Skip to main content

authyouragent (Python)

SDK for Auth Your Agent: let AI agents act for a person on websites, with the person's approval on their phone.

  • AgentClient: an agent asks for access, then calls sites with a short-lived pass and a fresh DPoP proof (RFC 9449) on every request.
  • SiteVerifier: a website checks each call in one line.
  • Browser vault: the agent's browser runs in a container it cannot read into. When a site asks for a password, a CAPTCHA or 2FA, the owner takes over from their phone; clicks that commit something wait for the owner's approval.

Python 3.9+. Depends on httpx, pyjwt, cryptography.

Full documentation: https://authyouragent.com/docs/developers/quickstart

Install

You need Python 3.9+ and Docker.

pip install "authyouragent[mcp]"
authyouragent vault up --agent-id ag_xxxxx --key /path/to/agent-key.pem

vault up starts the browser vault: the browser your agent uses, in a container on your machine. The agent drives it through the vault and never gets its cookies. It prints the env block for your MCP client. If you skip it, the MCP server starts the vault itself the first time the agent needs the browser (AYA_VAULT_AUTOSTART=0 turns that off). See vault/README.md for what protects what, and the known limits.

For just the SDK (no browser, no MCP): pip install authyouragent.

MCP server

The authyouragent-mcp command starts an MCP server with thirteen tools:

  • Browser: navigate, click, type_text, read_page. Only public websites open. Clicks that submit a form, or whose button says create, send, save, delete, pay and the like, wait for your approval on your phone.
  • check_login_wall: is the page asking for a password, a code or a sign-in approval?
  • list_secrets / fill_secret: fill a username, password or authenticator code from your own Bitwarden or Vaultwarden (only the items in its "Auth Your Agent" folder). The agent never sees the value; it fills only on the item's own site and only the right kind of field.
  • request_takeover / wait_for_takeover: you take over the browser from your phone. The agent is disconnected until you finish, and the vault hands back by itself once you have signed in.
  • request_approval: ask you to approve an action the vault cannot see.
  • end_session: sign out of every site used, then destroy the browser profile. Always called at the end.
  • check_agent_status: is the agent still authorized? You can revoke it at any time.
  • report_site: report a site where take over did not work.

Configuration

AYA_AGENT_ID=ag_xxxxx
AYA_KEY_FILE=/path/to/agent-key.pem
AYA_VAULT_URL=http://127.0.0.1:7801
AYA_VAULT_TOKEN_FILE=~/.authyouragent/vault/token

Hermes

mcp:
  authyouragent:
    enabled: true
    command: authyouragent-mcp
    env:
      AYA_AGENT_ID: "ag_xxxxx"
      AYA_KEY_FILE: "/path/to/agent-key.pem"
      AYA_VAULT_URL: "http://127.0.0.1:7801"
      AYA_VAULT_TOKEN_FILE: "~/.authyouragent/vault/token"

Claude Desktop / Cursor

Claude Desktop: claude_desktop_config.json. Cursor: ~/.cursor/mcp.json.

{
  "mcpServers": {
    "authyouragent": {
      "command": "authyouragent-mcp",
      "env": {
        "AYA_AGENT_ID": "ag_xxxxx",
        "AYA_KEY_FILE": "/path/to/agent-key.pem",
        "AYA_VAULT_URL": "http://127.0.0.1:7801",
        "AYA_VAULT_TOKEN_FILE": "~/.authyouragent/vault/token"
      }
    }
  }
}

Agent

python -m authyouragent keygen --name "Job-search assistant"

Register the printed jwk in the app (Agents -> Add an agent). Keep privkey_pem on the agent's machine.

from authyouragent import AgentClient

agent = AgentClient(base_url="https://authyouragent.com", agent_id="ag_…",
                    privkey_pem=open("agent-key.pem").read())
agent.ensure_grant("jobs.example.com", scopes=["list", "apply"])   # phone approval
r = agent.request("GET", "https://jobs.example.com/api/jobs")
r = agent.request("POST", "https://jobs.example.com/api/jobs/j1/apply", stepup_action="apply")

Site

from authyouragent import SiteVerifier, AuthError

verifier = SiteVerifier("https://authyouragent.com", expected_audience="jobs.example.com",
                        public_base_url="https://jobs.example.com")

@app.get("/api/jobs")
def jobs(request: Request):
    try:
        auth = verifier.verify(request)
    except AuthError as e:
        raise HTTPException(401, {"error": e.error})
    ...

See examples/ for a complete agent and a complete FastAPI site.

Licence

MIT

Metadata

Release files for authyouragent 0.3.8

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for authyouragent 0.3.8
File Size Uploaded
authyouragent-0.3.8.tar.gz 37.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for authyouragent 0.3.8
File Interpreter ABI Platform
authyouragent-0.3.8-py3-none-any.whl Python 3 none any Details

Total release size: 76.1 kB

Release files / authyouragent-0.3.8.tar.gz

Download URL authyouragent-0.3.8.tar.gz
Size 37.4 kB
Tags Source
SHA-256 checksum
How to use checksums
652359eca7258b17aa80dfda80c29a89afdb7a062cc7d4967e400f2f25e5c40e
BLAKE2b-256 checksum
How to use checksums
5100e38c3c2cc2b96ee2539e6323f8cf19b4e06d3897f1314216cf1ba933a3fa
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / authyouragent-0.3.8-py3-none-any.whl

Download URL authyouragent-0.3.8-py3-none-any.whl
Size 38.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
483e23b9271b4222cc6cb5de5d491c8d8daece65f28289c0064e5c9530c5440e
BLAKE2b-256 checksum
How to use checksums
64069d4fecdb5ff9b51389d397403102475694e532b65d4623672dcd8038ad57
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.3.8 This release

2 release files

0.3.7

2 release files

0.3.6

2 release files

0.3.5

2 release files

0.3.4

2 release files

0.3.3

2 release files

0.3.2

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page