Browse docs · Security
Get started
Concepts
Guides
Security
Reference
Docs / Security
Break-glass
Emergency controls: freeze every agent in seconds, revoke every agent token, and grant one agent short, audited access during an incident.
When an agent misbehaves or a credential may have leaked, the Break-glass page gives you three controls. Every action is recorded and emailed to everyone on the account.
Lockdown
Freeze all agents makes every broker refuse every agent operation, including approved requests and published endpoints. Brokers apply it within about 5 seconds. Nothing overrides it. Ending it requires typing UNFREEZE. Agents only see the reason lockdown, never your note.
Revoke all agent tokens
Invalidates every 90-day agent token at once. Connected brokers stop accepting them within one poll. Workload identity tokens are unaffected.
Emergency access grants
A grant lets one agent perform specific actions on one named resource that its policy denies or holds for approval, for 15 minutes, 1 hour or 4 hours. A reason is required and it can be revoked at any time. Grants never override account guardrails or a lockdown, calls under them are audited with reason break_glass, and any credential minted under a grant expires before the grant does.
Local kill switch
Freeze a single broker on its own host, with no connection to PastKeys needed:
export BROKER_LOCKDOWN_FILE=/var/lib/pastkeys/lockdown ./pastkeys lockdown on ./pastkeys lockdown status ./pastkeys lockdown off
The broker must run with the same BROKER_LOCKDOWN_FILE; it refuses every operation while the file exists.