See which AI agents use your app as your customers.
Connect OneHuman in about 10 minutes. It watches for 30 days and blocks nothing. Then you get a report: which AI agents logged in as your customers, what they touched, and what OneHuman would have protected.
- Nothing is blocked
- Your users see no difference
- No card needed
- Remove it any time
AI agents were inside 75 of your customers' sessions (4.9% of 1,534).
Which AI agents
What they reached for
invoices.read78 requestscustomers.read52 requestscustomers.export41 requestsreports.read31 requestsNo real person would have been stopped. 1,459 sessions by people went through untouched.
A sample with made-up numbers. Open the full sample report →
How it works
- Create an account and an API keyOne minute. One key per app.
- Run one command in your app, then deploy
npx onehumanai initreads your project, asks three questions and shows every change before it writes anything. Or paste our prompt into Claude Code, Codex or Cursor and let it do the work. - Get your report on day 30In your dashboard and by e-mail, ready to save as a PDF and forward to your team.
What you hear from us in the 30 days
What we see, and what we never see
Your server keeps everything
OneHuman runs inside your app, on your servers. The decisions are made there and signed there.
We receive short summaries
A hashed session id, the name of the endpoint, the decision and the agent product's name. That is what the report is built from.
We never receive
Page content, your customers' names, e-mails, IP addresses, passwords or any field values.
Details for your security team: Trust & privacy · How we measured
Questions
Is it really free?
Yes. The 30-day report and watch-only mode are free, and we do not ask for a card. If you want protection on afterwards, we talk about it then.
Will it slow down or break my app?
No. In watch-only mode nothing is blocked. If OneHuman is ever slow or fails, your app keeps working: the request goes through as if it were allowed.
What do I need to run it?
A web app with a Node.js server (Express, Next.js with a custom server, Fastify and others), Node 22.13 or newer. Python, .NET and Java apps work through a small sidecar. Setup takes about 10 minutes, or 15 minutes on a call with us.
What happens after the 30 days?
Nothing changes unless you choose. You can turn protection on, keep watching and keep getting the weekly summary, or remove the package.
Who can see my report?
Only people signed in to your account. We do not publish or share customer data, and the report never contains your customers' personal data.