Browse docs · Guides
Get started
Concepts
Guides
Security
Reference
Docs / Guides
Claude Code and MCP
Run the PastKeys MCP server so Claude Code and other MCP agents can perform authorized operations with no provider credential in their tools.
The broker ships an MCP server. Point an MCP-capable agent at it and its tools ask the broker to act, instead of holding provider tokens themselves.
The tools
| Tool | What it does |
|---|---|
pastkeys_list_providers | Lists providers and their actions |
pastkeys_authorize | Dry-run: would this operation be allowed? |
pastkeys_execute | Performs an operation; returns the result, or approval_required |
pastkeys_check_operation | Polls an operation waiting for approval |
pastkeys_usage | Shows usage against the plan |
Configure Claude Code
Add the server to your project's .mcp.json:
{
"mcpServers": {
"pastkeys": {
"command": "/path/to/pastkeys",
"args": ["mcp", "--broker-url", "http://127.0.0.1:8080"],
"env": { "PASTKEYS_AGENT_TOKEN": "<agent token>" }
}
}
}
The MCP server reads PASTKEYS_BROKER_URL and PASTKEYS_AGENT_TOKEN if you prefer environment variables. The agent token identifies the agent to the broker; it carries no provider access on its own, and the policy decides what the agent may do.
Why this is safer
- No provider token sits in the MCP server's environment for a prompt injection to reach.
- An injected tool call can only request operations the policy already allows, and each attempt is audited.
- Sensitive operations can require approval, and a lockdown stops everything at once.