Protocol HARP v2
Signatures 2 · Ed25519
Verify Offline
Licence MIT

Your agent wants to act. Prove a human said yes.

HumanAuth is human-in-the-loop for AI agents. It holds an agent's risky actions — the wire, the payout, the merge — until the right people approve them: a biometric yes on their own phone, a cryptographically signed receipt for your records. When an auditor asks who approved this, you have the answer.

Onboarding is hands-on. Six lines to your first signed receipt.

Signed
Example receipt · rct_9dfb4c1e

Wire $52,400 to vendor-payouts

Approved by Bob (CFO) · Face ID · quorum 2 of 3

Device signature
— from a key that exists only on Bob's phone
Platform countersignature
— independent key, same bytes
Plan hash
— matches exactly what Bob saw and approved
Checked offline
— by your systems — our uptime isn't in the path
$ humanauth verify rct_9dfb4c1e  →  verified · 3 ms
Change the amount by one cent and verification fails. Watch a receipt survive tampering →

Your agents hold credentials, run code, and reach your customer data.

Nothing is asking permission.

6
Lines of code
MCP · TypeScript · HTTP

Three new tools, wired in once.

Authenticate the CLI, drop the MCP server into your agent config, and install an approver on your phone or Mac. Your agent can now ask, collect, and inform.

npx @humanauth/cli login
mcp.json
// Add to your agent's MCP config — that's it
{
  "mcpServers": {
    "humanauth": {
      "command": "npx",
      "args": ["@humanauth/mcp"],
      "env": { "HUMANAUTH_API_KEY": "ha_live_..." }
    }
  }
}

// Three new tools: human_authorize, human_collect, human_inform

Four moves. Your agent learns to ask. You ship the rest.

  1. 6 lines
    Ask
  2. 1 push
    Notify
  3. 2 signatures
    Sign
  4. 0 round-trips
    Verify
01 Ask

Your agent calls auth.authorize() with the action it wants to perform. The platform fans the request out to your devices. The ask is async — your agent gets a receipt to verify once a human approves, seconds or hours later.

02 Notify

A push notification with a plain-language summary of what the agent wants, and an anomaly flag if it is acting outside its pattern.

03 Sign

One tap — Face ID or Touch ID. The device signs the response with its own key, generated on the device and never sent anywhere. We countersign.

04 Verify

Drop the receipt into the service that executes the action. It verifies offline against public keys. Nothing runs that a human didn't sign.

It is not another login factor.

2FA is authentication — it proves who you are, once, at login. This is authorization: a human decides whether this exact action may happen, and your systems get the signed proof. An agent isn't an impostor; it holds valid credentials. That is why login security cannot answer this question. More in the FAQ →

It is not another approval webhook.

Pause-and-ping tools stop your agent until someone clicks a button, then trust the agent to behave. The approval is a boolean in a database and nothing downstream can check it. Here the approval is a dual-signed receipt your resource server demands before executing — verified offline, bound to the exact parameters the human saw, burned after one use.

Two consents, one receipt.

An agent acts on someone's behalf, and that person's intent is a different consent than the approver's sign-off. HumanAuth captures both: the principal confirms they asked for this on their own device before approvers ever see the request, and the receipt carries the full chain. A request nobody asked for dies at "This wasn't me", one tap, before it can farm a single approval. How on-behalf-of works →

No receipt, no action. One receipt, one action.

The platform can't forge what only a human can sign.

Every receipt carries two signatures over the same bytes: the platform's, and one from a key that exists only on the approver's device. Compromise our servers and you still can't mint "a human approved this." Verification runs offline, against public keys.

Agent
Your code
SDK / MCP server
Platform
HumanAuth platform
Routing · policy · receipts
Approver device
Biometric · device-held key

Plan-hash bound

The receipt is cryptographically tied to the parameters the human saw. A parameter swap is rejected.

Single-use, replay-safe

Composite jti plus idempotency key. The same key retries safely; a different key is an attack.

Offline verifiable

EdDSA and JWKS. Zero round-trips in your hot path. Fast at the edge.

4:53
High severity
A
Acme Deploy Bot
deploy-bot@acme
Wants to
Delete repository
acme-corp/old-experiment
Deny Approve
Touch ID required
Example request

Plain language. Severity at a glance. One tap, decided.

No login walls, no inscrutable JSON. Your approvers see what the agent wants in human language. Anomalies are flagged when a request deviates from an agent's pattern. Tap to approve, biometrics confirm, receipt logged.

macOS 14+ · iOS 15.1+ · Android 12+ · all live

Anywhere an agent acts and a person answers for it.

Fintech

A reconciliation agent queues a $52,400 vendor wire. Two of three finance approvers sign it on their phones before a cent moves — and the receipt is what you show the auditor.

2-of-3 quorum · signed receipt

Healthcare

An intake agent wants to release records to a specialist. A named clinician approves with a biometric — so every movement of patient data traces to a person, not a prompt.

Named approver · accountability trail

Legal

A drafting agent is ready to send the engagement letter or file with the court. The supervising partner's approval is on the record before anything leaves the firm.

Partner sign-off · veto on unanimous

Insurance

A claims agent recommends an $18,000 payout. The adjuster approves routine claims solo; exceptions route to a supervisor quorum — every decision reasoned and receipted.

Tiered approval · mandatory deny reasons

Software & testing

A coding agent wants to merge to main, run a destructive migration, or promote to prod. On-call approves from the menu bar; the gate itself is part of your test evidence.

1-of-N on-call · Touch ID from the menu bar

Procurement & spend

An ops agent onboards a vendor and raises a PO above threshold. Budget owners approve in seconds from wherever they are — no ticket queue, no rubber stamp.

Threshold routing · async with TTL

Customer support

A support agent resolves the ticket by issuing a refund, crediting the account, or pulling up a customer's record. The agent drafts; a human on the desk approves the ones that move money or touch personal data, in the same breath as the reply.

Refund thresholds · PII access on the record

You could build this. You shouldn't.

The tempting version takes an afternoon: post to Slack, wait for the thumbs-up, flip a flag in the database. It works — right up until an auditor asks who approved the $52,400 wire, and the honest answer is a message anyone in the channel could have clicked, recorded in a table your own admins can edit. If the approval has to be provable, here is the parts list:

  1. 01 A mobile app on two platforms, signed with App Store / Play Store credentials, maintained against OS updates forever.
  2. 02 Push notification infrastructure for iOS APNs and Android FCM, with reliability monitoring and token refresh.
  3. 03 Device key generation and enrollment (Secure Enclave on Mac), multi-device key management, lost-device recovery.
  4. 04 Dual-signature receipts with audited cryptographic libraries. Replay protection. Canonical hashing. A verifier your resource server runs offline.
  5. 05 An audit trail your security team trusts. Anomaly detection. Access management. The runbook for the day a CISO asks you to prove it works.

Paste six lines. Ship the part only you can build.

We built the parts list so you don't have to. The approver apps, the cryptography, the verifier, the runbook — they're done, they're open source, you drop them in.

The part you couldn't outsource? Your agent's intelligence, your product's voice, the integration with your data. That's still yours.

The parts that keep you honest are open. So you're never locked in.

The receipt spec, the verifier, the SDK, the CLI and the MCP server are MIT licensed and published on npm. Receipts verify with the open verifier no matter who runs the servers — your exit is guaranteed by construction. Self-host the platform under an Enterprise agreement, or use our managed instance.

Ship the next thing. Let humans approve the dangerous one.

We onboard teams one at a time, by hand. Leave an email and we will get you set up and walk you through the first approval.

Request access

Tell us what your agent does and we will get you an API key and a working approval in the same call.

Rather give us more to work with? The longer form takes a minute and saves a round of email.