Free · 30 days · watch-only

See which AI agents use your app as your customers.

Connect OneHuman in about 10 minutes. It watches for 30 days and blocks nothing. Then you get a report: which AI agents logged in as your customers, what they touched, and what OneHuman would have protected.

OneHuman30-day report · sample data

AI agents were inside 75 of your customers' sessions (4.9% of 1,534).

1,534customer sessions
4.9%had an AI agent in them
4AI agent products
225agent requests that would have been hidden, refused or sent to the owner

Which AI agents

Claude in Chrome44 sessions
Browser side-panel agent12 sessions
Codex (Chrome extension)10 sessions
Claude app browser9 sessions

What they reached for

invoices.read78 requests
customers.read52 requests
customers.export41 requests
reports.read31 requests

No real person would have been stopped. 1,459 sessions by people went through untouched.

A sample with made-up numbers. Open the full sample report →

How it works

  1. Create an account and an API keyOne minute. One key per app.
  2. Run one command in your app, then deploynpx onehumanai init reads your project, asks three questions and shows every change before it writes anything. Or paste our prompt into Claude Code, Codex or Cursor and let it do the work.
  3. Get your report on day 30In your dashboard and by e-mail, ready to save as a PDF and forward to your team.

What you hear from us in the 30 days

Day 1Your app is connectedThe 30 days start with the first report from your app.
Any dayThe first AI agentWhich agent it was, and what it asked for.
Every weekA short summarySessions, agents, and what OneHuman would have done.
Day 30Your reportThen you decide: turn protection on, keep watching, or remove it.

What we see, and what we never see

Your server keeps everything

OneHuman runs inside your app, on your servers. The decisions are made there and signed there.

We receive short summaries

A hashed session id, the name of the endpoint, the decision and the agent product's name. That is what the report is built from.

We never receive

Page content, your customers' names, e-mails, IP addresses, passwords or any field values.

Details for your security team: Trust & privacy · How we measured

Questions

Is it really free?

Yes. The 30-day report and watch-only mode are free, and we do not ask for a card. If you want protection on afterwards, we talk about it then.

Will it slow down or break my app?

No. In watch-only mode nothing is blocked. If OneHuman is ever slow or fails, your app keeps working: the request goes through as if it were allowed.

What do I need to run it?

A web app with a Node.js server (Express, Next.js with a custom server, Fastify and others), Node 22.13 or newer. Python, .NET and Java apps work through a small sidecar. Setup takes about 10 minutes, or 15 minutes on a call with us.

What happens after the 30 days?

Nothing changes unless you choose. You can turn protection on, keep watching and keep getting the weekly summary, or remove the package.

Who can see my report?

Only people signed in to your account. We do not publish or share customer data, and the report never contains your customers' personal data.

Find out in 30 days. Block nothing until you decide.