Credential custody for agents: use secrets blind (ssh/http/smtp/git/db), never in context.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
π‘ Paste into ~/Library/Application Support/Claude/claude_desktop_config.json (macOS) or %APPDATA%\Claude\claude_desktop_config.json (Windows)
Secrets management SDK for AI agents. Keep credentials out of context windows.
DemiPass is a client SDK for the Dustforge identity platform. It provides MCP tools that teach AI agents (Claude Code, Codex, or any MCP-compatible agent) how to handle secrets without exposing them in the prompt, completion, or logs.
Add to your .mcp.json:
| Tool | Description |
|---|---|
demipass_store | Deposit a secret β encrypted at rest, never returned |
demipass_ssh | SSH via ref code β password injected server-side |
demipass_use | Combined token request + execute in one call |
demipass_search | Find secrets by name, type, or provider |
demipass_list | List all secrets (names + metadata, never values) |
demipass_expiring | List secrets expiring within N days |
demipass_rotate | Rotate a secret with context transfer |
demipass_rotate_blind | Server-side password rotation β new password never enters agent context |
demipass_whoami | Check identity, trust band, wallet status |
demipass_get_token | Request a 30-second use-token |
demipass_execute | Redeem a use-token |
demipass_onboard | Self-onboard to Dustforge |
demipass_genesis_seed | Get the ODT seed document |
demipass_genesis_submit | Submit origin refraction (permanent) |
demipass_genesis_verify | Verify refraction matches origin |
demipass_genesis_status | Check genesis status |
| Tool | Description |
|---|---|
buoy_tick | Drop a temporal anchor (begin, complete, handoff, decision, etc.) |
buoy_verify | Verify a tick signature |
buoy_chain_verify | Verify chain integrity |
buoy_stats | Total ticks, streak, first/last |
buoy_ledger | Read recent tick history |
DemiPass is a client SDK β all encryption, storage, and secret execution happens on the Dustforge server. This package provides:
The secrets vault, trust gradient, velocity throttle, and other security features are implemented in Dustforge. See dustforge.com for the platform documentation.
Every stored secret gets a routed reference code:
Share ref codes freely β they're routing addresses, not secrets.
MIT β AKStrapped LLC
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/demipass)<a href="https://allmcps.com/mcp/demipass"><img src="https://allmcps.com/api/badge/demipass?style=directory" alt="Demipass on AllMCPs" /></a>