Terms of Service
HumanAuth is a tool for putting a human in the loop on AI-agent actions. It produces signed receipts — proof that a specific person approved or denied a specific action. These terms describe what you can expect from that tool, and what remains yours to do.
These Terms of Service are an agreement between you and [LEGAL ENTITY] ("HumanAuth", "we", "us"). By creating an account, calling the API, or using an approver app, you accept these terms. If you are agreeing on behalf of an organization, you confirm you are authorized to bind it.
HumanAuth is a developer preview ahead of its 1.0 release. The service, its APIs, and these terms may change as it matures.
HumanAuth produces signed receipts: cryptographic proof that a specific human approved or denied a specific action. That is what the service does. It does not sit in your execution path, and it does not stop anything on its own.
A receipt gates an action only where you verify it and refuse to proceed without a valid one. Deciding which actions require approval, and enforcing the outcome, is work you do in your own system. HumanAuth gives you the proof; you hold the gate. We are not responsible for actions your systems take, or fail to take, on the strength of a receipt you did not verify.
- Decide what needs approval
You choose which actions are consequential enough to route through a human. HumanAuth does not make that judgment for you.
- Enforce the result
Verify each receipt's signature, the action it names, and its freshness — and refuse to proceed without a valid one. An approval you never check enforces nothing.
- Protect keys and devices
Keep your API credentials and your approvers' devices under your control. You are responsible for actions taken with your credentials.
- Stay lawful
You are responsible for the actions you place behind an approval and for complying with the laws that apply to them.
HumanAuth is a security tool. You agree not to:
- Forge, replay, or tamper with approval receipts or their signatures.
- Probe, scan, or overload the service outside a coordinated-disclosure or a written agreement.
- Use the service to approve unlawful actions or to facilitate harm to a person.
- Circumvent authentication, access another tenant's data, or misrepresent whose approval a receipt carries.
- Resell or relabel the service as your own without a written agreement.
The HumanAuth client libraries — the SDKs, the CLI, and the MCP server — are open source under the MIT License. Your use of those components is governed by the license shipped with them, not by these terms. These terms cover the hosted service: the API, the approval relay, and the approver apps. Nothing here narrows a right the MIT License grants you.
We may change, suspend, or discontinue any part of the service during the developer-preview period. We do not commit to an uptime or support level unless we have agreed one with you in a separate written agreement. Because HumanAuth sits beside your enforcement rather than inside it, design your system so that a failure to reach the service is handled deliberately — not silently waved through.
The service is provided AS IS and AS AVAILABLE, without warranties of any kind, whether express or implied — including any implied warranty of merchantability, fitness for a particular purpose, or non-infringement. We do not warrant that the service will be uninterrupted, error-free, or that it will prevent every action you would want stopped. You are responsible for verifying receipts and for the enforcement you build around them.
To the maximum extent permitted by law, HumanAuth and [LEGAL ENTITY] are not liable for any indirect, incidental, special, consequential, or exemplary damages, or for lost profits, data, or goodwill, arising out of or relating to the service — even if we have been advised of the possibility.
Our total liability for all claims relating to the service is limited to the greater of the fees you paid us for the service in the twelve months before the claim, or USD 100. Some jurisdictions do not allow certain of these limits; where that is so, they apply only to the extent permitted.
These terms are governed by the laws of [GOVERNING LAW / JURISDICTION], without regard to its conflict-of-laws rules. You and [LEGAL ENTITY] submit to the exclusive jurisdiction of the courts located there for any dispute that is not otherwise resolved.
If we change these terms we will update this page and revise the effective date above. Continuing to use the service after a change means you accept the revised terms.
Questions about these terms: [email protected]