{
  "data": {
    "similar": [
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/permit-mcp-gateway.json",
        "name": "Permit MCP Gateway",
        "score": 54.1,
        "shared": [
          "hitl.approve",
          "hitl.channels",
          "hitl.audit"
        ],
        "slug": "permit-mcp-gateway"
      },
      {
        "grade": "D",
        "json": "https://www.anchorterminal.com/tools/pushary.json",
        "name": "Pushary",
        "score": 51.4,
        "shared": [
          "hitl.approve",
          "hitl.channels",
          "hitl.audit"
        ],
        "slug": "pushary"
      },
      {
        "grade": "E",
        "json": "https://www.anchorterminal.com/tools/gotohuman.json",
        "name": "gotoHuman",
        "score": 43.6,
        "shared": [
          "hitl.approve",
          "hitl.channels",
          "hitl.audit"
        ],
        "slug": "gotohuman"
      },
      {
        "grade": "BB",
        "json": "https://www.anchorterminal.com/tools/temporal.json",
        "name": "Temporal",
        "score": 77.2,
        "shared": [
          "hitl.approve",
          "hitl.audit"
        ],
        "slug": "temporal"
      },
      {
        "grade": "C",
        "json": "https://www.anchorterminal.com/tools/orkes-conductor.json",
        "name": "Orkes Conductor Human tasks",
        "score": 54,
        "shared": [
          "hitl.approve",
          "hitl.audit"
        ],
        "slug": "orkes-conductor"
      },
      {
        "grade": "A",
        "json": "https://www.anchorterminal.com/tools/descope-agentic-identity.json",
        "name": "Descope Agentic Identity Hub",
        "score": 78.1,
        "shared": [
          "hitl.approve"
        ],
        "slug": "descope-agentic-identity"
      }
    ],
    "tool": {
      "slug": "withhuman",
      "name": "withHuman",
      "vendor": "Metoro Inc",
      "vendorUrl": "https://withhuman.ai",
      "kind": "http-api",
      "category": "human-in-the-loop",
      "summary": "withHuman is a hosted approval service for AI agents from Metoro Inc. It holds an agent's tool calls for a person to approve or deny through the Agent Approval Protocol API, coding-agent hooks, an MCP gateway and an MCP server.",
      "url": "https://www.anchorterminal.com/tools/withhuman",
      "markdownUrl": "https://www.anchorterminal.com/tools/withhuman.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/withhuman.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/withhuman.json",
      "license": "Proprietary hosted service under Metoro Inc's terms. The site describes an open-source edition, but the repository it links to returned 404 on 8 October 2026",
      "transports": [
        "http"
      ],
      "remoteUrl": "https://app.withhuman.ai",
      "packages": [],
      "auth": "mixed",
      "authNotes": "Five credentials, all sent as `Authorization: Bearer`. An agent credential (`whc_`) is bound to one agent instance and can only create approval requests and wait for decisions. A provisioner token (`whp_`) can only create and manage instances of its agent. A personal API key (`whk_`) follows its owner's permissions, can be narrowed to chosen actions and expires after 90 days by default. An organisation API key (`who_`, Scale plan and above) carries its own permission policies and cannot decide requests. The MCP server at `/api/mcp/v1` signs in with OAuth (authorisation code with PKCE and dynamic client registration) or takes an API key as a bearer token. A person signs up in the browser and connects the first agent.",
      "pricing": "freemium",
      "pricingNotes": "Free hosted plan at $0 for up to 5 members, with unlimited agents and approval requests, email, Slack and Discord, the audit log and the MCP gateway. Scale is $20 per user a month and adds the phone apps, organisation and scoped API keys, single sign-on and directory sync. Enterprise is a custom annual contract. New organisations start on a trial and move to Free without a subscription. Monthly allowances for gateway tool calls and phone messages exist but their numbers aren't on the pricing page (https://withhuman.ai/pricing, checked 2026-10-08).",
      "priceSummary": "$20 / seat-mo",
      "where": "hosted",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the OpenAPI document or the pricing page (checked 2026-10-08).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": null,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-08"
      },
      "docsUrl": "https://withhuman.ai/docs",
      "llmsTxt": "https://withhuman.ai/llms.txt",
      "openapi": "https://withhuman.ai/openapi.yaml",
      "capabilities": [
        "hitl.approve",
        "hitl.channels",
        "hitl.audit"
      ],
      "tags": [
        "hosted",
        "freemium",
        "free-tier",
        "mcp",
        "oauth",
        "openapi",
        "llms-txt",
        "webhooks",
        "enterprise",
        "early-access"
      ],
      "lastRelease": "2026-10-08",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 51.8,
        "grade": "D",
        "agentReady": false,
        "rank": 573,
        "ranked": true,
        "rankOf": 722,
        "categoryRank": 7,
        "methodology": "0.4",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 74,
          "maintenance": 49,
          "payments": 30,
          "reliability": 16,
          "schema": 81,
          "security": 73,
          "transparency": 53
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "breakdown": [
          {
            "key": "reliability",
            "name": "Reliability",
            "weight": 16,
            "effectiveWeight": 20,
            "score": 16,
            "points": 3.2,
            "reason": "Graded as a hosted service. No status page is linked from the site, the docs or the support page, and status.withhuman.ai did not connect (0), so there is no incident history to read (5). No request rate limits are published. 429 is documented only for the plan's limit on pending requests or active agents, with no numbers in the docs (0). `Idempotency-Key` is required on four write commands with documented replay and conflict behaviour, and the long-poll guide says to call again after a dropped connection, but no Retry-After or backoff guidance was found for 429 (11 of 15). The terms give no uptime guarantee outside an enterprise agreement (0). The terms say the service is in early access and the API document is version 0.1.0 (0)."
          },
          {
            "key": "performance",
            "name": "Performance",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes."
          },
          {
            "key": "schema",
            "name": "Schema \u0026 documentation",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 81,
            "points": 13.16,
            "reason": "A public OpenAPI 3.1 document with 116 operations and 148 schemas, also served by each instance at `/api/openapi.yaml` (25). llms.txt lists every docs page with a Markdown copy (10). Operation descriptions state purpose, preconditions and what each credential may do, and the docs separate the MCP server from the MCP gateway (16 of 20). Enums for status, required fields and bounded durations are typed. `arguments`, `context` and instance metadata are free-form objects by design (12 of 15). Each operation has a curl example, sample responses and a response table, and the error envelope has a table of stable types (13 of 15). Paths are versioned (`/api/aap/v1`, `/api/v1`), but no changelog was found and the blog is empty (5 of 15)."
          },
          {
            "key": "ergonomics",
            "name": "Agent ergonomics",
            "weight": 13,
            "effectiveWeight": 16.25,
            "score": 74,
            "points": 12.03,
            "reason": "The approval surface is 7 operations and a request needs three fields. List endpoints take `limit`, and the MCP server's tool list could not be read without signing in (17 of 25). `limit` on 14 list operations, `cursor` or `offset`, `q`, status filters and eight audit filters (16 of 20). Errors carry a stable `type` and `code`, a `request_id` and structured `details`, with 409, 412 and 428 codes an agent can act on (18 of 20). Mandatory idempotency keys and `If-Match` on revision activation. MCP tool annotations were not checked (16 of 20). Sensible defaults and few required parameters, with hooks for six agent runtimes through the CLI, but no SDK package was found on npm or PyPI (7 of 15)."
          },
          {
            "key": "security",
            "name": "Security \u0026 auth",
            "weight": 14,
            "effectiveWeight": 17.5,
            "score": 73,
            "points": 12.78,
            "reason": "Purpose-limited credentials. An agent credential can only create and read its own requests, a provisioner token only manages instances, personal keys can be narrowed and expire after 90 days by default, and the MCP server uses OAuth with PKCE, dynamic client registration and 35 scopes. Choosing specific actions is limited to the hosted paid plans (28 of 30). Agents and organisation keys can never decide a request, sensitive grants need a recent sign-in, and the docs say the required-MFA settings don't yet work with the built-in sign-in methods (16 of 20). Reviewers see agent reasoning as a claim separate from the arguments, `server` is documented as an unverified label, and notifications never carry arguments (11 of 15). Append-only audit log with search by API, and every key's changes recorded under the key, in the hosted edition (13 of 15). The footer says SOC 2 Type II with no report, auditor or trust page. No security.txt (404 on both hosts), disclosure policy or bounty found (5 of 20)."
          },
          {
            "key": "payments",
            "name": "Payments \u0026 pricing",
            "weight": 10,
            "effectiveWeight": 12.5,
            "score": 30,
            "points": 3.75,
            "reason": "No machine payment protocol (0). Public plan prices, Free at $0 for up to 5 members and Scale at $20 per user a month, with no per-request price and unpublished monthly allowances for gateway calls and phone messages (10). The Free plan and trial need no subscription per the billing docs. We did not sign up to confirm that no card is asked for (20). A person signs up in a browser and approves each agent's enrolment. Provisioner tokens then issue instance credentials by API (0)."
          },
          {
            "key": "tasks",
            "name": "Task success",
            "weight": 10,
            "effectiveWeight": 0,
            "pending": true,
            "points": 0,
            "reason": "Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored."
          },
          {
            "key": "maintenance",
            "name": "Maintenance \u0026 community",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 49,
            "points": 4.29,
            "reason": "The CLI's `latest` build files were last modified on 8 October 2026, and the sitemap dates docs changes to 6 October (30). No versioned release notes or changelog were found. The sitemap shows docs edits on eight dates between 22 September and 6 October, which we count in part (5 of 20). Closed service with email support said to reply within one working day and a Discord for the protocol. The linked GitHub repositories returned 404 (6 of 15). No official SDK found. The CLI is the only client (5 of 15). CLI builds for four platforms ship with SHA256SUMS, and no public CI was found (3 of 10)."
          },
          {
            "key": "transparency",
            "name": "Transparency \u0026 trust",
            "weight": 7,
            "effectiveWeight": 8.75,
            "score": 53,
            "points": 4.64,
            "note": "editorial 52, provenance 53",
            "reason": "Closed hosted service with short, clear terms. The site calls the core open source, but the repository it links to returned 404 on 8 October 2026, so no licence could be read (15 of 30). The privacy policy and terms agree on no model training, server logs kept 30 days and records kept for the life of the organisation. The purge after deletion is only 'a short grace period', no DPA was found, and the AI Judge docs name OpenAI model keys while the processor list names no model provider (18 of 30). The terms promise notice of removals and 14 days' email notice of material changes to the terms, with no dated deprecation policy (5 of 20). Eight processors are named with purposes and hosting is stated as Azure UK South, less the missing model provider (14 of 20)."
          }
        ],
        "assessment": {
          "date": "2026-10-08",
          "basis": "public evidence",
          "confidence": "medium",
          "notes": {
            "ergonomics": "The approval surface is 7 operations and a request needs three fields. List endpoints take `limit`, and the MCP server's tool list could not be read without signing in (17 of 25). `limit` on 14 list operations, `cursor` or `offset`, `q`, status filters and eight audit filters (16 of 20). Errors carry a stable `type` and `code`, a `request_id` and structured `details`, with 409, 412 and 428 codes an agent can act on (18 of 20). Mandatory idempotency keys and `If-Match` on revision activation. MCP tool annotations were not checked (16 of 20). Sensible defaults and few required parameters, with hooks for six agent runtimes through the CLI, but no SDK package was found on npm or PyPI (7 of 15).",
            "maintenance": "The CLI's `latest` build files were last modified on 8 October 2026, and the sitemap dates docs changes to 6 October (30). No versioned release notes or changelog were found. The sitemap shows docs edits on eight dates between 22 September and 6 October, which we count in part (5 of 20). Closed service with email support said to reply within one working day and a Discord for the protocol. The linked GitHub repositories returned 404 (6 of 15). No official SDK found. The CLI is the only client (5 of 15). CLI builds for four platforms ship with SHA256SUMS, and no public CI was found (3 of 10).",
            "payments": "No machine payment protocol (0). Public plan prices, Free at $0 for up to 5 members and Scale at $20 per user a month, with no per-request price and unpublished monthly allowances for gateway calls and phone messages (10). The Free plan and trial need no subscription per the billing docs. We did not sign up to confirm that no card is asked for (20). A person signs up in a browser and approves each agent's enrolment. Provisioner tokens then issue instance credentials by API (0).",
            "reliability": "Graded as a hosted service. No status page is linked from the site, the docs or the support page, and status.withhuman.ai did not connect (0), so there is no incident history to read (5). No request rate limits are published. 429 is documented only for the plan's limit on pending requests or active agents, with no numbers in the docs (0). `Idempotency-Key` is required on four write commands with documented replay and conflict behaviour, and the long-poll guide says to call again after a dropped connection, but no Retry-After or backoff guidance was found for 429 (11 of 15). The terms give no uptime guarantee outside an enterprise agreement (0). The terms say the service is in early access and the API document is version 0.1.0 (0).",
            "schema": "A public OpenAPI 3.1 document with 116 operations and 148 schemas, also served by each instance at `/api/openapi.yaml` (25). llms.txt lists every docs page with a Markdown copy (10). Operation descriptions state purpose, preconditions and what each credential may do, and the docs separate the MCP server from the MCP gateway (16 of 20). Enums for status, required fields and bounded durations are typed. `arguments`, `context` and instance metadata are free-form objects by design (12 of 15). Each operation has a curl example, sample responses and a response table, and the error envelope has a table of stable types (13 of 15). Paths are versioned (`/api/aap/v1`, `/api/v1`), but no changelog was found and the blog is empty (5 of 15).",
            "security": "Purpose-limited credentials. An agent credential can only create and read its own requests, a provisioner token only manages instances, personal keys can be narrowed and expire after 90 days by default, and the MCP server uses OAuth with PKCE, dynamic client registration and 35 scopes. Choosing specific actions is limited to the hosted paid plans (28 of 30). Agents and organisation keys can never decide a request, sensitive grants need a recent sign-in, and the docs say the required-MFA settings don't yet work with the built-in sign-in methods (16 of 20). Reviewers see agent reasoning as a claim separate from the arguments, `server` is documented as an unverified label, and notifications never carry arguments (11 of 15). Append-only audit log with search by API, and every key's changes recorded under the key, in the hosted edition (13 of 15). The footer says SOC 2 Type II with no report, auditor or trust page. No security.txt (404 on both hosts), disclosure policy or bounty found (5 of 20).",
            "transparency": "Closed hosted service with short, clear terms. The site calls the core open source, but the repository it links to returned 404 on 8 October 2026, so no licence could be read (15 of 30). The privacy policy and terms agree on no model training, server logs kept 30 days and records kept for the life of the organisation. The purge after deletion is only 'a short grace period', no DPA was found, and the AI Judge docs name OpenAI model keys while the processor list names no model provider (18 of 30). The terms promise notice of removals and 14 days' email notice of material changes to the terms, with no dated deprecation policy (5 of 20). Eight processors are named with purposes and hosting is stated as Azure UK South, less the missing model provider (14 of 20)."
          },
          "sources": [
            {
              "what": "home page",
              "url": "https://withhuman.ai",
              "seen": "2026-10-08"
            },
            {
              "what": "pricing",
              "url": "https://withhuman.ai/pricing",
              "seen": "2026-10-08"
            },
            {
              "what": "docs index for agents",
              "url": "https://withhuman.ai/llms.txt",
              "seen": "2026-10-08"
            },
            {
              "what": "API overview, credentials, errors, idempotency",
              "url": "https://withhuman.ai/docs/reference/overview.md",
              "seen": "2026-10-08"
            },
            {
              "what": "Agent Approval Protocol reference",
              "url": "https://withhuman.ai/docs/reference/agent-approval-protocol.md",
              "seen": "2026-10-08"
            },
            {
              "what": "OpenAPI document",
              "url": "https://withhuman.ai/openapi.yaml",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP server",
              "url": "https://withhuman.ai/docs/web-app/mcp-server.md",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP OAuth metadata",
              "url": "https://app.withhuman.ai/.well-known/oauth-authorization-server",
              "seen": "2026-10-08"
            },
            {
              "what": "MCP gateway",
              "url": "https://withhuman.ai/docs/web-app/mcp-gateway.md",
              "seen": "2026-10-08"
            },
            {
              "what": "billing and plan limits",
              "url": "https://withhuman.ai/docs/web-app/billing.md",
              "seen": "2026-10-08"
            },
            {
              "what": "personal API keys",
              "url": "https://withhuman.ai/docs/web-app/personal-api-keys.md",
              "seen": "2026-10-08"
            },
            {
              "what": "organisation policies and MFA limitation",
              "url": "https://withhuman.ai/docs/web-app/organization-policies.md",
              "seen": "2026-10-08"
            },
            {
              "what": "AI Judge blocks",
              "url": "https://withhuman.ai/docs/web-app/ai-judge-blocks.md",
              "seen": "2026-10-08"
            },
            {
              "what": "audit log",
              "url": "https://withhuman.ai/docs/web-app/audit-log.md",
              "seen": "2026-10-08"
            },
            {
              "what": "terms",
              "url": "https://withhuman.ai/terms",
              "seen": "2026-10-08"
            },
            {
              "what": "privacy policy",
              "url": "https://withhuman.ai/privacy",
              "seen": "2026-10-08"
            },
            {
              "what": "support",
              "url": "https://withhuman.ai/support",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI installer",
              "url": "https://downloads.withhuman.ai/install.sh",
              "seen": "2026-10-08"
            },
            {
              "what": "CLI release checksums",
              "url": "https://downloads.withhuman.ai/cli/latest/SHA256SUMS",
              "seen": "2026-10-08"
            },
            {
              "what": "linked repository, 404",
              "url": "https://github.com/withHumanAI/withHuman",
              "seen": "2026-10-08"
            },
            {
              "what": "GitHub organisation, no public repositories",
              "url": "https://github.com/withHumanAI",
              "seen": "2026-10-08"
            },
            {
              "what": "protocol site",
              "url": "https://agentapprovalprotocol.io/docs/getting-started/introduction",
              "seen": "2026-10-08"
            },
            {
              "what": "domain registration",
              "url": "https://rdap.org/domain/withhuman.ai",
              "seen": "2026-10-08"
            }
          ],
          "openQuestions": [
            "The lead named an npm package `@withhuman/mcp` and SDKs. The npm registry returned 404 for `@withhuman/mcp`, `@withhuman/cli` and `@withhuman/sdk`, and PyPI for `withhuman`. The MCP server is hosted.",
            "Whether the open-source edition exists in public. Both linked repositories returned 404 on 8 October 2026, and the header shows the number 123 beside the GitHub link.",
            "unchecked: the MCP server's tool count, input schemas and annotations, which need a signed-in account.",
            "unchecked: whether signup or the trial asks for a card. The signup page is drawn by script and we did not create an account.",
            "unchecked: status.withhuman.ai did not connect through our proxy. No status page is linked anywhere on the site.",
            "Which company supplies the AI Judge models. The docs list keys such as `gpt-5.6-luna`, and the privacy policy's processor list names no model provider.",
            "What backs the SOC 2 Type II line in the site footer. No report, auditor or trust page was found.",
            "The numbers behind the Free plan's limits on pending approvals, gateway tool calls and phone messages."
          ]
        },
        "negative": -2,
        "negativeNotes": [
          "8 October 2026. The home page and pricing page describe an open-source, self-hostable edition and link https://github.com/withHumanAI/withHuman, which returned 404. The withHumanAI organisation listed no public repositories and the protocol repository https://github.com/agentapprovalprotocol/agentapprovalprotocol also returned 404. Counted as a claim the public cannot verify today (-2). Sources https://withhuman.ai/pricing and https://github.com/withHumanAI"
        ],
        "verdict": "The approval API is small and carefully specified, with a public OpenAPI 3.1 document, mandatory idempotency keys and agent credentials that can never approve. The service is in early access under its own terms, with no status page, published rate limits or changelog, and the open-source repository the site links to returned 404 on 8 October 2026.",
        "bestFor": "Teams that want tool calls from coding agents or their own agents held for approval by rules, with escalation and an audit log, and no review UI to build.",
        "strengths": [
          "Public OpenAPI 3.1 document with 116 operations and 148 schemas, plus llms.txt and a Markdown copy of every docs page",
          "`Idempotency-Key` is required on request creation, instance creation and decisions, and a reused key with changed input answers 409",
          "An agent credential can only create requests and wait for decisions. Approving or denying needs a signed-in person or a personal key",
          "The MCP server signs in with OAuth, PKCE and dynamic client registration, across 35 scopes, with access lasting 90 days or until revoked",
          "Free hosted plan at $0 for up to 5 members with unlimited agents and approval requests, per the pricing page"
        ],
        "weaknesses": [
          "The terms say the service is in early access, and the API document is version 0.1.0",
          "No status page, published request rate limits, SLA outside an enterprise contract, or changelog found",
          "The GitHub repository the site links as its open-source edition returned 404 on 8 October 2026, and the organisation lists no public repositories",
          "No SDK found on npm or PyPI. Integration is the HTTP API, the CLI hooks or the MCP gateway",
          "The site footer says SOC 2 Type II with no report, auditor or trust page, and neither host serves a security.txt"
        ],
        "agentNotes": [
          "Send an `Idempotency-Key` header on `POST /api/aap/v1/requests`. The call answers 400 without one",
          "Read the decision with `GET /api/aap/v1/requests/{id}?wait=30s` and repeat while `status` is `pending`. `wait` is capped at 30 seconds",
          "Set `timeout` between one second and seven days, and treat `expired` and `cancelled` as a refusal",
          "Start an approved call within five minutes of `decided_at`, because the decision carries an `expires_at`",
          "Cancel a request when you stop waiting, so reviewers stop seeing it"
        ],
        "metrics": {
          "kind": "remote",
          "measured": false
        },
        "reviewCount": 0,
        "avgRating": 0,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "D",
            "methodology": "0.4",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 51.8
          }
        ],
        "editorialScores": {
          "ergonomics": 74,
          "maintenance": 49,
          "payments": 30,
          "reliability": 16,
          "schema": 81,
          "security": 73,
          "transparency": 52
        },
        "provenanceScore": 53
      },
      "connect": {
        "install": "curl -fsSL https://downloads.withhuman.ai/install.sh | sh -s -- onboard",
        "http": "curl -X POST \"https://app.withhuman.ai/api/aap/v1/requests\" \\\n  -H \"Authorization: Bearer $WITHHUMAN_TOKEN\" \\\n  -H \"Idempotency-Key: 4f1c9a2e-7b3d-4e8f-a1c5-2d6b8e0f9a31\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{ \"tool\": \"Bash\", \"arguments\": { \"command\": \"rm -rf build\" }, \"timeout\": \"30m\" }'",
        "claudeCode": "claude mcp add --transport http --scope user withhuman https://app.withhuman.ai/api/mcp/v1",
        "config": {
          "mcpServers": {
            "withhuman": {
              "url": "https://app.withhuman.ai/api/mcp/v1"
            }
          }
        }
      },
      "letme": {
        "capability": "https://letme.dev/hitl.approve",
        "tool": "https://letme.dev/withhuman"
      },
      "notable": [
        "An approval request is one `POST /api/aap/v1/requests` with `tool`, `arguments` and `timeout`, and optional `server`, `agent_reasoning` and `context`. The pipeline can decide at once or leave the request `pending` (https://withhuman.ai/docs/reference/agent-approval-protocol.md)",
        "The API has two halves, `/api/aap/v1` for the Agent Approval Protocol and `/api/v1` for the review queue, agents, pipelines, escalation paths and organisation settings (https://withhuman.ai/docs/reference/overview.md)",
        "The MCP server at `https://app.withhuman.ai/api/mcp/v1` configures withHuman itself (pipelines, escalation paths, teams, agents, webhook endpoints). Deciding requests always needs a signed-in person (https://withhuman.ai/docs/web-app/mcp-server.md)",
        "The CLI installs hooks for Claude Code, Codex, OpenClaw, Pi, Hermes and DeepSeek (https://withhuman.ai/docs/web-app/agents.md)",
        "Reviewers can be reached by email, text message, WhatsApp, Slack, Discord and the iPhone and Android apps, and notification messages never carry the request's arguments (https://withhuman.ai/privacy)",
        "The terms name Metoro Inc as operator and say the service is in early access (https://withhuman.ai/terms, effective 4 September 2026)",
        "The site links https://github.com/withHumanAI/withHuman as the open-source edition. That URL and https://github.com/agentapprovalprotocol/agentapprovalprotocol both returned 404 on 8 October 2026"
      ],
      "area": "agent-runtime",
      "details": [
        {
          "label": "APIs",
          "value": "Agent Approval Protocol at `/api/aap/v1` (7 operations) and the product API at `/api/v1` (107), in one OpenAPI 3.1 document, version 0.1.0, served from https://app.withhuman.ai"
        },
        {
          "label": "MCP server",
          "value": "Hosted, streamable HTTP at `https://app.withhuman.ai/api/mcp/v1`. It manages agents, people, teams, pipelines, escalation paths, webhook endpoints, the gateway and the audit log. It cannot decide requests"
        },
        {
          "label": "MCP gateway",
          "value": "Hosted edition only. It keeps a downstream MCP server's credentials in withHuman and sends every call through the approval pipeline. The CLI adds it to an agent as `withhuman-gateway`"
        },
        {
          "label": "Credentials",
          "value": "Agent credential `whc_`, provisioner token `whp_`, personal key `whk_`, organisation key `who_`, session cookie. Shown once, stored as a hash, checked live on every call"
        },
        {
          "label": "Decisions",
          "value": "`pending`, `approved`, `denied`, `expired` or `cancelled`, with an optional reviewer note. Long poll with `wait` up to 30 seconds, or a signed webhook to the instance in asynchronous mode"
        },
        {
          "label": "Timeouts",
          "value": "`timeout` from one second to seven days per request. Escalation paths contact further reviewers after set delays, and an unanswered request expires at its deadline"
        },
        {
          "label": "Rules",
          "value": "Approval pipelines of blocks with conditions on agent, tool, arguments and context, an AI Judge block, webhook blocks, branch and delegate blocks, stored as numbered revisions with rollback"
        },
        {
          "label": "Channels",
          "value": "Email, Slack and Discord on every hosted plan, text message and WhatsApp on hosted plans, iPhone and Android apps from Scale"
        },
        {
          "label": "Errors",
          "value": "One envelope with a stable `type` and `code`, a `request_id` matching the `X-Request-ID` header, and `details` on documented codes. 429 means a limit on pending requests or active agents was reached"
        },
        {
          "label": "Audit",
          "value": "Append-only audit log in the hosted edition, searchable in the app, the API and the MCP server. SIEM export on Enterprise"
        },
        {
          "label": "Hosting",
          "value": "Microsoft Azure UK South, with Cloudflare in front, per the privacy policy"
        },
        {
          "label": "Support",
          "value": "Email, with a reply usually within one working day per the support page. Enterprise contracts add a shared channel and a 30-minute response for blocking issues"
        }
      ],
      "unitPrices": [
        {
          "item": "Scale plan",
          "unit": "seat-month",
          "usd": 20,
          "note": "Free plan covers up to 5 members"
        }
      ],
      "provenance": {
        "legalEntity": "Metoro Inc",
        "domain": "withhuman.ai",
        "domainRegistered": "2026-07-13",
        "endpointOnVendorDomain": true,
        "terms": "https://withhuman.ai/terms",
        "privacy": "https://withhuman.ai/privacy",
        "statusPage": "",
        "changelog": "",
        "securityTxt": "none",
        "checked": "2026-10-08",
        "notes": [
          "The terms (effective 4 September 2026) are between the user and Metoro Inc, which operates withHuman, and cover the hosted service, the iPhone app and the website. Delaware law governs.",
          "The privacy policy (effective 4 September 2026) calls Metoro Inc a Delaware corporation and covers approval requests, decisions and audit records as well as the website.",
          "RDAP for withhuman.ai gives a registration date of 2026-07-13.",
          "https://withhuman.ai/.well-known/security.txt and https://app.withhuman.ai/.well-known/security.txt both returned 404 on 2026-10-08.",
          "No status page is linked from the site, the docs or the support page, and status.withhuman.ai did not connect. No changelog was found, and the blog says coming soon.",
          "The API and the MCP server answer at app.withhuman.ai, and the CLI downloads from downloads.withhuman.ai."
        ],
        "score": 53,
        "checks": [
          {
            "check": "Legal entity named",
            "value": "Metoro Inc",
            "points": 20,
            "max": 20,
            "state": "ok"
          },
          {
            "check": "Domain age",
            "value": "withhuman.ai, registered 2026-07-13 (under a year)",
            "points": 0,
            "max": 15,
            "state": "no"
          },
          {
            "check": "Endpoint on the vendor's domain",
            "value": "app.withhuman.ai",
            "points": 15,
            "max": 15,
            "state": "ok"
          },
          {
            "check": "Terms of service",
            "value": "read, states 6 of the 7 things a reader expects",
            "points": 9.1,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Privacy policy",
            "value": "read, states 6 of the 8 things a reader expects",
            "points": 8.5,
            "max": 10,
            "state": "part"
          },
          {
            "check": "Status page",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "Changelog",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          },
          {
            "check": "security.txt",
            "value": "not found",
            "points": 0,
            "max": 10,
            "state": "no"
          }
        ],
        "policies": [
          {
            "kind": "terms",
            "url": "https://withhuman.ai/terms",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-04",
            "words": 1230,
            "points": 9.1,
            "max": 10,
            "expected": [
              {
                "key": "terms.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "We may update these terms. When we do, we change the date below and, for changes that matter, tell account holders by email at least fourteen days before they take effect. Continuing to use the servi…",
                "says": "Last updated 2026-09-04"
              },
              {
                "key": "terms.law",
                "label": "Names the governing law or courts",
                "found": true,
                "quote": "Otherwise these terms are governed by the laws of the State of Delaware, United States, without regard to its conflict of law rules, and disputes go to the state and federal courts located in Delaware.",
                "says": "The law of the State of Delaware, with disputes in the courts of Delaware"
              },
              {
                "key": "terms.liability",
                "label": "States a limit on its liability",
                "found": true,
                "quote": "To the extent the law allows, neither party is liable for indirect, incidental, special, or consequential loss, and our total liability under these terms is limited to the fees you paid us in the twelve months before the claim.",
                "says": "Capped at the fees paid in the 12 months before the claim"
              },
              {
                "key": "terms.termination",
                "label": "Says how the agreement or account can be ended",
                "found": true,
                "quote": "We may suspend an organization or an account that breaches these rules, giving notice where it is reasonable to do so."
              },
              {
                "key": "terms.changes",
                "label": "Says how changes to the terms are announced",
                "found": false
              },
              {
                "key": "terms.use",
                "label": "Lists what users may not do",
                "found": true,
                "quote": "Use the service to approve, route, or carry out anything unlawful, or anything that harms other people or their property."
              },
              {
                "key": "terms.sla",
                "label": "Refers to a service level or uptime commitment",
                "found": true,
                "quote": "We aim to keep the service available at all times, but we do not guarantee uptime outside an enterprise agreement, which may include an availability commitment and a response-time commitment for blocking issues."
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "The terms say content sent by agents and reviewers' decisions are never used to train models.",
                "quote": "We process it only to provide the service, as described in our privacy policy, and we never use it to train models."
              },
              {
                "date": "2026-10-08",
                "text": "The service is in early access and functionality may be added, altered or removed, with notice when something relied on is removed.",
                "quote": "The service is in early access. Features change, and we may add, alter, or remove functionality. We give notice of changes that remove something you rely on."
              },
              {
                "date": "2026-10-08",
                "text": "The customer must defend and indemnify the vendor against claims arising from content its agents send and actions they take.",
                "quote": "You will defend and indemnify us against claims arising from the content your agents send, the actions they take, or your breach of these terms."
              }
            ]
          },
          {
            "kind": "privacy",
            "url": "https://withhuman.ai/privacy",
            "state": "read",
            "readAt": "2026-10-08",
            "statedDate": "2026-09-04",
            "words": 1027,
            "points": 8.5,
            "max": 10,
            "expected": [
              {
                "key": "privacy.date",
                "label": "Gives the date it was last updated",
                "found": true,
                "quote": "When this policy changes we update the date below and, for changes that matter, tell account holders by email. This version is effective 4 September 2026.",
                "says": "Last updated 2026-09-04"
              },
              {
                "key": "privacy.collected",
                "label": "Says what personal data is collected",
                "found": true,
                "quote": "This page says what we collect, why, where it is kept, and how to get it back or have it removed."
              },
              {
                "key": "privacy.retention",
                "label": "Says how long data is kept",
                "found": true,
                "quote": "Account data for as long as your organization is active."
              },
              {
                "key": "privacy.processors",
                "label": "Says who else receives the data",
                "found": true,
                "quote": "We do not share, sell, or provide your mobile phone number or messaging consent data to third parties or affiliates for marketing or promotional purposes."
              },
              {
                "key": "privacy.sale",
                "label": "Says whether personal data is sold or shared for advertising",
                "found": true,
                "quote": "We do not run advertising or tracking on the website, the web app, or the iPhone app, and the iPhone app declares no tracking to Apple."
              },
              {
                "key": "privacy.rights",
                "label": "Says what rights people have over their data",
                "found": false
              },
              {
                "key": "privacy.contact",
                "label": "Gives a privacy contact",
                "found": true,
                "quote": "Questions and requests about this policy go to [email protected].",
                "says": "Gives an email address, hidden from our reader by the page"
              },
              {
                "key": "privacy.transfers",
                "label": "Says where data is transferred or stored",
                "found": false
              }
            ],
            "notes": [
              {
                "date": "2026-10-08",
                "text": "Approval requests hold the tool call, its arguments and the agent's reasoning, and can include the customer's own customers' data.",
                "quote": "This can include your customers' data if an agent includes it; your organization decides what its agents send."
              },
              {
                "date": "2026-10-08",
                "text": "The policy says approval requests, decisions and notes are not used to train models.",
                "quote": "We do not use approval requests, decisions, or notes to train models."
              }
            ]
          }
        ]
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/withhuman.json",
      "live": {
        "slug": "withhuman",
        "probe": {
          "target": "https://app.withhuman.ai",
          "method": "get",
          "lastAt": "2026-10-08T21:53:38.699457954Z",
          "lastOk": true,
          "lastStatus": 200,
          "lastMs": 173,
          "authRequired": false,
          "uptime24h": 100,
          "uptime30d": 100,
          "p50ms24h": 166,
          "p95ms24h": 258,
          "samples24h": 28,
          "samples30d": 28,
          "days": [
            {
              "date": "2026-10-08",
              "probes": 28,
              "ok": 28
            }
          ]
        },
        "updatedAt": "2026-10-08T21:53:38.699457954Z"
      }
    },
    "verify": {
      "accepts": "a page on withhuman.ai or one of its subdomains",
      "badgeUrl": "https://www.anchorterminal.com/badges/withhuman.svg",
      "body": {
        "slug": "withhuman",
        "url": "the page with the badge or the link"
      },
      "docs": "https://www.anchorterminal.com/builders/#verify",
      "effect": "none, it never changes a grade, rank or review",
      "endpoint": "https://www.anchorterminal.com/api/v1/verify",
      "listingUrl": "https://www.anchorterminal.com/tools/withhuman",
      "mcpTool": "verify_listing",
      "recheck": "weekly; two failed checks in a row and it lapses, a later pass restores it",
      "snippets": {
        "html": "\u003ca href=\"https://www.anchorterminal.com/tools/withhuman\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/withhuman.svg\" alt=\"withHuman on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e",
        "markdown": "[![withHuman on Anchor Terminal](https://www.anchorterminal.com/badges/withhuman.svg)](https://www.anchorterminal.com/tools/withhuman)",
        "link": "\u003ca href=\"https://www.anchorterminal.com/tools/withhuman\"\u003ewithHuman on Anchor Terminal\u003c/a\u003e"
      }
    }
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/tools/withhuman",
    "json": "https://www.anchorterminal.com/tools/withhuman.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/tools/withhuman.md",
    "slim": "https://www.anchorterminal.com/tools/withhuman.min.md"
  },
  "markdown": "## Overview\n\n**Grade D · 51.8/100 · rank #573 of 722 · #7 in Human approval \u0026 handoff · not agent-ready · confidence medium**\n\n\n## Assessment\n\nThe approval API is small and carefully specified, with a public OpenAPI 3.1 document, mandatory idempotency keys and agent credentials that can never approve. The service is in early access under its own terms, with no status page, published rate limits or changelog, and the open-source repository the site links to returned 404 on 8 October 2026.\n\n## Facts\n\n| Field | Value |\n| --- | --- |\n| Vendor | Metoro Inc (https://withhuman.ai) |\n| Kind | HTTP API |\n| Category | Human approval \u0026 handoff (https://www.anchorterminal.com/categories/human-in-the-loop) |\n| Transport | HTTP |\n| Endpoint | `https://app.withhuman.ai` |\n| Auth | OAuth or key · Five credentials, all sent as `Authorization: Bearer`. An agent credential (`whc_`) is bound to one agent instance and can only create approval requests and wait for decisions. A provisioner token (`whp_`) can only create and manage instances of its agent. A personal API key (`whk_`) follows its owner's permissions, can be narrowed to chosen actions and expires after 90 days by default. An organisation API key (`who_`, Scale plan and above) carries its own permission policies and cannot decide requests. The MCP server at `/api/mcp/v1` signs in with OAuth (authorisation code with PKCE and dynamic client registration) or takes an API key as a bearer token. A person signs up in the browser and connects the first agent. |\n| Pricing | Freemium ($20 / seat-mo) · Free hosted plan at $0 for up to 5 members, with unlimited agents and approval requests, email, Slack and Discord, the audit log and the MCP gateway. Scale is $20 per user a month and adds the phone apps, organisation and scoped API keys, single sign-on and directory sync. Enterprise is a custom annual contract. New organisations start on a trial and move to Free without a subscription. Monthly allowances for gateway tool calls and phone messages exist but their numbers aren't on the pricing page (https://withhuman.ai/pricing, checked 2026-10-08). |\n| x402 | No · No x402, MPP or L402 in the docs, the OpenAPI document or the pricing page (checked 2026-10-08). |\n| Licence | Proprietary hosted service under Metoro Inc's terms. The site describes an open-source edition, but the repository it links to returned 404 on 8 October 2026 |\n| Docs | https://withhuman.ai/docs |\n| llms.txt | https://withhuman.ai/llms.txt |\n| Last release | 2026-10-08 |\n| APIs | Agent Approval Protocol at `/api/aap/v1` (7 operations) and the product API at `/api/v1` (107), in one OpenAPI 3.1 document, version 0.1.0, served from https://app.withhuman.ai |\n| MCP server | Hosted, streamable HTTP at `https://app.withhuman.ai/api/mcp/v1`. It manages agents, people, teams, pipelines, escalation paths, webhook endpoints, the gateway and the audit log. It cannot decide requests |\n| MCP gateway | Hosted edition only. It keeps a downstream MCP server's credentials in withHuman and sends every call through the approval pipeline. The CLI adds it to an agent as `withhuman-gateway` |\n| Credentials | Agent credential `whc_`, provisioner token `whp_`, personal key `whk_`, organisation key `who_`, session cookie. Shown once, stored as a hash, checked live on every call |\n| Decisions | `pending`, `approved`, `denied`, `expired` or `cancelled`, with an optional reviewer note. Long poll with `wait` up to 30 seconds, or a signed webhook to the instance in asynchronous mode |\n| Timeouts | `timeout` from one second to seven days per request. Escalation paths contact further reviewers after set delays, and an unanswered request expires at its deadline |\n| Rules | Approval pipelines of blocks with conditions on agent, tool, arguments and context, an AI Judge block, webhook blocks, branch and delegate blocks, stored as numbered revisions with rollback |\n| Channels | Email, Slack and Discord on every hosted plan, text message and WhatsApp on hosted plans, iPhone and Android apps from Scale |\n| Errors | One envelope with a stable `type` and `code`, a `request_id` matching the `X-Request-ID` header, and `details` on documented codes. 429 means a limit on pending requests or active agents was reached |\n| Audit | Append-only audit log in the hosted edition, searchable in the app, the API and the MCP server. SIEM export on Enterprise |\n| Hosting | Microsoft Azure UK South, with Cloudflare in front, per the privacy policy |\n| Support | Email, with a reply usually within one working day per the support page. Enterprise contracts add a shared channel and a 30-minute response for blocking issues |\n| Capabilities | hitl.approve, hitl.channels, hitl.audit |\n| Tags | hosted, freemium, free-tier, mcp, oauth, openapi, llms-txt, webhooks, enterprise, early-access |\n| JSON | https://www.anchorterminal.com/api/v1/tools/withhuman.json |\n\n## Score breakdown (methodology v0.4, October 2026 research run)\n\nAssessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. \"This run\" is each category's share of the 100 points.\n\n| Category | Weight | This run | Score (0–100) | Points |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% | 20 | 16 | 3.2 |\n| Performance | 10% | pending | pending | n/a |\n| Schema \u0026 documentation | 13% | 16.2 | 81 | 13.2 |\n| Agent ergonomics | 13% | 16.2 | 74 | 12.0 |\n| Security \u0026 auth | 14% | 17.5 | 73 | 12.8 |\n| Payments \u0026 pricing | 10% | 12.5 | 30 | 3.8 |\n| Task success | 10% | pending | pending | n/a |\n| Maintenance \u0026 community | 7% | 8.8 | 49 | 4.3 |\n| Transparency \u0026 trust (editorial 52, provenance 53) | 7% | 8.8 | 53 | 4.6 |\n| Negative events | up to −15 | up to −15 | 8 October 2026. The home page and pricing page describe an open-source, self-hostable edition and link https://github.com/withHumanAI/withHuman, which returned 404. The withHumanAI organisation listed no public repositories and the protocol repository https://github.com/agentapprovalprotocol/agentapprovalprotocol also returned 404. Counted as a claim the public cannot verify today (-2). Sources https://withhuman.ai/pricing and https://github.com/withHumanAI  | -2 |\n| **Total** | | | | **51.8 → D** |\n\n### Why each score\n\n- Reliability 16: Graded as a hosted service. No status page is linked from the site, the docs or the support page, and status.withhuman.ai did not connect (0), so there is no incident history to read (5). No request rate limits are published. 429 is documented only for the plan's limit on pending requests or active agents, with no numbers in the docs (0). `Idempotency-Key` is required on four write commands with documented replay and conflict behaviour, and the long-poll guide says to call again after a dropped connection, but no Retry-After or backoff guidance was found for 429 (11 of 15). The terms give no uptime guarantee outside an enterprise agreement (0). The terms say the service is in early access and the API document is version 0.1.0 (0).\n- Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes.\n- Schema \u0026 documentation 81: A public OpenAPI 3.1 document with 116 operations and 148 schemas, also served by each instance at `/api/openapi.yaml` (25). llms.txt lists every docs page with a Markdown copy (10). Operation descriptions state purpose, preconditions and what each credential may do, and the docs separate the MCP server from the MCP gateway (16 of 20). Enums for status, required fields and bounded durations are typed. `arguments`, `context` and instance metadata are free-form objects by design (12 of 15). Each operation has a curl example, sample responses and a response table, and the error envelope has a table of stable types (13 of 15). Paths are versioned (`/api/aap/v1`, `/api/v1`), but no changelog was found and the blog is empty (5 of 15).\n- Agent ergonomics 74: The approval surface is 7 operations and a request needs three fields. List endpoints take `limit`, and the MCP server's tool list could not be read without signing in (17 of 25). `limit` on 14 list operations, `cursor` or `offset`, `q`, status filters and eight audit filters (16 of 20). Errors carry a stable `type` and `code`, a `request_id` and structured `details`, with 409, 412 and 428 codes an agent can act on (18 of 20). Mandatory idempotency keys and `If-Match` on revision activation. MCP tool annotations were not checked (16 of 20). Sensible defaults and few required parameters, with hooks for six agent runtimes through the CLI, but no SDK package was found on npm or PyPI (7 of 15).\n- Security \u0026 auth 73: Purpose-limited credentials. An agent credential can only create and read its own requests, a provisioner token only manages instances, personal keys can be narrowed and expire after 90 days by default, and the MCP server uses OAuth with PKCE, dynamic client registration and 35 scopes. Choosing specific actions is limited to the hosted paid plans (28 of 30). Agents and organisation keys can never decide a request, sensitive grants need a recent sign-in, and the docs say the required-MFA settings don't yet work with the built-in sign-in methods (16 of 20). Reviewers see agent reasoning as a claim separate from the arguments, `server` is documented as an unverified label, and notifications never carry arguments (11 of 15). Append-only audit log with search by API, and every key's changes recorded under the key, in the hosted edition (13 of 15). The footer says SOC 2 Type II with no report, auditor or trust page. No security.txt (404 on both hosts), disclosure policy or bounty found (5 of 20).\n- Payments \u0026 pricing 30: No machine payment protocol (0). Public plan prices, Free at $0 for up to 5 members and Scale at $20 per user a month, with no per-request price and unpublished monthly allowances for gateway calls and phone messages (10). The Free plan and trial need no subscription per the billing docs. We did not sign up to confirm that no card is asked for (20). A person signs up in a browser and approves each agent's enrolment. Provisioner tokens then issue instance credentials by API (0).\n- Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored.\n- Maintenance \u0026 community 49: The CLI's `latest` build files were last modified on 8 October 2026, and the sitemap dates docs changes to 6 October (30). No versioned release notes or changelog were found. The sitemap shows docs edits on eight dates between 22 September and 6 October, which we count in part (5 of 20). Closed service with email support said to reply within one working day and a Discord for the protocol. The linked GitHub repositories returned 404 (6 of 15). No official SDK found. The CLI is the only client (5 of 15). CLI builds for four platforms ship with SHA256SUMS, and no public CI was found (3 of 10).\n- Transparency \u0026 trust 53: Closed hosted service with short, clear terms. The site calls the core open source, but the repository it links to returned 404 on 8 October 2026, so no licence could be read (15 of 30). The privacy policy and terms agree on no model training, server logs kept 30 days and records kept for the life of the organisation. The purge after deletion is only 'a short grace period', no DPA was found, and the AI Judge docs name OpenAI model keys while the processor list names no model provider (18 of 30). The terms promise notice of removals and 14 days' email notice of material changes to the terms, with no dated deprecation policy (5 of 20). Eight processors are named with purposes and hosting is stated as Azure UK South, less the missing model provider (14 of 20).\n\nFix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (22 items): https://www.anchorterminal.com/fixes/withhuman.md (JSON https://www.anchorterminal.com/fixes/withhuman.json)\n\n### What we couldn't check\n\n- The lead named an npm package `@withhuman/mcp` and SDKs. The npm registry returned 404 for `@withhuman/mcp`, `@withhuman/cli` and `@withhuman/sdk`, and PyPI for `withhuman`. The MCP server is hosted.\n- Whether the open-source edition exists in public. Both linked repositories returned 404 on 8 October 2026, and the header shows the number 123 beside the GitHub link.\n- unchecked: the MCP server's tool count, input schemas and annotations, which need a signed-in account.\n- unchecked: whether signup or the trial asks for a card. The signup page is drawn by script and we did not create an account.\n- unchecked: status.withhuman.ai did not connect through our proxy. No status page is linked anywhere on the site.\n- Which company supplies the AI Judge models. The docs list keys such as `gpt-5.6-luna`, and the privacy policy's processor list names no model provider.\n- What backs the SOC 2 Type II line in the site footer. No report, auditor or trust page was found.\n- The numbers behind the Free plan's limits on pending approvals, gateway tool calls and phone messages.\n\n### Sources\n\n- home page: \u003chttps://withhuman.ai\u003e (seen 2026-10-08)\n- pricing: \u003chttps://withhuman.ai/pricing\u003e (seen 2026-10-08)\n- docs index for agents: \u003chttps://withhuman.ai/llms.txt\u003e (seen 2026-10-08)\n- API overview, credentials, errors, idempotency: \u003chttps://withhuman.ai/docs/reference/overview.md\u003e (seen 2026-10-08)\n- Agent Approval Protocol reference: \u003chttps://withhuman.ai/docs/reference/agent-approval-protocol.md\u003e (seen 2026-10-08)\n- OpenAPI document: \u003chttps://withhuman.ai/openapi.yaml\u003e (seen 2026-10-08)\n- MCP server: \u003chttps://withhuman.ai/docs/web-app/mcp-server.md\u003e (seen 2026-10-08)\n- MCP OAuth metadata: \u003chttps://app.withhuman.ai/.well-known/oauth-authorization-server\u003e (seen 2026-10-08)\n- MCP gateway: \u003chttps://withhuman.ai/docs/web-app/mcp-gateway.md\u003e (seen 2026-10-08)\n- billing and plan limits: \u003chttps://withhuman.ai/docs/web-app/billing.md\u003e (seen 2026-10-08)\n- personal API keys: \u003chttps://withhuman.ai/docs/web-app/personal-api-keys.md\u003e (seen 2026-10-08)\n- organisation policies and MFA limitation: \u003chttps://withhuman.ai/docs/web-app/organization-policies.md\u003e (seen 2026-10-08)\n- AI Judge blocks: \u003chttps://withhuman.ai/docs/web-app/ai-judge-blocks.md\u003e (seen 2026-10-08)\n- audit log: \u003chttps://withhuman.ai/docs/web-app/audit-log.md\u003e (seen 2026-10-08)\n- terms: \u003chttps://withhuman.ai/terms\u003e (seen 2026-10-08)\n- privacy policy: \u003chttps://withhuman.ai/privacy\u003e (seen 2026-10-08)\n- support: \u003chttps://withhuman.ai/support\u003e (seen 2026-10-08)\n- CLI installer: \u003chttps://downloads.withhuman.ai/install.sh\u003e (seen 2026-10-08)\n- CLI release checksums: \u003chttps://downloads.withhuman.ai/cli/latest/SHA256SUMS\u003e (seen 2026-10-08)\n- linked repository, 404: \u003chttps://github.com/withHumanAI/withHuman\u003e (seen 2026-10-08)\n- GitHub organisation, no public repositories: \u003chttps://github.com/withHumanAI\u003e (seen 2026-10-08)\n- protocol site: \u003chttps://agentapprovalprotocol.io/docs/getting-started/introduction\u003e (seen 2026-10-08)\n- domain registration: \u003chttps://rdap.org/domain/withhuman.ai\u003e (seen 2026-10-08)\n\n## Who's behind it (provenance 53/100, checked 2026-10-08)\n\n| Check | Finding | Points |\n| --- | --- | --- |\n| Legal entity named | Metoro Inc | 20/20 |\n| Domain age | withhuman.ai, registered 2026-07-13 (under a year) | 0/15 |\n| Endpoint on the vendor's domain | app.withhuman.ai | 15/15 |\n| Terms of service | read, states 6 of the 7 things a reader expects | 9.1/10 |\n| Privacy policy | read, states 6 of the 8 things a reader expects | 8.5/10 |\n| Status page | not found | 0/10 |\n| Changelog | not found | 0/10 |\n| security.txt | not found | 0/10 |\n\nThe terms (effective 4 September 2026) are between the user and Metoro Inc, which operates withHuman, and cover the hosted service, the iPhone app and the website. Delaware law governs.\n\nThe privacy policy (effective 4 September 2026) calls Metoro Inc a Delaware corporation and covers approval requests, decisions and audit records as well as the website.\n\nRDAP for withhuman.ai gives a registration date of 2026-07-13.\n\nhttps://withhuman.ai/.well-known/security.txt and https://app.withhuman.ai/.well-known/security.txt both returned 404 on 2026-10-08.\n\nNo status page is linked from the site, the docs or the support page, and status.withhuman.ai did not connect. No changelog was found, and the blog says coming soon.\n\nThe API and the MCP server answer at app.withhuman.ai, and the CLI downloads from downloads.withhuman.ai.\n\n### Terms and privacy, as read\n\nA reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice.\n\n**Terms of service** (https://withhuman.ai/terms), read 2026-10-08, dated 2026-09-04, states 6 of the 7 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-09-04.\n- Names the governing law or courts. The law of the State of Delaware, with disputes in the courts of Delaware.\n- States a limit on its liability. Capped at the fees paid in the 12 months before the claim.\n- Not found in the text. Says how changes to the terms are announced.\n- Also in the text (2026-10-08). The terms say content sent by agents and reviewers' decisions are never used to train models. \"We process it only to provide the service, as described in our privacy policy, and we never use it to train models.\"\n- Also in the text (2026-10-08). The service is in early access and functionality may be added, altered or removed, with notice when something relied on is removed. \"The service is in early access. Features change, and we may add, alter, or remove functionality. We give notice of changes that remove something you rely on.\"\n- Also in the text (2026-10-08). The customer must defend and indemnify the vendor against claims arising from content its agents send and actions they take. \"You will defend and indemnify us against claims arising from the content your agents send, the actions they take, or your breach of these terms.\"\n\n**Privacy policy** (https://withhuman.ai/privacy), read 2026-10-08, dated 2026-09-04, states 6 of the 8 things a reader expects.\n\n- Gives the date it was last updated. Last updated 2026-09-04.\n- Not found in the text. Says what rights people have over their data.\n- Gives a privacy contact. Gives an email address, hidden from our reader by the page.\n- Not found in the text. Says where data is transferred or stored.\n- Also in the text (2026-10-08). Approval requests hold the tool call, its arguments and the agent's reasoning, and can include the customer's own customers' data. \"This can include your customers' data if an agent includes it; your organization decides what its agents send.\"\n- Also in the text (2026-10-08). The policy says approval requests, decisions and notes are not used to train models. \"We do not use approval requests, decisions, or notes to train models.\"\n\n## Live (updated 2026-10-08 21:53 UTC)\n\n- Right now: up, HTTP 200, 173 ms, checked 2026-10-08 21:53 UTC (get on `https://app.withhuman.ai`)\n- Uptime 24h 100.0% (28 probes) · 30 days 100.0% (28 probes) · p50 166 ms · p95 258 ms\n- Always current: https://www.anchorterminal.com/api/v1/live/withhuman.json\n\n## Probe metrics\n\nNot measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score.\n\n## Prices\n\n| Item | Price | Unit | Note |\n| --- | --- | --- | --- |\n| Scale plan | $20 | per seat per month | Free plan covers up to 5 members |\n\nAcross all listings: https://www.anchorterminal.com/prices/index.md\n\n## Strengths\n\n- Public OpenAPI 3.1 document with 116 operations and 148 schemas, plus llms.txt and a Markdown copy of every docs page\n- `Idempotency-Key` is required on request creation, instance creation and decisions, and a reused key with changed input answers 409\n- An agent credential can only create requests and wait for decisions. Approving or denying needs a signed-in person or a personal key\n- The MCP server signs in with OAuth, PKCE and dynamic client registration, across 35 scopes, with access lasting 90 days or until revoked\n- Free hosted plan at $0 for up to 5 members with unlimited agents and approval requests, per the pricing page\n\n## Weaknesses\n\n- The terms say the service is in early access, and the API document is version 0.1.0\n- No status page, published request rate limits, SLA outside an enterprise contract, or changelog found\n- The GitHub repository the site links as its open-source edition returned 404 on 8 October 2026, and the organisation lists no public repositories\n- No SDK found on npm or PyPI. Integration is the HTTP API, the CLI hooks or the MCP gateway\n- The site footer says SOC 2 Type II with no report, auditor or trust page, and neither host serves a security.txt\n\n## Before you call it (notes for agents)\n\n1. Send an `Idempotency-Key` header on `POST /api/aap/v1/requests`. The call answers 400 without one\n2. Read the decision with `GET /api/aap/v1/requests/{id}?wait=30s` and repeat while `status` is `pending`. `wait` is capped at 30 seconds\n3. Set `timeout` between one second and seven days, and treat `expired` and `cancelled` as a refusal\n4. Start an approved call within five minutes of `decided_at`, because the decision carries an `expires_at`\n5. Cancel a request when you stop waiting, so reviewers stop seeing it\n\n## Connect\n\nInstall:\n\n```bash\ncurl -fsSL https://downloads.withhuman.ai/install.sh | sh -s -- onboard\n```\n\nFirst request:\n\n```bash\ncurl -X POST \"https://app.withhuman.ai/api/aap/v1/requests\" \\\n  -H \"Authorization: Bearer $WITHHUMAN_TOKEN\" \\\n  -H \"Idempotency-Key: 4f1c9a2e-7b3d-4e8f-a1c5-2d6b8e0f9a31\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{ \"tool\": \"Bash\", \"arguments\": { \"command\": \"rm -rf build\" }, \"timeout\": \"30m\" }'\n```\n\nClaude Code:\n\n```bash\nclaude mcp add --transport http --scope user withhuman https://app.withhuman.ai/api/mcp/v1\n```\n\nMCP client configuration:\n\n```json\n{\n  \"mcpServers\": {\n    \"withhuman\": {\n      \"url\": \"https://app.withhuman.ai/api/mcp/v1\"\n    }\n  }\n}\n```\n\nThrough letme (picks today, calling later): https://letme.dev/withhuman. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md\n\n## Similar tools\n\nRanked by shared capabilities, then score. Same-category tools with no shared capability key are listed last.\n\n| Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown |\n| --- | --- | --- | --- | --- | --- | --- |\n| Permit MCP Gateway | C | 54.1 | 534 | hitl.approve, hitl.channels, hitl.audit | no | https://www.anchorterminal.com/tools/permit-mcp-gateway.md |\n| Pushary | D | 51.4 | 577 | hitl.approve, hitl.channels, hitl.audit | no | https://www.anchorterminal.com/tools/pushary.md |\n| gotoHuman | E | 43.6 | 670 | hitl.approve, hitl.channels, hitl.audit | no | https://www.anchorterminal.com/tools/gotohuman.md |\n| Temporal | BB | 77.2 | 20 | hitl.approve, hitl.audit | no | https://www.anchorterminal.com/tools/temporal.md |\n| Orkes Conductor Human tasks | C | 54 | 537 | hitl.approve, hitl.audit | no | https://www.anchorterminal.com/tools/orkes-conductor.md |\n| Descope Agentic Identity Hub | A | 78.1 | 13 | hitl.approve | no | https://www.anchorterminal.com/tools/descope-agentic-identity.md |\n\n## Panel reviews (0)\n\nReviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): .\n\nDesk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md\n\n## Notable\n\n- An approval request is one `POST /api/aap/v1/requests` with `tool`, `arguments` and `timeout`, and optional `server`, `agent_reasoning` and `context`. The pipeline can decide at once or leave the request `pending` (source: \u003chttps://withhuman.ai/docs/reference/agent-approval-protocol.md\u003e)\n- The API has two halves, `/api/aap/v1` for the Agent Approval Protocol and `/api/v1` for the review queue, agents, pipelines, escalation paths and organisation settings (source: \u003chttps://withhuman.ai/docs/reference/overview.md\u003e)\n- The MCP server at `https://app.withhuman.ai/api/mcp/v1` configures withHuman itself (pipelines, escalation paths, teams, agents, webhook endpoints). Deciding requests always needs a signed-in person (source: \u003chttps://withhuman.ai/docs/web-app/mcp-server.md\u003e)\n- The CLI installs hooks for Claude Code, Codex, OpenClaw, Pi, Hermes and DeepSeek (source: \u003chttps://withhuman.ai/docs/web-app/agents.md\u003e)\n- Reviewers can be reached by email, text message, WhatsApp, Slack, Discord and the iPhone and Android apps, and notification messages never carry the request's arguments (source: \u003chttps://withhuman.ai/privacy\u003e)\n- The terms name Metoro Inc as operator and say the service is in early access (source: \u003chttps://withhuman.ai/terms, effective 4 September 2026\u003e)\n- The site links https://github.com/withHumanAI/withHuman as the open-source edition. That URL and https://github.com/agentapprovalprotocol/agentapprovalprotocol both returned 404 on 8 October 2026\n\n## Compare\n\n- [gotoHuman vs withHuman](https://www.anchorterminal.com/compare/gotohuman-vs-withhuman.md): E 43.6 vs D 51.8\n- [Inngest vs withHuman](https://www.anchorterminal.com/compare/inngest-vs-withhuman.md): B 66 vs D 51.8\n- [Orkes Conductor Human tasks vs withHuman](https://www.anchorterminal.com/compare/orkes-conductor-vs-withhuman.md): C 54 vs D 51.8\n- [Permit MCP Gateway vs withHuman](https://www.anchorterminal.com/compare/permit-mcp-gateway-vs-withhuman.md): C 54.1 vs D 51.8\n- [Pushary vs withHuman](https://www.anchorterminal.com/compare/pushary-vs-withhuman.md): D 51.4 vs D 51.8\n- [Restate vs withHuman](https://www.anchorterminal.com/compare/restate-vs-withhuman.md): BB 73.3 vs D 51.8\n- [Temporal vs withHuman](https://www.anchorterminal.com/compare/temporal-vs-withhuman.md): BB 77.2 vs D 51.8\n- [Trigger.dev vs withHuman](https://www.anchorterminal.com/compare/trigger-dev-vs-withhuman.md): BB 74.7 vs D 51.8\n\n## Verify this listing\n\nFor the vendor. The badge or a plain link to this page verifies the listing, from a page on withhuman.ai or one of its subdomains. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{\"slug\": \"withhuman\", \"url\": \"…\"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify\n\nHTML badge:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/withhuman\"\u003e\u003cimg src=\"https://www.anchorterminal.com/badges/withhuman.svg\" alt=\"withHuman on Anchor Terminal\" height=\"20\"\u003e\u003c/a\u003e\n```\n\nMarkdown badge, for a README:\n\n```markdown\n[![withHuman on Anchor Terminal](https://www.anchorterminal.com/badges/withhuman.svg)](https://www.anchorterminal.com/tools/withhuman)\n```\n\nPlain link:\n\n```html\n\u003ca href=\"https://www.anchorterminal.com/tools/withhuman\"\u003ewithHuman on Anchor Terminal\u003c/a\u003e\n```\n\n## Share this listing\n\nFor the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say withHuman is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score.\n\n- Dark: https://www.anchorterminal.com/assets/share/withhuman-dark.png\n- Light: https://www.anchorterminal.com/assets/share/withhuman-light.png\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-08",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.4",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Terminal",
        "url": "https://www.anchorterminal.com/tools/"
      },
      {
        "name": "Human approval \u0026 handoff",
        "url": "https://www.anchorterminal.com/categories/human-in-the-loop"
      },
      {
        "name": "withHuman",
        "url": ""
      }
    ],
    "description": "withHuman is a hosted approval service for AI agents from Metoro Inc. It holds an agent's tool calls for a person to approve or deny through the Agent Approval Protocol API, coding-agent hooks, an MCP gateway and an MCP server.",
    "facts": [
      "rank #573 of 722",
      "OAuth or key auth",
      "0 desk reviews"
    ],
    "h1": "withHuman",
    "image": "https://www.anchorterminal.com/assets/og/tools-withhuman.png",
    "path": "/tools/withhuman",
    "published": "2026-10-01",
    "section": "tools",
    "title": "withHuman review for AI agents, grade D (51.8/100) | Anchor Terminal",
    "toc": null,
    "updated": "2026-10-08",
    "url": "https://www.anchorterminal.com/tools/withhuman"
  },
  "tokens": {
    "markdown": 7200,
    "slim": 1730
  },
  "version": 1
}
