Skip to main content
Agents Ask puts a real human in the loop for actions your AI agent should not take on its own word. Your agent proposes the action. The human sees it as a card in the BotShield app and gives a Confirm or Deny with their device biometric (passkey). You receive a signed Proof of Resolution that your code verifies before it executes anything.
BotShield notarizes; your platform executes. BotShield records and signs the human’s decision. It never performs the action and never decides what a Confirm permits. Your own code checks the proof and then acts.

When to use it

Use Agents Ask wherever an agent is about to do something that costs money, moves data, or is hard to undo: A confirmation typed into a chat window proves nothing: the agent’s own surface cannot show that a person was there. Agents Ask moves the decision to the human’s own phone, in the BotShield app, and returns a proof that any system can check without trusting the agent.
Try the whole loop in five minutes. The BotShield Demos include Ticketz · Agents Ask: chat with a ticket-buying agent (Claude, through the hosted MCP server), link your BotShield ID, ask it to book seats, and confirm the purchase on your phone. The chat then shows the order and its Proof of Resolution.

The three building blocks

A registered agent

You register the requesting agent in the BotShield Console and receive an agent key, bs_agent_…. The key authenticates every Agents Ask call. The Console also shows the agent’s Agent ID, and lets you rotate the key.

A linked human

The human links to your agent once, in the BotShield app. You get back an opaque_id (OP_…) that only your agent can use. No name, no email.

A proposed action

Your agent proposes an action to that opaque_id. The result is Confirmed, Denied, or Expired. Confirmed and Denied come with a signed proof.

The whole loop

What you can rely on

  • Every decision is a fresh biometric. The human confirms each action on their own device. A link alone never authorizes anything.
  • The proof is bound to one action. Its jti is the request_id you supplied, and its aud is your agent’s Agent ID, which you copy from Agents Ask → Trusted Agents in the Console. A proof for one action cannot be replayed for another.
  • You verify it yourself. The proof is an ES256 JWT. Check it locally against BotShield’s public keys. See Proof of Resolution.
  • Silence is not consent. A proposal that the human never answers expires and produces no proof. A Deny is an explicit, signed decision.
  • No personal data crosses to you. BotShield tells you that a verified human decided, never who they are. You address the human by an opaque_id that is meaningless outside your agent. See Privacy boundary.
Agents Ask is labelled Beta in the BotShield Console.

Ways to integrate

Next steps

Register an agent

Create the agent in the Console, then copy its key and its Agent ID.

Link a human

Run the one-time link and store the opaque_id.

Propose an action

Send the proposal, wait for the decision, or cancel it.

Proof of Resolution

Verify the signed result before you execute.

Live demo

Ticketz · Agents Ask — an agent buys, a human approves, on production.