Browse docs · Get started
Get started
Concepts
Guides
Security
Reference
Docs / Get started
PastKeys documentation
Learn how PastKeys lets AI agents perform authorized operations on your cloud without ever holding a secret: brokers, sealed credentials, policies, workload identity and audit.
PastKeys is a credential broker for AI agents and automated workloads. Your agent asks to perform an operation; a broker you run checks a default-deny policy, uses a short-lived scoped credential, and returns only the result. The agent never holds a provider secret, and the hosted service stores only ciphertext it cannot decrypt.
Choose your path
Quickstart →From zero to your first brokered call in about ten minutes.
How it works →The request lifecycle and what PastKeys can and cannot see.
GitHub Actions →Let a CI job act with no stored secret, using workload identity.
Claude Code and MCP →Give an MCP agent tools that carry no decryptable credential.
The three pieces
| Piece | Where it runs | What it holds |
|---|---|---|
| Agent | Your CI, server, laptop or cluster | Only its own identity (a short-lived platform token, or an agent token) |
| Broker | Your environment | The custody private key; it opens sealed credentials and performs operations |
| Control plane | pastkeys.com | Policies, sealed (ciphertext) credentials, audit records, settings |
Core ideas
- Credentials are sealed to your broker's public key before we store them.
- Policies are default-deny: an operation runs only if a rule allows it.
- Workload identity lets agents prove who they are without a stored key.
- Audit records one secret-free, hash-chained event per request.
- Break-glass freezes every agent in seconds when something goes wrong.