Comparison · checked 2026-10-07

HumanAuth vs HITL.sh

Both are human-in-the-loop apps: an AI agent or automation pauses, the request reaches a person's phone, and the answer goes back. The difference is what goes back — and whether anything downstream can prove a human actually sent it.

What your system receives

HumanAuth

A receipt signed twice — by a key held only on the approver's device, and by the platform.

HITL.sh

A webhook callback carrying the response data. source

Tied to the exact action

HumanAuth

Yes. The receipt carries a hash of the action and its parameters; change one and verification fails.

HITL.sh

No hash or digest field. The request's context is “any valid JSON object”. source

Callback authenticity

HumanAuth

Webhooks are HMAC-SHA256 signed with a timestamp and a 300-second replay window. The receipt itself is verified separately.

HITL.sh

Docs advise an optional IP allowlist and checking that required fields exist. No signature header or shared secret is documented. source

Verify later, without the vendor

HumanAuth

Offline, with the open-source @humanauth/verifier. Our uptime is not in your execution path.

HITL.sh

Not documented.

Biometric on the decision

HumanAuth

Every approval: Face ID or Touch ID on Apple devices, fingerprint or face unlock on Android.

HITL.sh

Not mentioned in the docs. Account-security advice is strong passwords and two-factor authentication. source

Approver apps

HumanAuth

iPhone and iPad, Android, and a Mac menu-bar app.

HITL.sh

iPhone and Android.

Response types

HumanAuth

Approve, or deny with a reason. Quorum (N of M) and blind ballots for group decisions.

HITL.sh

Free text, editable text, single and multi select, rating, number. source

Agent and workflow integrations

HumanAuth

MCP server, TypeScript SDK, n8n community node, HTTP API. No native Make or Zapier module.

HITL.sh

Native n8n, Zapier and Make. MCP server and SDKs listed as coming soon. source

Self-hosting

HumanAuth

Yes — the platform deploys into your own Cloudflare account; the same apps and verifier work against it.

HITL.sh

Not mentioned in the docs.

Getting started

HumanAuth

Hands-on: request access and we set you up.

HITL.sh

Self-serve sign-up.

Pricing

HumanAuth

1,000 requests free every month, then $0.03 per request. Every feature on every plan.

HITL.sh

5 requests free; $9.99 for 300, $29.99 for 1,000, $99.99 for 5,000 per month. source

HITL.sh column from docs.hitl.sh and hitl.sh as published on 2026-10-07. “Not documented” means we could not find it in their public docs, not that it cannot exist. Spot something out of date? Tell us and we will correct it.

The question to ask any HITL tool

What stops a forged approval from moving money?

HITL.sh's guidance on validating callbacks begins: “While HITL.sh callback URLs are set per-request and only known to you, you should still validate incoming webhooks” — and the validation it shows is an optional IP check and a test that the expected fields are present. So the protection is that the URL stays secret.

With HumanAuth, the service that executes the action checks a receipt before it runs. The receipt carries two Ed25519 signatures, one from a key that never leaves the approver's phone, and a hash of exactly what they approved. It verifies offline and is burned after one use. A leaked URL, a replayed message or an edited amount produces nothing that verifies.

Read the security model or see how verification works.

Choose HumanAuth if

  • the action moves money, changes production or touches personal data
  • you need to prove later who approved it, to someone who wasn't there
  • your agents run in Claude Code, Cursor or another MCP client
  • you want to self-host, or to keep the vendor out of your execution path

HITL.sh may suit you better if

  • you need answers richer than approve or deny: ratings, numbers, edited text
  • your workflows live in Zapier or Make and you want a native module
  • you want to sign up and start today without a conversation

Questions

What is a good alternative to HITL.sh?

HumanAuth is a human-in-the-loop app for AI agents with approver apps for iPhone, Android and the Mac. Like HITL.sh, it sends an agent's request to a person's phone. Unlike HITL.sh, each decision comes back as a receipt signed by the approver's device and bound to the exact action, which your backend verifies offline before acting.

Why does a signed receipt matter if the callback URL is secret?

A secret URL can leak — in logs, in a proxy, in a screenshot. If whatever arrives at that URL is believed, anyone who has it can approve anything. A receipt can only be produced by the approver's device key, and it only verifies for the action that was approved, so a forged or replayed message has nothing valid to carry.

When is HITL.sh the better fit?

When you need answers richer than approve or deny — ratings, numbers, edited text, multiple choice — or native Zapier and Make modules, or you want to sign up and start without talking to anyone.

Can I use HumanAuth with n8n?

Yes. The n8n-nodes-humanauth community node pauses a workflow until a human approves and passes the signed receipt to the next step.

Try the approval that leaves proof.

The apps are free on the App Store and Google Play. Request access and we will wire your first approval with you.