Human Seal

Agent payments

A person in the loop when an agent pays

Agents are starting to pay for things. When one does, the person it acts for usually cannot show later that they agreed to the exact payment. The Human Seal adds a named person's approval of the exact payment, and a signed receipt anyone can check offline.

What the Human Seal adds

A named person approves the exact action, and the agent gets a signed receipt. The receipt is bound to the exact cart: the agent hashes its cart, the receipt signs a digest that includes that hash, and anyone holding the cart can recompute the chain. Change one character of the cart and the receipt no longer matches.

Anyone can check the signature offline, with no call to us, in the verifier or in a few lines of code. To confirm the key is ours, compare it with the key published at did:web:humanseal.world.

Two working examples, in the sandbox

Both run against the Human Seal sandbox: no money moves, no live tenant is touched, and every receipt is marked as a rehearsal inside what is signed. The code is public: the payments examples.

To run them, follow the quickstart, then use python3 agent_spend_envelope_with_human_seal.py you@example.com. The script does the sandbox steps for you.

How this relates to AP2

AP2 is an open protocol for agent payments, published by Google and donated to the FIDO Alliance in April 2026, where its development continues in working groups. We read version 0.2 of the specification on GitHub. It describes mandates that a user signs on a trusted surface, in two states: open mandates with constraints, for payments the user is not present for, and closed mandates for one transaction. Our approval screen is designed to do the same job as a trusted surface: it shows the request in full and records a person's decision. It is not a registered trusted surface for any verifier.

What is not built

Nothing here holds money or moves it. What is built and what is not is on the limitations page; if anything here reads stronger, that page is right. Questions the pages do not answer can go to the flocore_support_ask tool, which says so when it cannot answer.

Try it. The steps are on the quickstart. Feedback: hello@humanseal.world.