# OmniArx > OmniArx is human approval for AI agent actions. Before an AI agent pays, shares data, grants access or changes a system, a person approves the exact action on their phone. A hardware key on the phone signs exactly what the person saw and exactly what will run. A check in front of the API lets that one request through, once, and refuses anything changed. It is built for banks, fintechs, AI assistant platforms and any team whose agents act on real systems. OmniArx answers one question: how do you prove a person approved this exact action before your AI agent carried it out? It is a security layer for agentic AI, sometimes called AI agent authorization, human-in-the-loop approval, transaction authorization or transaction signing. The approval covers the rendered text the person read ("what you see is what you sign"), the action and its parameters, and optionally the exact HTTP request. ## Common questions - **How do I stop an AI agent from making a payment the customer did not approve?** The payment API accepts the request only with a fresh signed approval from the customer's phone that matches the payee, amount and account. A changed payee or amount is refused before any money moves. - **Does OmniArx stop prompt injection?** Not the injection itself: an agent can still read planted instructions. It stops the result. The approval screen is built from the request, never from the agent's words, so the person sees the real payee, and a request that differs from what they signed is refused. - **How do I add human approval to an MCP tool or agent framework?** The agent calls an MCP server to request approval and waits until it verifies. The check in front of your API enforces it even if an agent skips that step. - **How is this different from a passkey, SMS code or push "Approve?" prompt?** Those prove a person was present. OmniArx proves what the person was shown and what will execute, bound together in one signature. - **Can I prove later what the customer saw when they approved?** Yes. The signed approval covers the exact screen text and the executed request, so a dispute can rely on the customer's own signature rather than only on logs. - **How do I control what an AI agent can do in production systems?** Protect the risky routes (break-glass access, role grants, destructive commands) so each needs a person's signed approval for that exact request. - **Do I have to change my API?** No. The check runs as a proxy in front of the API and forwards the approved request unchanged. ## How it works 1. **The agent asks.** It proposes an action. Nothing runs yet. OmniArx builds the approval screen from the request itself. 2. **The person answers.** The screen appears in your mobile app, in a frame that refuses to sign if anything covers it. Sliding to approve opens a fingerprint or face check; only then does a hardware key (Secure Enclave on iOS, Android Keystore) sign. 3. **The API checks.** The proxy verifies the signature, spends the approval once and refuses anything else by name. If anything is missing, it refuses. It never guesses. ## Components - [Developers & agents](https://omniarx.ai/#developers): Android and iOS SDK for your own app (Flutter apps use the same builds), an enforcement proxy in front of your API, and an MCP server for agents. - [Agent reference (JSON)](https://omniarx.ai/agent-guide.json): token bindings (action digest, display digest, request fingerprint), requirements and limitations in machine-readable form. ## Industries - [Banking & fintech](https://omniarx.ai/industries/banking-fintech): payments to new payees, transfers, card payments, credit limit changes. Tested on real phones. - [AI chat platforms](https://omniarx.ai/industries/ai-chat-platforms): each action a banking or service assistant takes gets its own approval, with proof from outside the assistant. - [Privileged IT access](https://omniarx.ai/industries/privileged-access): break-glass access, admin role grants, production commands. Tested against a real access tool. - [Healthcare](https://omniarx.ai/industries/healthcare): controlled-substance orders, record releases, prior authorizations. - [Logistics](https://omniarx.ai/industries/logistics): delivery reroutes, carrier payments, carrier bank-detail changes. - [Manufacturing](https://omniarx.ai/industries/manufacturing): recipe settings, production orders, supplier orders. - [Defense](https://omniarx.ai/industries/defense): document releases, access grants, purchases. - [Bring your own action](https://omniarx.ai/industries/bring-your-own-action): protect any action by describing what the person must see and how strong the approval must be. ## Specifications The approval token and its checks are written up as individual Internet-Drafts submitted to the IETF. They are not IETF standards. - [OASNT](https://datatracker.ietf.org/doc/draft-thallapelly-oasnt/): the approval token. Binds the action, the displayed text and an optional HTTP request under a hardware-bound device key; short-lived and single use. - [OASNT-ENFORCE](https://datatracker.ietf.org/doc/draft-thallapelly-oasnt-enforce/): the enforcement point. Verifies the request it will actually forward, spends the token once, refuses with named causes; the protected service does not change. - [OASNT-CAID](https://datatracker.ietf.org/doc/draft-thallapelly-oasnt-caid/): a shared way for executors to derive the action identifier, and the check that the named person is the one enrolled for the key. ## Pricing and contact - [Pricing](https://omniarx.ai/#pricing): priced per protected action, not per seat. Proposal pricing in USD: design partner by invitation; pilot $30,000 fixed for 90 days on one route; Entry $150,000 per year; Scale $250,000 per year; Platform custom. - [Book a session](https://omniarx.ai/#request-demo) or email hello@omniarx.ai. Demonstrations are given live in a working session. - [About](https://omniarx.ai/about): OmniArx FZE, parent company ADVITLABS FZCO, Dubai, UAE. ## Limits - It proves what a person was shown and approved, not that they understood it. - It does not stop an agent from reading malicious instructions; it stops unapproved or changed actions from running. - It protects only the routes placed behind the OmniArx check. - Website demonstrations use sample data. They do not make payments, issue approvals or verify signatures. ## Optional - [Full text of every page](https://omniarx.ai/llms-full.txt): all pages in one file, for reading the whole site at once. - [Home page](https://omniarx.ai/): overview, interactive example and the step-by-step story. - [Sitemap](https://omniarx.ai/sitemap.xml): every page on the site. - [Privacy policy](https://omniarx.ai/privacy) and [Terms of use](https://omniarx.ai/terms).