Browse docs · Concepts
Get started
Concepts
Guides
Security
Reference
Docs / Concepts
Credentials
How PastKeys seals provider credentials, mints short-lived scoped credentials per operation, and controls their lifetime.
A credential in PastKeys is the provider's root secret (a Cloudflare token, an AWS key, a GitHub App key, a database admin DSN) sealed to your broker. Agents never receive it. For each operation the broker either mints a narrow, short-lived credential from it or uses it broker-side.
Sealing
You seal the secret to the broker's public key with pastkeys seal on a trusted machine, then store the resulting blob in the dashboard. The control plane keeps only that ciphertext. Each credential has a provider and an ID (default root).
Per-operation credentials
| Provider | What the broker uses | Default lifetime |
|---|---|---|
| AWS | STS AssumeRole session, optional inline session policy | 15 minutes |
| GitHub | App installation token scoped to one repo and the least permission | ~1 hour (fixed by GitHub) |
| Postgres | Temporary login role inheriting a read-only base role | 15 minutes |
| Cloudflare | Per-call token scoped to one zone and the action's permissions (opt-in), otherwise the protected token | 15 minutes |
| HTTP | The protected token, injected broker-side | n/a |
Minted credentials are cached for their lifetime (minus a safety margin) and dropped if an operation fails, so a revoked credential is re-minted.
Setting the lifetime per rule
A policy rule can set credential_ttl (10s to 12h) so a destructive action runs on a credential that dies quickly:
{"provider": "cloudflare", "resource": "example.com",
"actions": ["DNS_DELETE"], "credential_ttl": "2m"}
Providers with a fixed or minimum lifetime clamp to it (AWS minimum 15 minutes, GitHub fixed at 1 hour). The audit record always shows the lifetime actually issued.