BotShield notarizes; your platform executes. BotShield records and signs the human’s decision. It never performs the action and never decides what a Confirm permits. Your own code checks the proof and then acts.
When to use it
Use Agents Ask wherever an agent is about to do something that costs money, moves data, or is hard to undo:
A confirmation typed into a chat window proves nothing: the agent’s own surface cannot show that a person was there. Agents Ask moves the decision to the human’s own phone, in the BotShield app, and returns a proof that any system can check without trusting the agent.
The three building blocks
A registered agent
You register the requesting agent in the BotShield Console and receive an agent key,
bs_agent_…. The key authenticates every Agents Ask call. The Console also shows the agent’s Agent ID, and lets you rotate the key.A linked human
The human links to your agent once, in the BotShield app. You get back an
opaque_id (OP_…) that only your agent can use. No name, no email.A proposed action
Your agent proposes an action to that
opaque_id. The result is Confirmed, Denied, or Expired. Confirmed and Denied come with a signed proof.The whole loop
What you can rely on
- Every decision is a fresh biometric. The human confirms each action on their own device. A link alone never authorizes anything.
- The proof is bound to one action. Its
jtiis therequest_idyou supplied, and itsaudis your agent’s Agent ID, which you copy from Agents Ask → Trusted Agents in the Console. A proof for one action cannot be replayed for another. - You verify it yourself. The proof is an ES256 JWT. Check it locally against BotShield’s public keys. See Proof of Resolution.
- Silence is not consent. A proposal that the human never answers expires and produces no proof. A Deny is an explicit, signed decision.
- No personal data crosses to you. BotShield tells you that a verified human decided, never who they are. You address the human by an
opaque_idthat is meaningless outside your agent. See Privacy boundary.
Agents Ask is labelled Beta in the BotShield Console.
Ways to integrate
Next steps
Register an agent
Create the agent in the Console, then copy its key and its Agent ID.
Link a human
Run the one-time link and store the
opaque_id.Propose an action
Send the proposal, wait for the decision, or cancel it.
Proof of Resolution
Verify the signed result before you execute.
Live demo
Ticketz · Agents Ask — an agent buys, a human approves, on production.
