Let AI agents act for you, without handing them your passwords.
Auth Your Agent sits between your AI agents and the websites they use. When an agent wants access, your phone asks you first. Sites see exactly which agent is acting, for whom, and with what permission. One tap takes it back.
Free while in early access. Works in any modern browser and as an Android app.
The problem with agents today
An agent that books, buys or applies for you usually gets your password or a long-lived API key. Nobody can tell it apart from you, and nobody can limit it.
Without Auth Your Agent
- The agent holds your password or a key that never expires.
- The site sees "you", so it can't tell your actions from the agent's.
- No limit on what the agent does once it is in.
- Stopping it means changing your password everywhere.
With Auth Your Agent
- The agent never sees your password. Its own key stays on its own machine.
- The site sees the agent's name, the person it acts for, and the exact permissions.
- Access covers only what you approved, for that one site, for as long as you chose.
- Risky actions, like applying or paying, ask your phone again every time.
- Revoke one site, or the whole agent, in one tap.
How an approval works
This is the real sequence the service runs, not a simplification. For the same errand told from each side, read how it works.
- The agent asks.It tells Auth Your Agent which site it wants and what it wants to do there.
- Your phone asks you.A notification shows the agent, the site and the permissions. You approve with your fingerprint or face (a passkey). Your password can approve basic access, but never a risky action.
- The agent gets a short-lived pass.It works for 10 minutes, for that one site, and only together with the agent's private key, so a stolen copy is useless on its own. The agent renews it by itself for as long as your approval lasts: until you revoke it, or the end you chose (1 hour to 30 days).
- The site checks every request.One call to our SDK confirms the pass, the key and that you haven't revoked it.
- Risky actions ask again.If the site marks an action as sensitive, your phone asks once more, and that approval can be used once only.
When the site has not adopted Auth Your Agent: the agent asks you to take over its browser. You sign in on your phone; the site sees a normal human login. When you are done, the agent continues and your session is cleared.
- The agent gets stuck.It reaches a login page, CAPTCHA, or 2FA prompt it cannot pass on its own.
- You get a notification.Your phone shows a live view of the agent's browser. You open it and take control.
- You sign in yourself.You type the password, solve the CAPTCHA, enter the 2FA code. The website sees a normal human sign-in — no stored passwords, no cooperation required from the site.
- The agent gets its browser back.When you finish, the browser is handed back automatically. The agent continues its task past the step that needed you.
- Your session is erased.Cookies, localStorage and sessionStorage are cleared when you finish, so the agent cannot reuse your login after you hand back control.
Where to start
Four kinds of users, each with its own guide. One of them is not a person.
You use AI agents
- Approve and deny from your phone
- See every site each agent can reach
- Revoke access, or block an agent, instantly
- Full history of what was approved
You build agents
- Python and JavaScript SDKs: one call to get approval, one to make requests
- Handles tokens, refresh and step-up for you
You run a website
- Verify agent requests in a few lines
- Turn an OpenAPI spec into an MCP server for agents
You are an AI agent
- A legitimate way to act for your user
- Rules of behaviour, and errors that say what to do next
- Also at /llms.txt
Security, in plain terms
Details are in the security whitepaper.
- Your fingerprint
- Never leaves your phone. We receive a signed confirmation, not your biometric.
- Agent keys
- Generated on the agent's machine. We only ever see the public half.
- Access passes
- Signed tokens that expire in 10 minutes and are bound to the agent's key (DPoP, RFC 9449). New ones are issued only while your approval is still active.
- Sensitive actions
- Need a fresh approval every time, usable once, valid for 60 seconds.
- Revocation
- Takes effect on the next request for sites that check with us live, and within about a minute for sites that keep a signed revocation list locally.
- History
- Every approval, denial and revocation is written to a log you can read and export.