Drop-in SDK + MCP server
Six lines in your agent config and you have three new tools:
authorize, collect, inform.
Works with Claude, OpenAI, LangChain, CrewAI, AutoGen, custom builds.
HumanAuth is a drop-in human-approval layer for AI agents. It lets your agent ask before it acts on real money, real infrastructure, or real customer data — and gives your resource server — the service that executes the action — a cryptographic receipt it can verify offline. Three pieces ship together: an SDK for your agent to call, approver apps (Mac, iPhone and iPad, and Android) for humans to confirm with biometrics, and a verifier for your resource server to enforce the result.
HumanAuth is agent-agnostic. If your system speaks HTTP or MCP, it can request human approval through HumanAuth.
The difference from webhook-based human-in-the-loop tools: the approval doesn’t come back as a trusted callback — it comes back as a dual-signed receipt (platform key + the approver’s device key) that your own infrastructure verifies offline. No receipt, no action; one receipt, one action.
Drop-in SDK + MCP server
Six lines in your agent config and you have three new tools:
authorize, collect, inform.
Works with Claude, OpenAI, LangChain, CrewAI, AutoGen, custom builds.
Biometric non-repudiation
Approvals are co-signed by a key held only on the approver’s device — Secure Enclave P-256 on the Mac, keychain-stored Ed25519 on phones — gated by Touch ID / Face ID.
Offline-verifiable receipts
Your resource server verifies receipts with JWKS + plan-hash binding in ~10 lines. No RTT in your hot path. No receipt = no execution, by construction.
A platform that can't forge approvals
Receipts require two signatures over the same bytes: the platform’s and the device’s. Our servers alone cannot mint “a human approved this.” The SDK, verifier, CLI and MCP server are MIT-licensed on npm; the platform can be self-hosted under an Enterprise agreement.
Your code. Integrates via the HumanAuth SDK, MCP server, or plain HTTP with a tenant API key.
Cloudflare Workers at api.humanauth.ai. Stamps the canonical plan hash, runs Cedar policy, fans out push, verifies the device co-signature, mints the receipt, keeps the audit log. Structurally unable to forge an approval on its own.
The approver, on the Mac menu-bar app or phone. Reviews the full context, confirms with biometrics, co-signs the exact plan-hash-bound bytes with a device-held key.
Your execution layer. Verifies the receipt with @humanauth/verifier before performing the action. No receipt, no execution — by construction.
| Primitive | Usage |
|---|---|
| Ed25519 (EdDSA JWS) | Platform receipt signatures, per-tenant keys resolved by kid |
| ECDSA P-256 · Secure Enclave | Mac approver’s hardware-bound, biometry-gated co-signature |
| Ed25519 (keychain) | Mobile approver’s device-held co-signature |
| JCS (RFC 8785) + SHA-256 | Plan-hash binding (parameter integrity) |
| DPoP-style device proof | Binds /v1/respond calls to a registered device key (±60s) |
| AES-256-GCM | Platform signing keys encrypted at rest under a versioned KEK |
| Package | Purpose |
|---|---|
@humanauth/sdk | TypeScript SDK — send authorization requests from any agent |
@humanauth/verifier | Verifier SDK — requireReceipt() for your resource server or MCP server (guide) |
@humanauth/cli | CLI — manage humans/groups/keys, test approvals, verify receipts |
@humanauth/mcp | MCP server — drop-in human approval for any MCP-compatible agent |
| OpenAPI 3.1 spec | Codegen typed clients for Python, Go, Java, Ruby, Rust, etc. |