Skip to content

HumanAuth

Add human approval to any AI agent in six lines. Biometric-signed. Replay-bound. Auditable.

HumanAuth is a drop-in human-approval layer for AI agents. It lets your agent ask before it acts on real money, real infrastructure, or real customer data — and gives your resource server — the service that executes the action — a cryptographic receipt it can verify offline. Three pieces ship together: an SDK for your agent to call, approver apps (Mac, iPhone and iPad, and Android) for humans to confirm with biometrics, and a verifier for your resource server to enforce the result.

HumanAuth is agent-agnostic. If your system speaks HTTP or MCP, it can request human approval through HumanAuth.

The difference from webhook-based human-in-the-loop tools: the approval doesn’t come back as a trusted callback — it comes back as a dual-signed receipt (platform key + the approver’s device key) that your own infrastructure verifies offline. No receipt, no action; one receipt, one action.


Drop-in SDK + MCP server

Six lines in your agent config and you have three new tools: authorize, collect, inform. Works with Claude, OpenAI, LangChain, CrewAI, AutoGen, custom builds.

Biometric non-repudiation

Approvals are co-signed by a key held only on the approver’s device — Secure Enclave P-256 on the Mac, keychain-stored Ed25519 on phones — gated by Touch ID / Face ID.

Offline-verifiable receipts

Your resource server verifies receipts with JWKS + plan-hash binding in ~10 lines. No RTT in your hot path. No receipt = no execution, by construction.

A platform that can't forge approvals

Receipts require two signatures over the same bytes: the platform’s and the device’s. Our servers alone cannot mint “a human approved this.” The SDK, verifier, CLI and MCP server are MIT-licensed on npm; the platform can be self-hosted under an Enterprise agreement.



A
Agent

Your code. Integrates via the HumanAuth SDK, MCP server, or plain HTTP with a tenant API key.

|
P
Platform

Cloudflare Workers at api.humanauth.ai. Stamps the canonical plan hash, runs Cedar policy, fans out push, verifies the device co-signature, mints the receipt, keeps the audit log. Structurally unable to forge an approval on its own.

|
H
Human

The approver, on the Mac menu-bar app or phone. Reviews the full context, confirms with biometrics, co-signs the exact plan-hash-bound bytes with a device-held key.

|
B
Resource server

Your execution layer. Verifies the receipt with @humanauth/verifier before performing the action. No receipt, no execution — by construction.


PrimitiveUsage
Ed25519 (EdDSA JWS)Platform receipt signatures, per-tenant keys resolved by kid
ECDSA P-256 · Secure EnclaveMac approver’s hardware-bound, biometry-gated co-signature
Ed25519 (keychain)Mobile approver’s device-held co-signature
JCS (RFC 8785) + SHA-256Plan-hash binding (parameter integrity)
DPoP-style device proofBinds /v1/respond calls to a registered device key (±60s)
AES-256-GCMPlatform signing keys encrypted at rest under a versioned KEK

PackagePurpose
@humanauth/sdkTypeScript SDK — send authorization requests from any agent
@humanauth/verifierVerifier SDK — requireReceipt() for your resource server or MCP server (guide)
@humanauth/cliCLI — manage humans/groups/keys, test approvals, verify receipts
@humanauth/mcpMCP server — drop-in human approval for any MCP-compatible agent
OpenAPI 3.1 specCodegen typed clients for Python, Go, Java, Ruby, Rust, etc.