Agents act.
Customers
okay it.
Before an agent does anything risky in a customer's account, the real customer approves that exact action with a passkey. The agent gets a limited session, and you keep a signed record.
Now taking a small number of design partners.
Approve this agent action?
Budget Buddy wants to add J. Okafor as a payee and send them $2,400.00.
To your website, an agent in an account looks exactly like your customer.
Browser agents ride the customer's logged-in session or type in their password. Cloud agents sign in from data centres. Either way your systems see the customer, so the agent inherits everything the account can do. Nothing it does can be limited, revoked or proved afterwards.
HumanOkay is the third option: let the customer decide, one action at a time.
How HumanOkay works
It sits between your bot management, which can see agents, and your login, which assumes a person is typing. The same four steps run every time an agent tries something risky, and each one adds lines to the customer's record.
Recognise the agent
HumanOkay reads the signals your bot vendor already produces, plus the cryptographic signatures that well-behaved agents attach to their requests. Agents that don't identify themselves are still caught by how they behave, and get the same treatment.
Ask the customer
Before a risky action, such as a new payee, a checkout to a new address or a booking change, the real account holder gets a push, a passkey prompt or an emailed link showing exactly what the agent wants to do. The agent never sees or touches the approval.
Give the agent a limited key
Approval issues a session for that one job: a spending cap, the actions allowed, an expiry and a kill switch. Routine actions the customer has already pre-approved go straight through, so people aren't asked twice.
Keep the signed record
Each approval becomes a signed record of who approved what, when, and for which agent, formatted as chargeback and dispute evidence. Customers see every agent they've connected on one page and can revoke any of them.
Built for the people who own agent risk
For banks and fintechs, retailers and marketplaces, and travel and loyalty programmes, where agents already reach logged-in accounts.
Fraud and risk
Separate the agent sessions your customers approved from everything else. Fewer account takeovers and "my agent did it" disputes, without blanket blocks.
Identity and login
Step-up that still works when the "user" is an agent: passkey approvals, limited sessions and instant revocation, alongside the login you already run.
Digital and e-commerce
Say yes to agent orders as they grow, instead of losing them to a CAPTCHA or a blocked checkout.
Compliance
A record of exactly what each customer authorised, and a page where they can see and revoke it. That's the control and transparency banks' new agentic-commerce principles ask for.
Other tools see the agent. HumanOkay asks the customer.
| Tool | Decides based on | Covers | What's missing |
|---|---|---|---|
| Bot management | The type of agent, such as every agent from one vendor | Traffic and sessions | The individual customer's consent, and evidence for each action |
| Fraud scoring | A risk score for the order | Transactions | Account actions that aren't payments, and the customer's say |
| Card-network agent programmes | The cardholder's approval of a card payment | Card payments | Logins, account changes and other ways to pay |
| HumanOkay | This customer's approval of this exact action | Any risky action in the account, payment or not | Nothing to rip out: it's designed to work alongside the three above |
Fits on top of what you already run
HumanOkay is designed to read the agent signals from the bot management you already pay for and to plug into your existing login, whoever provides it. It's built on open standards, so neither you nor the agents are locked in.
- Web Bot AuthRecognise agents by their signed requests
- Passkeys (FIDO2, WebAuthn)Phishing-resistant customer approvals
- OpenID CIBAPush approvals to the customer's own device
- OAuthLimited, expiring sessions for the agent
- Shared SignalsRevoke an agent everywhere, instantly
Start with an agent exposure audit
We're taking a small number of design partners. Each one starts with a paid audit of two to four weeks, run on your own logs, before anything is deployed.
- Who it's for
- Banks and fintechs, retailers and marketplaces, travel and loyalty programmes
- What you get
- A written report on agent activity in your logged-in flows and a recommended agent policy
- As a partner
- You shape the approval flows and the evidence format, and get first access to HumanOkay in production
Questions buyers ask first
Do the companies that make AI agents need to integrate with you?
No. The approval goes to your customer on their own device, not through the agent, so it's designed to work with any agent, including ones that don't identify themselves. Agents that do sign their requests get a smoother path.
Does this replace our bot management or fraud tools?
No. HumanOkay is designed to use the signals those tools already produce. They tell you an agent is there; HumanOkay gets the customer's consent for the specific action and keeps the evidence.
How is this different from Visa's and Mastercard's agent programmes?
Those programmes cover card payments. HumanOkay covers the rest of the account as well: logins, new payees, address and email changes, bookings, loyalty points and payment methods other than cards.
Won't customers get tired of approving things?
They're only asked about risky actions. Customers can set standing rules, such as reorders under $100, and those go straight through.
What does the evidence look like?
A signed record of the agent, the customer, the exact action, the limits, the time and how it was approved, formatted for card chargebacks and Regulation E disputes.
Where are you today?
We're working with a small number of design partners, starting with the agent exposure audit. If agents are already reaching your customers' accounts, book a call.
Give every agent action a paper trail.
Book 15 minutes to find out where agents already reach your customers' accounts, and what it would take to say yes to them safely.
Calls are on Google Meet. You'll get a calendar invite as soon as you book.
Pick a time
You're booked
Check your inbox for the calendar invite. It has the Google Meet link.