and returns only the result. Every request lands in a tamper-evident audit log.

Zero-access custodyDefault-deny policyShort-lived credentialsWorkload identityFull audit

Free for 3 agents and 10,000 operations a month. No card required.

agent ⇄ broker
agent asks for an operation
POST /v1/actions
Authorization: Bearer <workload-identity-token>

{ "provider": "cloudflare",
  "resource": "example.com",
  "action":   "DNS_CREATE",
  "parameters": { "name": "api", "type": "A" } }

broker returns the result, never the key
{ "success": true,
  "operation": "DNS_CREATE",
  "data": { "record_id": "9f2c…" },
  "request_id": "8a41d0c2" }

audit ▸ decision=ALLOW credential=short-lived 2m secret_in_record=none
secrets exposed to the agent
0
by construction: the key never enters the model
secrets leaked in public MCP configs
24,008
GitGuardian 2026, 2,117 still live
policy default
DENY
allow only on an explicit rule match
emergency lockdown
~5s
one click freezes every agent on every broker
FIG.1 request path

One boundary between the agent and every provider.

The broker authenticates the workload, evaluates a default-deny policy, uses a credential that never leaves the enclosure, and logs the result.

A · AUTHVerifies workload identity. Answers who, nothing else.
B · POLICYDefault-deny over agent, resource and action. Fails closed.
C · CREDENTIALSealed to a key only your broker holds; minted short-lived where possible.
D · AUDITExactly one secret-free record per request.
FIG.3 failure analysis

Blast radius when the worst happens.

Assume the agent's runtime, context or logs are fully exposed. Privilege an attacker can reach, as a share of the underlying credential's power.

traditional100% · full account
pastkeys~0% · one scoped op

A credential the broker mints is scoped to one operation and already expiring, the policy re-denies everything else, and the attempt is already in the audit log.

FIG.4 policy bench · live

Try the default-deny engine.

Pick a request. The bench evaluates it like pastkeys policy test: allow only on an explicit rule match, everything else denied.

  • Unknown agents are denied, always
  • Matching resource but wrong action is denied
  • Sensitive operations can require a human approval
  • Every decision, allow or deny, is audited
FIG.5 providers

One interface, every provider.

Where a provider supports it, the broker mints a short-lived, scoped credential per operation. Where it cannot, a protected token stays broker-side and is never exposed to the agent.

AdapterOperationsCredentialStatus
aws (sts)assume-role session · s3 list · caller identityshort-lived sessionbuilt
githubrepo read · issues · pr readscoped ~1h tokenbuilt
postgresread-only querytemporary rolebuilt
cloudflareDNS read / create / update / deleteper-call scoped token (opt-in)built
http (generic)any REST endpointprotected, broker-sidebuilt
ssh (ca)certificate issuanceshort-lived certresearch
FIG.6 per request

Five steps, fail-closed.

01

authenticate

Verify the agent's workload identity.

02

authorize

Default-deny policy over agent, provider, resource, action.

03

broker

Open the sealed credential; mint a scoped, short-lived one where possible.

04

execute

Perform the operation; return only the result.

05

audit

Write one secret-free record. Any error resolves to deny.

NOTE quickstart

Run a broker in two minutes.

Download the broker for your platform, generate a custody key, and connect it to your account. The private key never leaves your machine.

$ curl -fsSL https://pastkeys.com/download/broker-linux-amd64 -o pastkeys

macOS, Windows and arm64 builds plus checksums are in the quickstart.

PRICING simple, per account
Free
$0

3 agents, 10k ops / month

Team
$49/mo

25 agents, 1M ops / month

Enterprise
Custom

limits, SLA, support

Compare plans →

Stop handing agents long-lived secrets.Free for 3 agents. Set up your first brokered call in minutes.

Start freeRead the docs