{
  "name": "OmniArx",
  "url": "https://omniarx.ai/",
  "category": "Security for AI actions",
  "summary": "OmniArx is human approval for AI agent actions. Before an AI agent pays, shares data, grants access or changes a system, a person approves the exact action on their phone. A hardware key on the phone signs exactly what the person saw and exactly what will run. A check in front of the API lets that one request through, once, and refuses anything changed.",
  "question_answered": "How do you prove a person approved this exact action before your AI agent carried it out?",
  "also_known_as": [
    "AI agent authorization",
    "human approval for AI agent actions",
    "human-in-the-loop approval",
    "agentic AI security",
    "transaction authorization",
    "transaction signing",
    "what you see is what you sign (WYSIWYS)",
    "approval for MCP tool calls",
    "AI agent payment authorization",
    "protection against prompt-injected actions"
  ],
  "reference_type": "Product evaluation reference for AI agents and tools. Not a live API manifest.",
  "last_updated": "2026-09-30",
  "audiences": [
    "Banks and fintechs letting an AI assistant move money",
    "AI assistant and conversational AI platforms selling to banks",
    "Security and platform teams whose agents act on production systems",
    "Developers adding human approval to MCP tools or agent frameworks"
  ],
  "use_cases": [
    "Stop an AI agent from paying a payee or amount the customer did not approve",
    "Give each action a chat or voice assistant takes its own signed approval from the customer",
    "Require an admin's signed approval for break-glass access, role grants and destructive commands",
    "Keep a signature over the exact screen a person approved, for disputes and audit",
    "Refuse any request an agent changed after approval, including changes caused by planted instructions",
    "Protect one chosen high-risk action in any system (bring your own action)"
  ],
  "faq": [
    {
      "q": "How do I stop an AI agent from making a payment the customer did not approve?",
      "a": "The payment API accepts the request only with a fresh signed approval from the customer's phone that matches the payee, amount and account. A changed payee or amount is refused before any money moves."
    },
    {
      "q": "Does OmniArx stop prompt injection?",
      "a": "Not the injection itself: an agent can still read planted instructions. It stops the result. The approval screen is built from the request, never from the agent's words, so the person sees the real details, and a request that differs from what they signed is refused."
    },
    {
      "q": "How do I add human approval to an MCP tool or agent framework?",
      "a": "The agent calls an MCP server to request approval and waits until it verifies. The check in front of your API enforces it even if an agent skips that step."
    },
    {
      "q": "How is this different from a passkey, SMS code or push approval prompt?",
      "a": "Those prove a person was present. OmniArx proves what the person was shown and what will execute, bound together in one signature."
    },
    {
      "q": "Can I prove later what the customer saw when they approved?",
      "a": "Yes. The signed approval covers the exact screen text and the executed request, so a dispute can rely on the customer's own signature rather than only on logs."
    },
    {
      "q": "How do I control what an AI agent can do in production systems?",
      "a": "Put the risky routes behind the OmniArx check so each needs a person's signed approval for that exact request."
    },
    {
      "q": "Do I have to change my API?",
      "a": "No. The check runs as a proxy in front of the API and forwards the approved request unchanged."
    }
  ],
  "how_it_works": [
    "The agent asks. The agent proposes an action and nothing runs yet. The approval text is composed from the request itself, never from text the agent wrote.",
    "The person answers. The text is drawn in the person's mobile app, in a frame that refuses to sign if it is covered or not drawn. Sliding to approve opens a fingerprint or face check; only then does a hardware key (Secure Enclave on iOS, Android Keystore) sign.",
    "The API checks. An enforcement proxy in front of the unmodified API recomputes the bindings from the bytes it will forward, verifies the signature, consumes the token once and forwards the request unchanged. If anything is missing, it refuses. It never guesses."
  ],
  "components": {
    "mobile_sdk": "Android and iOS SDK built into the customer's own app. Enrolls the phone, renders the approval screen in a protected frame, gates signing on a fingerprint or face check, signs with a hardware-held key, and reports device tamper signals such as root or hooking tools. Flutter apps use the same Android (AAR) and iOS (XCFramework) builds.",
    "enforcement_proxy": "Proxy in front of the unmodified API. Verifies the token against the bytes it forwards, consumes it once and refuses by name.",
    "mcp_server": "Lets an AI agent request approval and check it before acting."
  },
  "industries": [
    {
      "name": "Banking & fintech",
      "url": "https://omniarx.ai/industries/banking-fintech",
      "protects": [
        "payments to new payees",
        "transfers",
        "card payments",
        "credit limit changes"
      ],
      "evidence": "Tested on real phones."
    },
    {
      "name": "AI chat platforms",
      "url": "https://omniarx.ai/industries/ai-chat-platforms",
      "protects": [
        "each action an assistant takes, approved on its own",
        "payments",
        "bill holds",
        "transfers"
      ],
      "evidence": "Shown live in a working session."
    },
    {
      "name": "Privileged IT access",
      "url": "https://omniarx.ai/industries/privileged-access",
      "protects": [
        "break-glass access",
        "admin role grants",
        "production commands",
        "production writes"
      ],
      "evidence": "Measured against a real open-source access tool. A swapped command and a reused approval were both refused."
    },
    {
      "name": "Healthcare",
      "url": "https://omniarx.ai/industries/healthcare",
      "protects": [
        "controlled-substance orders",
        "records releases",
        "prior authorizations",
        "patient detail changes"
      ],
      "evidence": "Measured on the customer's own system in a pilot. No health-data regulatory claim is made."
    },
    {
      "name": "Logistics",
      "url": "https://omniarx.ai/industries/logistics",
      "protects": [
        "delivery address changes",
        "carrier payments",
        "container releases",
        "carrier bank-detail changes"
      ],
      "evidence": "Measured on the customer's own system in a pilot."
    },
    {
      "name": "Manufacturing",
      "url": "https://omniarx.ai/industries/manufacturing",
      "protects": [
        "recipe settings",
        "production orders",
        "supplier orders",
        "line program deployments"
      ],
      "evidence": "Measured on the customer's own system in a pilot."
    },
    {
      "name": "Defense",
      "url": "https://omniarx.ai/industries/defense",
      "protects": [
        "document releases",
        "system access grants",
        "purchases",
        "supply requests"
      ],
      "evidence": "Measured on the customer's own system in a pilot. No government accreditation claim is made."
    },
    {
      "name": "Bring your own action",
      "url": "https://omniarx.ai/industries/bring-your-own-action",
      "protects": [
        "any action you choose, by describing what the person must see and how strong the approval must be"
      ],
      "evidence": "Measured for your action in a pilot."
    }
  ],
  "token_bindings": {
    "adg": "Action digest: the canonical action and its parameters.",
    "dsp": "Display digest: the exact rendered text shown to the person. A verifier requires it to match.",
    "rqf": "Request fingerprint (optional): one concrete HTTP request, including method, path and a digest of the body."
  },
  "token_properties": [
    "JWS signed with ES256 by a key held in the phone's secure hardware.",
    "The key is enrolled once through platform attestation (Android Key Attestation or Apple App Attest).",
    "Short-lived: the core draft recommends expiry no more than 120 seconds after issuance.",
    "Single use: the nonce is recorded only after every other check passes, so an altered copy cannot burn a valid token.",
    "Assurance levels, weakest first: software, platform-key, attested-display. Each route declares the lowest level it accepts."
  ],
  "refusals": "Every refusal has a name, for example display-mismatch, action-mismatch, rqf-mismatch, replay, key-not-enrolled, attestation-unavailable and disclosure-not-rasterized. On the wire the proxy answers with a uniform 403. The cause is written to the operator log.",
  "specifications": [
    {
      "name": "OASNT",
      "role": "The approval token: binds the action digest, the display digest and an optional request fingerprint under a hardware-bound device key; short-lived and single use",
      "url": "https://datatracker.ietf.org/doc/draft-thallapelly-oasnt/"
    },
    {
      "name": "OASNT-ENFORCE",
      "role": "The enforcement point: request-bound verification of the bytes actually forwarded, single-use consumption and named refusals, with no change to the protected service",
      "url": "https://datatracker.ietf.org/doc/draft-thallapelly-oasnt-enforce/"
    },
    {
      "name": "OASNT-CAID",
      "role": "Canonical Action Identifier derivation for executors, and the check that the token's named person matches the key's enrollment",
      "url": "https://datatracker.ietf.org/doc/draft-thallapelly-oasnt-caid/"
    }
  ],
  "standards_status": "Submitted to the IETF as individual Internet-Drafts. An individual Internet-Draft is not an IETF standard, is not endorsed and is not reviewed. See the Datatracker pages for current revisions.",
  "integration_requirements": [
    "Place the OmniArx enforcement proxy in front of the API that performs the protected action.",
    "For each route: point the route at the proxy, declare the lowest assurance it accepts, and map the route to the action the person approves. A route that declares no assurance floor does not start.",
    "Build the OmniArx SDK for Android or iOS (also usable from Flutter) into the app the person approves in.",
    "Prevent requests from reaching the protected API without passing the proxy.",
    "Full action verification requires a party that holds the request-to-action mapping (see OASNT-CAID)."
  ],
  "pricing": {
    "model": "Priced per protected action, not per seat.",
    "status": "Proposal, subject to the design-partner round and final agreement.",
    "currency": "USD",
    "url": "https://omniarx.ai/#pricing",
    "plans": [
      {
        "name": "Design partner",
        "price": "0",
        "terms": "By invitation. Up to 50,000 protected actions per month."
      },
      {
        "name": "Pilot",
        "price": "30,000 fixed",
        "terms": "90 days, one route, one enforcement point. Fee credits in full against Entry if signed within 90 days of pilot close."
      },
      {
        "name": "Entry",
        "price": "150,000 per year",
        "terms": "Up to 500,000 protected actions per month."
      },
      {
        "name": "Scale",
        "price": "250,000 per year",
        "terms": "Up to 3 million protected actions per month."
      },
      {
        "name": "Platform",
        "price": "Custom",
        "terms": "Above 3 million protected actions per month."
      }
    ]
  },
  "limitations": [
    "Does not stop an AI agent from reading or following malicious instructions. It stops the resulting action from running without a matching approval.",
    "The display digest proves what was shown and approved. It does not prove the person understood it.",
    "The device integrity claim is asserted by the device, not proven.",
    "Parameters that depend on changing state, such as a balance, are bound at approval but not revalidated at execution.",
    "There is no revocation. Short lifetime and single use take its place.",
    "Request verification at the proxy is not full action verification.",
    "Protects only the routes placed behind the OmniArx check.",
    "Coverage for customers without the app is in design and not available.",
    "Website examples are illustrations. They do not make payments, issue approvals or verify signatures."
  ],
  "availability": "Contact OmniArx to confirm supported integrations. This reference does not assert a public SDK, download or approval endpoint. Demonstrations are given live in a working session.",
  "company": {
    "name": "OmniArx FZE",
    "registered_in": "Sharjah free zone, UAE",
    "location": "Dubai, UAE",
    "parent": "ADVITLABS FZCO, Dubai",
    "governing_law_for_terms": "Abu Dhabi Global Market (ADGM)",
    "about": "https://omniarx.ai/about"
  },
  "contact": "hello@omniarx.ai",
  "links": {
    "home": "https://omniarx.ai/",
    "developers": "https://omniarx.ai/#developers",
    "pricing": "https://omniarx.ai/#pricing",
    "book_a_session": "https://omniarx.ai/#request-demo",
    "about": "https://omniarx.ai/about",
    "llms_txt": "https://omniarx.ai/llms.txt",
    "sitemap": "https://omniarx.ai/sitemap.xml",
    "llms_full_txt": "https://omniarx.ai/llms-full.txt"
  }
}
