The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Demipass listing page.
Secrets management SDK for AI agents. Keep credentials out of context windows.
DemiPass is a client SDK for the Dustforge identity platform. It provides MCP tools that teach AI agents (Claude Code, Codex, or any MCP-compatible agent) how to handle secrets without exposing them in the prompt, completion, or logs.
Add to your .mcp.json:
| Tool | Description |
|---|---|
demipass_store | Deposit a secret — encrypted at rest, never returned |
demipass_ssh | SSH via ref code — password injected server-side |
demipass_use | Combined token request + execute in one call |
demipass_search | Find secrets by name, type, or provider |
demipass_list | List all secrets (names + metadata, never values) |
demipass_expiring | List secrets expiring within N days |
demipass_rotate | Rotate a secret with context transfer |
demipass_rotate_blind | Server-side password rotation — new password never enters agent context |
demipass_whoami | Check identity, trust band, wallet status |
demipass_get_token | Request a 30-second use-token |
demipass_execute | Redeem a use-token |
demipass_onboard | Self-onboard to Dustforge |
demipass_genesis_seed | Get the ODT seed document |
demipass_genesis_submit | Submit origin refraction (permanent) |
demipass_genesis_verify | Verify refraction matches origin |
demipass_genesis_status | Check genesis status |
| Tool | Description |
|---|---|
buoy_tick | Drop a temporal anchor (begin, complete, handoff, decision, etc.) |
buoy_verify | Verify a tick signature |
buoy_chain_verify | Verify chain integrity |
buoy_stats | Total ticks, streak, first/last |
buoy_ledger | Read recent tick history |
DemiPass is a client SDK — all encryption, storage, and secret execution happens on the Dustforge server. This package provides:
The secrets vault, trust gradient, velocity throttle, and other security features are implemented in Dustforge. See dustforge.com for the platform documentation.
Every stored secret gets a routed reference code:
Share ref codes freely — they're routing addresses, not secrets.
MIT — AKStrapped LLC