Spot.
See every AI agent in your customers' sessions the moment it joins. Start in watch-only mode.
Product
OneHuman spots the agent, applies your rule to every action, and signs each decision on your own server.
Their clicks move like a hand. The action returns the balance.
Seen in 0.3 s. What is on screen is hidden before the agent reads it.
Balance hidden. The export waits for the person. Every decision signed.
Only their passkey approves an action or takes the session back.
See every AI agent in your customers' sessions the moment it joins. Start in watch-only mode.
One rule per action: allow it, hide private fields, ask the owner, or never share.
Every decision is signed and chained on your server. An auditor checks it offline.
Only the owner's passkey approves a risky action. The agent cannot do that step.
The numbers behind this: How we measured → · Agent scorecard →
People now use their bank, their CRM and their work tools through an AI agent.Most apps can only block it or trust it.OneHuman lets it in on your terms.
More on the home page, or write to hello@onehuman.ai.
Two ways. Agent tools leave traces in the page when they attach, so the session is marked before the agent's first action. And every click is checked: a hand curves, trembles and slows onto a button, while a program jumps there and releases in a few milliseconds. Agents that sign their requests (Web Bot Auth) are identified by signature.
A Node.js server (22.13 or newer): Express 4 or 5, Connect, a Next.js custom server or plain node:http. Run npx onehumanai init in your project. It finds the routes worth protecting, asks three plain questions and shows every change before it writes it.
The browser SDK, the middleware and the CLI are Apache 2.0. The engine's source is public under the Business Source License 1.1, with production use granted. You install it from npm and run it on your own server.