Docs / Concepts

Policies

PastKeys policies are default-deny JSON documents that name an agent and the exact operations it may perform, with constraints, time windows, rate limits, approvals and credential lifetimes.

A policy names one agent and lists rules. An operation is allowed only when a rule explicitly matches it; everything else is denied. Policies are edited in the dashboard and delivered to brokers automatically.

Shape

{
  "agent": "github:repo:acme/infra:ref:refs/heads/main",
  "rules": [
    { "id": "dns-read", "provider": "cloudflare", "resource": "example.com",
      "actions": ["DNS_READ"] },
    { "id": "dns-write", "provider": "cloudflare", "resource": "example.com",
      "actions": ["DNS_CREATE", "DNS_UPDATE"],
      "constraints": [{ "param": "name", "prefix": "api." }],
      "require_approval": true, "credential_ttl": "2m" }
  ]
}

Rule fields

FieldMeaning
idStable name shown in decisions and audit
providercloudflare, aws, github, postgres, http
resourceZone, bucket, owner/repo, database or base URL. A trailing * matches a prefix; * alone matches any
actionsActions this rule covers
effectallow (default) or deny. An explicit deny always wins
constraintsPer-parameter checks: one_of, not_one_of, prefix, regex, min, max. A missing parameter fails the check
require_approvalA human must approve each call (approvals)
not_before, not_afterRFC 3339 window when the rule is active
rate_limit{"requests": 10, "per_seconds": 60} per agent
credential_ttlLifetime of the minted credential, e.g. "2m"

Evaluation

  1. Any matching deny rule refuses the request (explicit_deny).
  2. The first matching allow rule whose constraints and rate limit pass allows it.
  3. Otherwise it is denied, with the most specific reason: rate_limited, constraint_violation, action_not_allowed, no_matching_rule or unknown_agent.

Guardrails

A policy whose agent is * holds account-wide deny rules. They apply to every agent, to published endpoints and over emergency grants, so you can forbid an operation everywhere in one place.

{"agent": "*", "rules": [{"effect": "deny", "provider": "aws",
  "resource": "prod-*", "actions": ["S3_LIST"]}]}

Testing

./pastkeys policy test --agent demo-agent --provider cloudflare \
  --resource example.com --action DNS_DELETE --policies ./policies

Agents can also ask POST /v1/authorize for a dry run that spends no rate-limit budget.