Your agent can act. Who said yes?
Written while the phone apps were still in review. All three approvers are now live: the App Store, Google Play and the Mac menu bar.
TL;DR — HumanAuth is live. Wire any agent to request approval in six lines, approve from a Mac menu-bar app (shipping now) or the iPhone app (in App Store review), and verify the signed receipt offline in your own backend.
The gap
2026 is the year agents got hands. They open PRs, move money, touch production. The auth stack answered one question well — may this agent act as you? — once, at grant time, with an OAuth screen.
But the incident reports don't come from grant time. They come from 2 a.m., when an agent with a perfectly valid token does something perfectly catastrophic. The missing primitive isn't identity. It's per-action human approval with proof.
What HumanAuth does
- Your agent hits
POST /v1/authorize— "terminate EC2 instance i-0a3f8b2c" — with a severity and a TTL. - The humans on the roster see it on their devices, in plain language. One tap, then Face ID or Touch ID.
- The decision is signed on-device — Ed25519, key in the secure enclave, never exported — and countersigned by the platform.
- Your backend — not ours — verifies the receipt with an open verifier. Offline. No callback to us, no uptime of ours in your critical path. No receipt, no action.
The approval plaintext is end-to-end encrypted: we route ciphertext, your devices hold keys. An audit trail you can hand a CISO comes free.
What ships today
- Platform — live at
api.humanauth.ai: multi-tenant, TTL'd async approvals, quorum policies (1-of-2, N-of-M). - Mac approver — a menu-bar app: request arrives, popover opens, Touch ID decides. Developer ID-signed, notarized, auto-updating. Download · macOS 14+, Apple Silicon.
- iPhone & iPad app — feature-complete, in App Store review. The listing goes live the moment Apple clears it.
- MCP server — Claude Code and Cursor get approval gates with zero code changes to your agent.
- SDK + verifier — TypeScript today; the receipt format is documented and the verifier is open, so any language can check a receipt.
What it costs
Free tier with the security features ungated — E2E encryption and offline verification are not enterprise add-ons. One meter, no cliffs. Pricing.
Where this goes
Async approvals already ride the same rails as CIBA-style backchannel authentication; we intend to meet the standards where they are, not fork them. Python SDK is next; so are the open demo repos.