Browse docs · Get started
Get started
Concepts
Guides
Security
Reference
Docs / Get started
Quickstart
Set up PastKeys in about ten minutes: create an account, run a broker, seal a provider credential, write a policy, and make your first brokered call.
This walks through one complete brokered call: an agent reads DNS records from Cloudflare without ever seeing the Cloudflare token. Every step is also available inside the dashboard's guided setup.
1. Create an account
Sign up with email or GitHub. The free plan covers 3 agents and 10,000 operations a month.
2. Create a broker token
In the dashboard open Brokers and choose Add broker. Copy the token: it is shown once. The broker uses it to fetch its configuration and push audit records.
3. Download and start the broker
curl -fsSL https://pastkeys.com/download/broker-linux-amd64 -o pastkeys chmod +x pastkeys sha256sum pastkeys # compare with https://pastkeys.com/download/SHA256SUMS ./pastkeys keygen --out custody.key export BROKER_CONTROLPLANE_URL=https://pastkeys.com export BROKER_TOKEN=pk_brk_... # from step 2 export BROKER_CUSTODY_KEY_FILE=custody.key ./pastkeys serve --addr 127.0.0.1:8080
Builds exist for Linux and macOS (amd64, arm64) and Windows. The broker registers its public key and shows as online in the dashboard within seconds. The private key in custody.key never leaves this machine. Run ./pastkeys doctor to check the setup.
keygen prints the matching public key (a long line) to the screen. Copy it, you need it in the next step to seal credentials. If you lose it, ./pastkeys doctor prints it again under "custody public key".
4. Seal a provider credential
Seal the Cloudflare token to the broker's public key on a trusted machine, using the public key keygen printed in step 3 (the dashboard also shows this command with your key filled in):
./pastkeys seal --pubkey '<the public key from step 3>' # paste the token, press Ctrl-D, copy the sealed blob
In Credentials, choose Store credential, pick cloudflare, and paste the blob. PastKeys stores only the ciphertext.
5. Write a policy
In Policies, add a policy that lets one agent read DNS for one zone. Everything else stays denied.
{"agent": "demo-agent",
"rules": [{"provider": "cloudflare", "resource": "example.com", "actions": ["DNS_READ"]}]}
6. Give the agent an identity
In Agents, add demo-agent and choose Generate token. For CI and cloud workloads, use workload identity instead so there is no long-lived token at all.
7. Make the call
curl -sS http://127.0.0.1:8080/v1/actions \
-H "Authorization: Bearer $AGENT_TOKEN" \
-d '{"provider":"cloudflare","resource":"example.com","action":"DNS_READ"}'
The broker authenticates the agent, checks the policy, uses the sealed token, and returns the records. Open Audit log to see the event. Try an action the policy does not allow, such as DNS_DELETE, and you get 403 with reason action_not_allowed.