PASTKEYS
GUIDE Quickstart

Getting started with PastKeys

PastKeys · October 2026

PastKeys sits between your AI agent and the providers it needs (Cloudflare, GitHub, AWS, Postgres, and others). The agent asks for an authorized operation, and PastKeys performs it with a short-lived, scoped credential that the agent never sees.

The model in one line

The agent receives authorization to perform an operation, not the permanent credential used to perform it. Provider secrets stay inside a broker you run; the hosted control plane only ever holds ciphertext it cannot decrypt.

Five steps to your first brokered call

1. Run a broker

Download the broker binary from your dashboard and run it in your own environment. On first start it generates an X25519 custody keypair. The private key stays on your host and is never uploaded, which is what makes the setup zero-access.

2. Seal a provider credential to the broker

In the dashboard, add a credential for a provider. The provider token is encrypted in your browser to the broker's public key before it is stored, so the control plane keeps only a sealed blob. Only your broker can open it.

3. Write a default-deny policy

Policies are JSON documents that name an agent and the operations it may perform. Anything not explicitly allowed is denied. A minimal policy looks like this:

{
  "agent": "deploy-bot",
  "rules": [
    { "effect": "allow", "provider": "cloudflare",
      "resource": "example.com", "action": "DNS_READ" }
  ]
}

4. Mint an agent token

Create a workload for your agent and mint it a token. The token identifies the agent to the broker; it is not a provider secret and carries no provider access on its own.

5. Call an authorized operation

The agent sends the operation to the broker. The broker authenticates the agent, evaluates the policy, mints or retrieves a short-lived provider credential, performs the operation, and returns only the result plus an audit record. The credential is never in the response.

POST /v1/actions
Authorization: Bearer <agent-token>

{ "provider": "cloudflare", "resource": "example.com", "action": "DNS_READ" }
Using MCP? The broker ships an MCP server (broker mcp) that exposes the same authorize and execute calls as tools, so an MCP-capable agent can use PastKeys without any provider secret in its context.

What you get

For the full design and threat model, read the zero-access whitepaper.

Stop handing agents long-lived secrets.

Create an account Read the whitepaper