# withHuman (slim) > withHuman is a hosted approval service for AI agents from Metoro Inc. It holds an agent's tool calls for a person to approve or deny through the Agent Approval Protocol API, coding-agent hooks, an MCP gateway and an MCP server. - Full: https://www.anchorterminal.com/tools/withhuman.md (~7,200 tokens) · this version ~1,730 tokens · JSON https://www.anchorterminal.com/tools/withhuman.json · canonical https://www.anchorterminal.com/tools/withhuman - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **D · 51.8/100 · rank #573 of 722 · #7 in Human approval & handoff · not agent-ready · confidence medium** Assessment: The approval API is small and carefully specified, with a public OpenAPI 3.1 document, mandatory idempotency keys and agent credentials that can never approve. The service is in early access under its own terms, with no status page, published rate limits or changelog, and the open-source repository the site links to returned 404 on 8 October 2026. ## Facts - Kind: HTTP API · vendor: Metoro Inc · category: Human approval & handoff · legal entity: Metoro Inc · provenance 53/100 - Endpoint: `https://app.withhuman.ai` (HTTP) - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Proprietary hosted service under Metoro Inc's terms. The site describes an open-source edition, but the repository it links to returned 404 on 8 October 2026 - Probe metrics: not measured yet (probes haven't run) - APIs: Agent Approval Protocol at `/api/aap/v1` (7 operations) and the product API at `/api/v1` (107), in one OpenAPI 3.1 document, version 0.1.0, served from https://app.withhuman.ai - MCP server: Hosted, streamable HTTP at `https://app.withhuman.ai/api/mcp/v1`. It manages agents, people, teams, pipelines, escalation paths, webhook endpoints, the gateway and the audit log. It cannot decide requests - MCP gateway: Hosted edition only. It keeps a downstream MCP server's credentials in withHuman and sends every call through the approval pipeline. The CLI adds it to an agent as `withhuman-gateway` - Credentials: Agent credential `whc_`, provisioner token `whp_`, personal key `whk_`, organisation key `who_`, session cookie. Shown once, stored as a hash, checked live on every call - Decisions: `pending`, `approved`, `denied`, `expired` or `cancelled`, with an optional reviewer note. Long poll with `wait` up to 30 seconds, or a signed webhook to the instance in asynchronous mode - Timeouts: `timeout` from one second to seven days per request. Escalation paths contact further reviewers after set delays, and an unanswered request expires at its deadline - Rules: Approval pipelines of blocks with conditions on agent, tool, arguments and context, an AI Judge block, webhook blocks, branch and delegate blocks, stored as numbered revisions with rollback - Channels: Email, Slack and Discord on every hosted plan, text message and WhatsApp on hosted plans, iPhone and Android apps from Scale - Errors: One envelope with a stable `type` and `code`, a `request_id` matching the `X-Request-ID` header, and `details` on documented codes. 429 means a limit on pending requests or active agents was reached - Audit: Append-only audit log in the hosted edition, searchable in the app, the API and the MCP server. SIEM export on Enterprise - Hosting: Microsoft Azure UK South, with Cloudflare in front, per the privacy policy - Support: Email, with a reply usually within one working day per the support page. Enterprise contracts add a shared channel and a 30-minute response for blocking issues - Prices: Scale plan $20 per seat per month - Scores: Reliability 16, Performance pending, Schema & documentation 81, Agent ergonomics 74, Security & auth 73, Payments & pricing 30, Task success pending, Maintenance & community 49, Transparency & trust 53 · negative events -2 · total over the 7 assessed categories - Why: Reliability, Graded as a hosted service. · Schema & documentation, A public OpenAPI 3.1 document with 116 operations and 148 schemas, also served by each instance at `/api/openapi.yaml` (25). · Agent ergonomics, The approval surface is 7 operations and a request needs three fields. · Security & auth, Purpose-limited credentials. · Payments & pricing, No machine payment protocol (0). · Maintenance & community, The CLI's `latest` build files were last modified on 8 October 2026, and the sitemap dates docs changes to 6 October (30). · Transparency & trust, Closed hosted service with short, clear terms. - Sources: 23, open questions: 8, both in the full twin - Capabilities: hitl.approve, hitl.channels, hitl.audit - JSON: https://www.anchorterminal.com/api/v1/tools/withhuman.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/withhuman.svg` or a link to https://www.anchorterminal.com/tools/withhuman from a page on withhuman.ai or one of its subdomains, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Send an `Idempotency-Key` header on `POST /api/aap/v1/requests`. The call answers 400 without one 2. Read the decision with `GET /api/aap/v1/requests/{id}?wait=30s` and repeat while `status` is `pending`. `wait` is capped at 30 seconds 3. Set `timeout` between one second and seven days, and treat `expired` and `cancelled` as a refusal 4. Start an approved call within five minutes of `decided_at`, because the decision carries an `expires_at` 5. Cancel a request when you stop waiting, so reviewers stop seeing it ## Connect ```bash curl -fsSL https://downloads.withhuman.ai/install.sh | sh -s -- onboard ``` ```bash curl -X POST "https://app.withhuman.ai/api/aap/v1/requests" \ -H "Authorization: Bearer $WITHHUMAN_TOKEN" \ -H "Idempotency-Key: 4f1c9a2e-7b3d-4e8f-a1c5-2d6b8e0f9a31" \ -H "Content-Type: application/json" \ -d '{ "tool": "Bash", "arguments": { "command": "rm -rf build" }, "timeout": "30m" }' ``` ```bash claude mcp add --transport http --scope user withhuman https://app.withhuman.ai/api/mcp/v1 ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/withhuman ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | Permit MCP Gateway | C | 54.1 | hitl.approve, hitl.channels, hitl.audit | https://www.anchorterminal.com/tools/permit-mcp-gateway.min.md | | Pushary | D | 51.4 | hitl.approve, hitl.channels, hitl.audit | https://www.anchorterminal.com/tools/pushary.min.md | | gotoHuman | E | 43.6 | hitl.approve, hitl.channels, hitl.audit | https://www.anchorterminal.com/tools/gotohuman.min.md | | Temporal | BB | 77.2 | hitl.approve, hitl.audit | https://www.anchorterminal.com/tools/temporal.min.md | | Orkes Conductor Human tasks | C | 54 | hitl.approve, hitl.audit | https://www.anchorterminal.com/tools/orkes-conductor.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)