Docs / Get started

Quickstart

Set up PastKeys in about ten minutes: create an account, run a broker, seal a provider credential, write a policy, and make your first brokered call.

This walks through one complete brokered call: an agent reads DNS records from Cloudflare without ever seeing the Cloudflare token. Every step is also available inside the dashboard's guided setup.

1. Create an account

Sign up with email or GitHub. The free plan covers 3 agents and 10,000 operations a month.

2. Create a broker token

In the dashboard open Brokers and choose Add broker. Copy the token: it is shown once. The broker uses it to fetch its configuration and push audit records.

3. Download and start the broker

curl -fsSL https://pastkeys.com/download/broker-linux-amd64 -o pastkeys
chmod +x pastkeys
sha256sum pastkeys   # compare with https://pastkeys.com/download/SHA256SUMS

./pastkeys keygen --out custody.key

export BROKER_CONTROLPLANE_URL=https://pastkeys.com
export BROKER_TOKEN=pk_brk_...            # from step 2
export BROKER_CUSTODY_KEY_FILE=custody.key
./pastkeys serve --addr 127.0.0.1:8080

Builds exist for Linux and macOS (amd64, arm64) and Windows. The broker registers its public key and shows as online in the dashboard within seconds. The private key in custody.key never leaves this machine. Run ./pastkeys doctor to check the setup.

4. Seal a provider credential

Seal the Cloudflare token to the broker's public key on a trusted machine (the dashboard shows the exact command with your key filled in):

./pastkeys seal --pubkey '<broker public key>'
# paste the token, press Ctrl-D, copy the sealed blob

In Credentials, choose Store credential, pick cloudflare, and paste the blob. PastKeys stores only the ciphertext.

5. Write a policy

In Policies, add a policy that lets one agent read DNS for one zone. Everything else stays denied.

{"agent": "demo-agent",
 "rules": [{"provider": "cloudflare", "resource": "example.com", "actions": ["DNS_READ"]}]}

6. Give the agent an identity

In Agents, add demo-agent and choose Generate token. For CI and cloud workloads, use workload identity instead so there is no long-lived token at all.

7. Make the call

curl -sS http://127.0.0.1:8080/v1/actions \
  -H "Authorization: Bearer $AGENT_TOKEN" \
  -d '{"provider":"cloudflare","resource":"example.com","action":"DNS_READ"}'

The broker authenticates the agent, checks the policy, uses the sealed token, and returns the records. Open Audit log to see the event. Try an action the policy does not allow, such as DNS_DELETE, and you get 403 with reason action_not_allowed.

Next: learn how a request flows, or connect a real provider with the Cloudflare, AWS, GitHub or Postgres guide.