Docs / Get started

PastKeys documentation

Learn how PastKeys lets AI agents perform authorized operations on your cloud without ever holding a secret: brokers, sealed credentials, policies, workload identity and audit.

PastKeys is a credential broker for AI agents and automated workloads. Your agent asks to perform an operation; a broker you run checks a default-deny policy, uses a short-lived scoped credential, and returns only the result. The agent never holds a provider secret, and the hosted service stores only ciphertext it cannot decrypt.

Choose your path

The three pieces

PieceWhere it runsWhat it holds
AgentYour CI, server, laptop or clusterOnly its own identity (a short-lived platform token, or an agent token)
BrokerYour environmentThe custody private key; it opens sealed credentials and performs operations
Control planepastkeys.comPolicies, sealed (ciphertext) credentials, audit records, settings

Core ideas

  • Credentials are sealed to your broker's public key before we store them.
  • Policies are default-deny: an operation runs only if a rule allows it.
  • Workload identity lets agents prove who they are without a stored key.
  • Audit records one secret-free, hash-chained event per request.
  • Break-glass freezes every agent in seconds when something goes wrong.