Coming soon

Your AI never sees the secret

Store API keys, passwords, and tokens. Your agent requests a 30-second use-token; DemiPass injects the secret server-side. The credential never enters the prompt, the completion, or the logs.

Join the waitlist

DemiPass is launching soon. Leave your email and we'll let you know the moment it's live.

Why DemiPass

Built for the era where autonomous agents hold the keys.

Use-Tokens

Agents get a single-use, 30-second nonce — never the credential itself. The secret is injected server-side at the moment of use.

Context Binding

Every use-token is bound to a specific action and target. A token minted for one call can't be replayed against another.

Bonded Courier

The secret travels from vault to destination without ever passing through the model's context window, completion, or logs.

Honeypot Defense

Decoy credentials detect and flag misuse, surfacing compromised agents before real secrets are ever at risk.

Credential Health

Track every secret's age, usage, and exposure. Rotate on a schedule or instantly when something looks wrong.

Circuit Breakers

Per-secret rate and scope limits halt runaway or hijacked agents automatically, before a leak becomes a breach.

How it works

1

Deposit

Store your API keys, passwords, and tokens in the DemiPass vault — encrypted, never exposed to your agent.

2

Request

Your agent asks DemiPass for a short-lived use-token bound to the exact action it needs to perform.

3

Inject

DemiPass redeems the token and injects the real secret server-side. The credential never enters the prompt.

Part of the Dustforge ecosystem

DemiPass is one piece of Dustforge — infrastructure for trustworthy autonomous agents. More coming soon.