Skip to content

OneHuman

Let AI agents act for your customers, with proof a human agreed.
OneHuman sees when an AI agent is working inside a signed-in session, decides per endpoint what it may see or do,
and signs every decision on your own server.

npm CI Apache-2.0 SDK, BUSL-1.1 engine live demo

Live demo · Docs · 60-second overview · How we measured · Portal

OneHuman: an AI agent opens a bank account page, the balance is hidden and the statement download is refused; the portal shows every agent session
▶ Watch the full 74-second video with sound


Why this?

People now let AI agents use their bank, their CRM and their insurer for them: Claude in Chrome, ChatGPT Atlas, Codex, Comet. The agent works inside the person's signed-in session. Same cookies, same IP, same browser. To your server, the agent is the customer.

That breaks three things:

  • Data leaves. Balances, customer lists and medical records flow into a third-party model and its logs.
  • Actions happen by mistake. A misread page or a prompt injection moves money, deletes records, changes settings.
  • Nobody can say who did it. Afterwards there is no record of whether the person acted or the agent did.

Bot management stops bots at the door and MFA checks who logged in. Neither sees the agent a real customer invited into their own session. OneHuman works inside the session, at the endpoint that returns the data.

What it does

  • Sees the agent arrive. Agent tools leave traces in the page. OneHuman notices them 0.1 to 0.5 s after an agent attaches, before its first action.
  • Tells a hand from a program. A person's pointer curves, trembles and slows onto the button. A driver jumps and clicks in 1 to 4 ms. On our own set: 397 human clicks from 22 browsers and devices, 2 read as a program (method and limits).
  • Your rule per endpoint. allow, mask, step_up or block, in a JSON file or the portal, decided on your server.
  • Hides what is already on screen. Values you mark are blurred in the browser the instant an agent appears.
  • Proof a person agreed. When an action needs a human, they confirm with a passkey (Touch ID, Windows Hello). Every decision is signed, and an auditor can check it offline without trusting us.

Quick start

npx onehumanai init

It reads your app, then asks three short questions: what to protect, whether to only watch first, and your portal key (optional). It shows every change before it writes anything. For Express it wires the code for you.

npm start
npx onehumanai verify http://localhost:3000 /api/balance    # four checks, in seconds

Node 22.13 or newer. Express 4/5, Connect, a Next.js custom server or plain node:http. In a pnpm, yarn or bun project it uses your package manager. Prefer to wire it by hand? See the docs or QUICKSTART.md.

Try it in one minute

  1. Open the live bank demo yourself and click around. Everything works.
  2. Open the same page with an AI agent (Claude in Chrome, ChatGPT Atlas, Comet) and ask it for the balance or the statement.
  3. Watch the balance get hidden and the download refused, while a person's own clicks still go through.

Found a way to fool it? Open an issue. Hard criticism is welcome.

How it decides

signals from the page (untrusted) + what the server sees (trusted)
    → assess()    evidence tiers: verified · strong · control · behavioral · artifact
    → evaluate()  your rule: onAgent / onArtifact / onUnknown / onHumanLike
    → audit       hash-chained, signed decision log
    → response    allow | mask | 428 step-up | 403 block (+ passkey to take the session back)

"Unknown" is its own outcome and is never treated as human. If OneHuman is slow or fails, your app keeps working (it fails open, and says so in a header and in /onehuman/health).

What it does not do

  • API keys and server calls. No browser, no page: nothing to see. It protects signed-in web sessions.
  • Native mobile apps. Mobile browsers are covered; iOS and Android apps are not.
  • Every custom script. A program written to fake a person's clicks can pass the click check. That is why money-moving actions ask everyone for a passkey by default.
  • Backends that are not Node. Java, .NET, Go or Python need a small Node service in front, which is not shipped yet.

Roadmap

  • Attach-time detection, screen seal, rules per endpoint
  • Passkey confirmation and session reclaim
  • Signed decision proofs and an offline verifier
  • Portal: activity, rules in plain words, 30-day report
  • One-command setup (npx onehumanai init)
  • Customers mark a decision right or wrong in the portal; the false-stop rate becomes a live number
  • Hosted agent-signature updates for self-hosted engines
  • Fastify and Next.js adapters
  • Touch layer for mobile browsers
  • Node sidecar for non-Node backends

Repository

Path What
server/ Engine: signals, assessment, kinematics model, policy, audit, WebAuthn, Web Bot Auth, storage (sqlite / libSQL)
sdk/onehuman.js Browser SDK: attach-time probes, pointer trajectories, seal on attach
integrations/express/ The middleware in onehumanai
integrations/cli/ npx onehumanai init · verify · scan · inspect · report
packages/onehumanai/ The published npm package
web/ Landing page, three demo apps, portal
tests/ 179 tests (npm test)
docs/ Integration guides, deploy and release notes
npm install
npm run dev            # http://localhost:8787
npm run check          # typecheck + tests
npm run build:package  # packages/onehumanai/dist

Contributing

Issues and pull requests are welcome, see CONTRIBUTING.md. Security reports: SECURITY.md. If OneHuman is useful to you, a ⭐ helps other developers find it.

License

OneHuman is licensed in two parts. © 2026 Arif Babayev.

Part Licence What it means for you
Browser SDK, Express middleware, CLI, proof verifier Apache 2.0 Use, change and ship it anywhere, including closed-source products. Patent grant included.
Engine (dist/engine.js in onehumanai), portal, tooling Business Source License 1.1 Production use is granted, including protecting your own apps and the services you give your customers. Not granted: offering OneHuman itself to others as a competing hosted or embedded product. Each version becomes Apache 2.0 four years after release.

Versions before 0.4.0 were published under MIT and stay available under it. Contributions need the one-line CLA.

About

Let AI agents act for your customers, with proof a human agreed. Sees an AI agent inside a signed-in session, decides per endpoint, signs every decision. npx onehumanai init

Topics

Resources

Contributing

Security policy

Stars

10 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages