Browse docs · Concepts
Get started
Concepts
Guides
Security
Reference
Docs / Concepts
Policies
PastKeys policies are default-deny JSON documents that name an agent and the exact operations it may perform, with constraints, time windows, rate limits, approvals and credential lifetimes.
A policy names one agent and lists rules. An operation is allowed only when a rule explicitly matches it; everything else is denied. Policies are edited in the dashboard and delivered to brokers automatically.
Shape
{
"agent": "github:repo:acme/infra:ref:refs/heads/main",
"rules": [
{ "id": "dns-read", "provider": "cloudflare", "resource": "example.com",
"actions": ["DNS_READ"] },
{ "id": "dns-write", "provider": "cloudflare", "resource": "example.com",
"actions": ["DNS_CREATE", "DNS_UPDATE"],
"constraints": [{ "param": "name", "prefix": "api." }],
"require_approval": true, "credential_ttl": "2m" }
]
}
Rule fields
| Field | Meaning |
|---|---|
id | Stable name shown in decisions and audit |
provider | cloudflare, aws, github, postgres, http |
resource | Zone, bucket, owner/repo, database or base URL. A trailing * matches a prefix; * alone matches any |
actions | Actions this rule covers |
effect | allow (default) or deny. An explicit deny always wins |
constraints | Per-parameter checks: one_of, not_one_of, prefix, regex, min, max. A missing parameter fails the check |
require_approval | A human must approve each call (approvals) |
not_before, not_after | RFC 3339 window when the rule is active |
rate_limit | {"requests": 10, "per_seconds": 60} per agent |
credential_ttl | Lifetime of the minted credential, e.g. "2m" |
Evaluation
- Any matching deny rule refuses the request (
explicit_deny). - The first matching allow rule whose constraints and rate limit pass allows it.
- Otherwise it is denied, with the most specific reason:
rate_limited,constraint_violation,action_not_allowed,no_matching_ruleorunknown_agent.
Guardrails
A policy whose agent is * holds account-wide deny rules. They apply to every agent, to published endpoints and over emergency grants, so you can forbid an operation everywhere in one place.
{"agent": "*", "rules": [{"effect": "deny", "provider": "aws",
"resource": "prod-*", "actions": ["S3_LIST"]}]}
Testing
./pastkeys policy test --agent demo-agent --provider cloudflare \ --resource example.com --action DNS_DELETE --policies ./policies
Agents can also ask POST /v1/authorize for a dry run that spends no rate-limit budget.