Docs / Reference

CLI reference

Commands of the pastkeys broker binary: serve, keygen, seal, custody, policy, audit, mcp, doctor, lockdown and license.

The broker is a single binary. Run ./pastkeys <command>.

CommandWhat it does
serve [--addr :8080] [--policies DIR]Run the broker
keygen [--out FILE]Generate a custody keypair (hybrid post-quantum)
seal --pubkey KEYSeal a secret read from stdin to a broker's public key
custody rotateAdd a new custody key, keeping the old one for opening
policy test --agent A --provider P --resource R --action X [--policies DIR]Evaluate a request against policy files
audit verify --file FILE [--pubkey KEY]Verify an audit log's hash chain and signatures
audit pubkeyPrint the audit signing public key
mcp [--broker-url URL]Run the MCP server over stdio
doctorCheck configuration; non-zero exit on a security problem
lockdown on|off|status [--file PATH]Toggle the local kill switch
license keygen|sign|verifyManage plan licenses (self-hosted)
versionPrint version and build info