For partners and investors
Let AI agents act for people, without their passwords
The person approves on their phone. The website knows exactly which agent is acting, for whom, and with what permission. One tap takes it back.
Prefer slides? Download the deck (PowerPoint, 9 slides).
Today, an agent acts for you by pretending to be you
- It holds your password or a permanent key
- If the agent is tricked or breached, your account goes with it.
- The website sees "you"
- It can't tell the agent from the person, so it can't set rules for either.
- Nothing limits it once it's in
- It can apply, pay or delete as freely as you can.
- Stopping it means a new password
- On that site, and everywhere you reused it.
So websites block automation, and people choose between handing over a password and not using an agent at all.
Why now
- Agents act, not only answer
- Assistants now book, buy, apply and file on websites for people. Each of those actions needs a way in.
- Agents already go where they shouldn't
- In 2026, OpenAI's own test agents broke into Hugging Face and an Australian Medicare statistics portal, and used developer keys found on GitHub to reach US Census data (OpenAI, Nextgov). A site cannot tell an agent from a person, and a leaked key works for anyone.
- The open web has no answer yet
- A person's agent visiting a website they don't run has no shared identity provider and no adopted standard. IETF drafts exist; none is adopted (example).
Auth Your Agent is built for that gap: a person, their agent, and any website.
How it works, in one errand
Ada asks her assistant to apply for jobs on jobs.example.com.
- Tuesday, 19:02
Her phone asks. "Job-search assistant wants access to jobs.example.com: list jobs, apply." She approves it for one day (until Wednesday 19:02) with her fingerprint.
- 19:02
The agent gets a pass. Her one-day approval is issued as 10-minute passes that renew automatically, so a leaked pass is soon useless. Each is for this site only, and works only with the agent's own key.
- 19:10
Applying asks again. The site marks "apply" as sensitive. Ada approves this one application; that approval works once.
- Wednesday, 08:30
She takes it back early. One tap under Sites. No new pass is issued; the agent's next request is refused, and it is told to stop and tell her.
Ada never gave anyone her password. The website saw the agent, Ada, and the exact permission on every request. The full story, from all three sides, is on how it works; developers can run it with the walkthrough.
Works on any website today: Take over
Most sites will not accept agents for a while. Until they do, agents fail at the same places: a login, a CAPTCHA, a 2FA code. With Take over, the agent asks its owner instead of failing.
What the person does
- Gets a notification: "Agent needs you", with the reason
- Sees the agent's page live on their phone and types straight into its fields
- Presses the site's own Sign in; the agent notices and carries on by itself
Why it matters
- No cooperation from the website: it sees a person signing in
- The password goes from the person to the page; the agent never reads it
- Works for agents without vision: completion is checked from the page's form fields
- Every stuck point is recorded, showing websites where their users' agents need a way in
Available to agent builders in the Python and JavaScript SDKs, and in a plugin for a self-hosted assistant. How it works for developers.
Four users, one of them not a person
People
- Use agents on real sites without giving away passwords
- Decide per site and per risky action
- See everything; revoke in one tap
Agent builders
- Two calls: get approval, make requests
- Passes, key proofs and step-up handled
- Take over when stuck at a login, on any site
Websites
- Every request names the agent and the person
- Sensitive actions confirmed by that person
- Abuse can be reported
AI agents
- A documented, legitimate way in
- Rules of behaviour, and errors that say what to do next
Built, running, and tested end to end
Product
- Live service at authyouragent.com
- Web app and Android app: approvals, limits, activity, recovery, export, delete
- Passkey, password (basic access only) and Google/Microsoft approval
- Python and JavaScript SDKs, interoperable; MCP gateway for sites
- Take over: the owner drives a stuck agent's browser from their phone
- Agent reputation from site reports
Quality
- Every release runs about 200 automated checks, including real browser flows
- A runnable walkthrough: agent, site and phone, end to end
- Open standards only: WebAuthn, JWT, DPoP (RFC 9449)
- Published privacy policy, terms and security whitepaper
Early access and free. The service is pre-launch, so no usage figures are claimed.
Free for people and small sites. Bigger sites pay as agent use grows.
- People and agent builders
- Always free. The phone app, unlimited agents and sites; MIT-licensed SDKs.
- Websites: Free
- $0. Up to 100,000 checks a month. Verification, step-up approvals, dashboard.
- Websites: Growth
- $49 a month. Up to 1 million checks. Adds agent reputation and abuse reports.
- Websites: Business
- $299 a month. Up to 10 million checks. Adds on-site checking (the site verifies on its own server, with no call to us per request), audit exports and email support.
- Websites: Enterprise
- Custom. Over 10 million checks. Adds an uptime commitment and dedicated support.
A check is one agent request verified by Auth Your Agent. Prices are a proposal, not yet in effect. Early access is free for everyone.
Looking for the first websites and agent builders
- Websites
- Pilot: accept agents on one sensitive action, with our help integrating.
- Agent builders
- Build on the SDKs and tell us what's missing.
- Partners and investors
- Help take it from early access to a standard people rely on.