Govern what your AI agent is allowed to do
authoxi is a control plane for AI agents. It sits in front of an agent's actions, enforces what that agent may do, escalates the high-stakes few to a human — and emits a cryptographically signed record of every decision that anyone can verify offline, with no account and no call back to us.
Verify one of our signed decisions right now, in your browser → Then try to forge it. It takes about thirty seconds and it explains the entire product better than this page can.
The problem
Your agent could issue the refund, pay the invoice, merge the branch, provision the access, move the money. It doesn't — because nobody can answer the question that gets asked the moment something goes wrong:
"Prove that this specific human approved this specific $9,000 payment, and that nobody edited the record afterwards."
Most teams answer with a Slack message and an approved_by column. That is a reasonable first
answer, and it holds right up until it is challenged — because a database row is mutable by everyone
who can write to the database, including the person you are trying to hold accountable. A log
tells you what happened. Evidence proves it.
So the agent stays read-only, the launch slips, and the enterprise deal stalls in security review.
What authoxi does
- Enforces, in-path. Every agent action is
allow/deny/escalate, decided against a signed mandate. Budget caps are atomic and race-free — the 51st dollar of a $50 mandate never passes, and concurrent calls cannot jointly overshoot. - Escalates to a human. A high-stakes action blocks mid-call. A human approves it by signing it with their own Ed25519 key. The approval is non-repudiable — they cannot later deny it.
- Produces evidence, not logs. Every decision emits a
loss-event/v2: canonicalized, signed, carrying its own public key inside adid:key, so a third party verifies it with nothing but the file. - Never holds your keys. The enforcement point runs inside your boundary, or sealed under your KMS. authoxi is not a credential vault, by design.
What authoxi is not
Stated plainly, so you don't waste a call:
- Not an LLM token proxy or a FinOps cost dashboard. We are not in your inference path. If you want to meter model spend, use a gateway; several give it away free.
- Not a credential vault. The agent never holds your provider key, and neither do we.
- Not a probabilistic AI-security filter. We don't guess whether an action looks malicious. We decide whether it was authorized, deterministically, and prove it.
- Possibly not necessary for you at all. If nobody will ever have to prove an approval to a third party, a Slack button genuinely beats us and you should build that instead. We'd rather tell you now.
Start here
| If you want to… | Go to |
|---|---|
| See the thing work, and try to break it | Verify a decision in your browser |
| Stop your agent taking an action without a human | Human approval for agent actions |
| Survive the question "prove a human approved it" | Prove a human approved an action |
| Give an agent a spending limit that actually holds | AI agent spending limits |
| Gate MCP tool calls per action | Block an MCP tool call |
| Know what an auditor will actually ask for | AI agent audit logs |
| Decide whether to build this yourself | Build vs buy |
| Implement the record format | loss-event/v2 spec |