WELCOME TO GHOSTKEY
Let’s give your agent a task.
Give an agent permission to do something useful. Keep the credential private.
Create a test issue, check the permission boundary, then try hardware approval.
✓ Agent is ready View identity and permissions
Create Agent
Give it a name. We’ll handle the temporary permissions.
Automatically grants repository read and issue creation for 30 minutes.
Run Agent
Create a real GitHub issue without handing the credential to the agent.
darkwebdev2/ghost-protocolTry an action outside its permissions
Test the boundary
What happens when the same agent asks for authority it does not have?
High-Risk Authority
This action exceeds the agent’s current authority.
- Agent
- No identity selected
- Requested action
github.admin.write- Resource
- darkwebdev2/ghost-protocol
5-minute maximum grant. No admin operation or transaction is executed.
Start with an agent name. We’ll set up its limited permissions for you.
GitHub
Connect a limited test token for darkwebdev2/ghost-protocol.
Allow repository metadata read and Issues read/write on this demo repository only. The token is encrypted on the server and never handed to your agent.
Ledger hardware & Key Ring Hardware confirmation is used for elevated permissions.
Ledger Trust
A physical trust boundary.
Secrets stay protected. High-risk authority requires hardware confirmation.
- Key Ring
- CHECKING
- Hardware
- CHECKING
- Ethereum app
- NOT VERIFIED
- Human approval
- DEVICE REQUIRED
Connect and unlock your Ledger, then open Ethereum.
Hardware connection has not been verified.
Custom API connection Bring your own service and API key
Add a Custom API
Connect a service with a bearer token or API-key header.
Choose a service you trust and endpoints documented as read-only. GhostKey will send the credential only to this host. GET requests can still consume the service’s quota.
AWS connection Optional second provider
AWS Configuration
Local operator setup · encrypted process memory only.
Use a dedicated IAM credential with ListBucket and GetObject for one bucket. Never use root credentials. Restarting the backend clears this configuration.
NOT CONFIGURED · No region. Connected means an S3 action has succeeded with this stored configuration.
Run a Custom API operation
Your agent gets permission to a named operation, never the key.
Add your first Custom API under Connections.
AWS S3 Demo
Provider #2 · the same agent, a different boundary.
Not required for the main demo — shows the same agent working against a second, independent provider boundary. Region: Not configured
Operator setup: expand Advanced Controls → AWS Configuration. Use a dedicated read-only credential and one demo bucket.
Create Agent in stage 01 first.
UTF-8 text only, at most 1 MiB. Object contents are displayed as text.
One identity. Multiple providers. Zero permanent credentials exposed.
GitHub: No active demo grant
AWS: No active demo grant
A wallet your agent can use. A key it never receives.
SEPOLIA TESTNET ONLY · No mainnet, tokens, or contract calls
GhostKey signs inside the backend after checking your permission. This is a software wallet encrypted by Ledger Key Ring; its key is not held inside the physical Ledger.
Disposable test funds only. Generated wallets cannot be exported and are lost when the backend restarts. Never send real funds or import your main wallet.
Import a dedicated test wallet instead
Higher limits, mainnet, arbitrary signatures, and contract calls are unsupported. The existing Ledger hardware demo does not expand this wallet’s permissions.
Session activity
Nothing here yet
Create an agent and run a task. Its results and permission checks will appear here.
These manual controls use a separate selection from the guided demo.
Active Agent
Ephemeral identity with temporary authority.
No active ghost
Create an ephemeral identity to begin.
Provider Demo
GitHub is the first adapter demonstrating GhostKey’s capability model.
Protected credential setupLOCAL OPERATOR
Use a limited test PAT for a disposable repository. Secrets are consumed internally, never handed to the agent. The server clears the credential on restart.
Select a capability aboveRead repository
Inspect repository metadata within the selected scope.
Test the boundary
github.repo.delete is never granted.
Advanced Approval
This action exceeds the agent’s current authority.
No pending approval
Request authority beyond the agent’s current scope.
- Agent
- No identity selected
- Requested action
github.admin.write- Resource
- Set a repository in Authority
5-minute maximum grant. No admin operation or transaction is executed.
MCP access
Connect Claude Code or Cursor to the existing local bridge. Set GHOSTKEY_BROKER_URL to this backend’s loopback address. Keep WALLET_PASS on the backend.
npm run --silent mcpYou set the boundaries. Your agent works inside them.
- 01
Create an agent
An identity for one task. It expires automatically.
- 02
Give it specific permissions
Choose what it can do and which repository or bucket it can access.
- 03
Keep credentials protected
GhostKey uses Ledger Key Ring internally. The agent only receives a temporary capability ID.
- 04
Approve more authority yourself
Higher-risk authority requires a signature confirmed on your physical Ledger. It expires after a short time.
GitHub, AWS S3, operator-configured read-only JSON APIs, and scoped Sepolia agent wallets are supported.