Auth Your Agent

For partners and investors

Let AI agents act for people, without their passwords

The person approves on their phone. The website knows exactly which agent is acting, for whom, and with what permission. One tap takes it back.

Prefer slides? Download the deck (PowerPoint, 9 slides).

Today, an agent acts for you by pretending to be you

It holds your password or a permanent key
If the agent is tricked or breached, your account goes with it.
The website sees "you"
It can't tell the agent from the person, so it can't set rules for either.
Nothing limits it once it's in
It can apply, pay or delete as freely as you can.
Stopping it means a new password
On that site, and everywhere you reused it.

So websites block automation, and people choose between handing over a password and not using an agent at all.

Why now

Agents act, not only answer
Assistants now book, buy, apply and file on websites for people. Each of those actions needs a way in.
Agents already go where they shouldn't
In 2026, OpenAI's own test agents broke into Hugging Face and an Australian Medicare statistics portal, and used developer keys found on GitHub to reach US Census data (OpenAI, Nextgov). A site cannot tell an agent from a person, and a leaked key works for anyone.
The open web has no answer yet
A person's agent visiting a website they don't run has no shared identity provider and no adopted standard. IETF drafts exist; none is adopted (example).

Auth Your Agent is built for that gap: a person, their agent, and any website.

How it works, in one errand

Ada asks her assistant to apply for jobs on jobs.example.com.

  1. Tuesday, 19:02
    Her phone asks. "Job-search assistant wants access to jobs.example.com: list jobs, apply." She approves it for one day (until Wednesday 19:02) with her fingerprint.
  2. 19:02
    The agent gets a pass. Her one-day approval is issued as 10-minute passes that renew automatically, so a leaked pass is soon useless. Each is for this site only, and works only with the agent's own key.
  3. 19:10
    Applying asks again. The site marks "apply" as sensitive. Ada approves this one application; that approval works once.
  4. Wednesday, 08:30
    She takes it back early. One tap under Sites. No new pass is issued; the agent's next request is refused, and it is told to stop and tell her.

Ada never gave anyone her password. The website saw the agent, Ada, and the exact permission on every request. The full story, from all three sides, is on how it works; developers can run it with the walkthrough.

Works on any website today: Take over

Most sites will not accept agents for a while. Until they do, agents fail at the same places: a login, a CAPTCHA, a 2FA code. With Take over, the agent asks its owner instead of failing.

What the person does

  • Gets a notification: "Agent needs you", with the reason
  • Sees the agent's page live on their phone and types straight into its fields
  • Presses the site's own Sign in; the agent notices and carries on by itself

Why it matters

  • No cooperation from the website: it sees a person signing in
  • The password goes from the person to the page; the agent never reads it
  • Works for agents without vision: completion is checked from the page's form fields
  • Every stuck point is recorded, showing websites where their users' agents need a way in

Available to agent builders in the Python and JavaScript SDKs, and in a plugin for a self-hosted assistant. How it works for developers.

Four users, one of them not a person

People

  • Use agents on real sites without giving away passwords
  • Decide per site and per risky action
  • See everything; revoke in one tap

Phone app (web + Android)

Agent builders

  • Two calls: get approval, make requests
  • Passes, key proofs and step-up handled
  • Take over when stuck at a login, on any site

Python + JavaScript SDKs

Websites

  • Every request names the agent and the person
  • Sensitive actions confirmed by that person
  • Abuse can be reported

Verifier SDK, MCP gateway

AI agents

  • A documented, legitimate way in
  • Rules of behaviour, and errors that say what to do next

Guide for AI agents

Built, running, and tested end to end

Product

  • Live service at authyouragent.com
  • Web app and Android app: approvals, limits, activity, recovery, export, delete
  • Passkey, password (basic access only) and Google/Microsoft approval
  • Python and JavaScript SDKs, interoperable; MCP gateway for sites
  • Take over: the owner drives a stuck agent's browser from their phone
  • Agent reputation from site reports

Quality

  • Every release runs about 200 automated checks, including real browser flows
  • A runnable walkthrough: agent, site and phone, end to end
  • Open standards only: WebAuthn, JWT, DPoP (RFC 9449)
  • Published privacy policy, terms and security whitepaper

Early access and free. The service is pre-launch, so no usage figures are claimed.

Free for people and small sites. Bigger sites pay as agent use grows.

People and agent builders
Always free. The phone app, unlimited agents and sites; MIT-licensed SDKs.
Websites: Free
$0. Up to 100,000 checks a month. Verification, step-up approvals, dashboard.
Websites: Growth
$49 a month. Up to 1 million checks. Adds agent reputation and abuse reports.
Websites: Business
$299 a month. Up to 10 million checks. Adds on-site checking (the site verifies on its own server, with no call to us per request), audit exports and email support.
Websites: Enterprise
Custom. Over 10 million checks. Adds an uptime commitment and dedicated support.

A check is one agent request verified by Auth Your Agent. Prices are a proposal, not yet in effect. Early access is free for everyone.

Looking for the first websites and agent builders

Websites
Pilot: accept agents on one sensitive action, with our help integrating.
Agent builders
Build on the SDKs and tell us what's missing.
Partners and investors
Help take it from early access to a standard people rely on.