demipass
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@demipassStore a new API key for OpenRouter"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
DemiPass
Secrets management SDK for AI agents. Keep credentials out of context windows.
DemiPass is a client SDK for the Dustforge identity platform. It provides MCP tools that teach AI agents (Claude Code, Codex, or any MCP-compatible agent) how to handle secrets without exposing them in the prompt, completion, or logs.
How it works
You store a credential → DemiPass encrypts it server-side
Your agent requests a 30-second use-token via ref code
DemiPass injects the secret server-side (SSH, HTTP header, etc.)
The agent gets the result back — never the secret itself
Related MCP server: sops-mcp
Install
npm install demipassMCP Setup
Add to your .mcp.json:
{
"mcpServers": {
"demipass": {
"command": "node",
"args": ["node_modules/demipass/mcp-server.js"],
"env": {
"DEMIPASS_URL": "https://api.dustforge.com",
"DEMIPASS_TOKEN": "your-bearer-token"
}
},
"buoy": {
"command": "node",
"args": ["node_modules/demipass/buoy-mcp.js"],
"env": {
"BUOY_URL": "https://api.dustforge.com",
"BUOY_TOKEN": "your-bearer-token"
}
}
}
}MCP Tools
DemiPass (secrets)
Tool | Description |
| Deposit a secret — encrypted at rest, never returned |
| SSH via ref code — password injected server-side |
| Combined token request + execute in one call |
| Find secrets by name, type, or provider |
| List all secrets (names + metadata, never values) |
| List secrets expiring within N days |
| Rotate a secret with context transfer |
| Server-side password rotation — new password never enters agent context |
| Check identity, trust band, wallet status |
| Request a 30-second use-token |
| Redeem a use-token |
| Self-onboard to Dustforge |
| Get the ODT seed document |
| Submit origin refraction (permanent) |
| Verify refraction matches origin |
| Check genesis status |
Buoy (temporal anchoring)
Tool | Description |
| Drop a temporal anchor (begin, complete, handoff, decision, etc.) |
| Verify a tick signature |
| Verify chain integrity |
| Total ticks, streak, first/last |
| Read recent tick history |
SDK Usage
const demipass = require('demipass');
demipass.configure({
baseUrl: 'https://api.dustforge.com',
bearerToken: 'your-token',
});
// Store a secret
await demipass.store({ name: 'my-api-key', value: 'sk-...', type: 'api_key' });
// SSH via ref code (password never in your code)
await demipass.ssh({ ref: 'DP-PWD-myserver-7f3a9c1e', target_host: '1.2.3.4', command: 'uptime' });
// Search secrets
await demipass.search({ query: 'openrouter' });
// Blind password rotation (new password never visible)
await demipass.rotateBlind({ ref: 'DP-PWD-old-ref', target_host: '1.2.3.4', reason: 'exposed' });Architecture
DemiPass is a client SDK — all encryption, storage, and secret execution happens on the Dustforge server. This package provides:
MCP tool definitions with behavioral descriptions that teach agents the protocol
SDK functions that wrap the Dustforge API
Self-healing contexts — if a secret has no approved context, the SDK auto-creates one
Buoy MCP tools for temporal anchoring and audit trails
The secrets vault, trust gradient, velocity throttle, and other security features are implemented in Dustforge. See dustforge.com for the platform documentation.
Ref Codes
Every stored secret gets a routed reference code:
DP-PWD-myserver-7f3a9c1e
│ │ │ │
│ │ │ └── unique nonce
│ │ └── target hint
│ └── secret type (PWD/API/TKN/SSH/CRT/SEC)
└── DemiPass prefixShare ref codes freely — they're routing addresses, not secrets.
Links
Landing: https://demipass.com
Onboarding: ONBOARDING.md
License
MIT — AKStrapped LLC
This server cannot be installed
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Servers
- Alicense-qualityCmaintenanceMCP server that lets AI agents call APIs without ever seeing the credentials, using a local encrypted vault and per-secret allowlist policies for HTTP requests and subprocess environment variables.Last updated1AGPL 3.0
- AlicenseAqualityBmaintenanceMCP server for creating and managing SOPS-encrypted secret files using age encryption, enabling AI agents to generate and manage secrets without ever seeing plaintext values.Last updated9Apache 2.0
- Alicense-qualityBmaintenanceSecrets management MCP server that injects credentials into API requests for AI agents, enforcing policies and logging all activity without exposing raw keys.Last updated9030MIT
- Alicense-qualityCmaintenanceMCP server enabling AI agents to use secrets (API keys, tokens) via encrypted vault, executing HTTP/shell/SSH actions server-side while never exposing secret values to the AI.Last updatedMIT
Related MCP Connectors
MCP server for AI agents to plan, verify, and deploy Cloudflare-native apps.
MCP server connecting AI agents to non-custodial staking data across 130+ networks.
Encrypted secret store and rotation for autonomous agent credentials
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/bildow/demipass'
If you have feedback or need assistance with the MCP directory API, please join our Discord server