BotShield MCP Tools.
Five tools your agents call to put a person behind the actions that can’t be undone. None of the five can say yes. The proof carries the person’s intent, never the model’s guess. That is the shape of the surface, not a policy.
An agent connects with its key and gets five tools.
Bind to a human. Check the binding. Propose an action. Check the decision. Cancel. Anything a person approves comes back as a signed Proof of Resolution — verified by your code, not by the model, before anything executes.
How it works.
Invocation over MCP is model-mediated, so asking is cooperative. Enforcement is on your side: your executor verifies the Proof of Resolution and refuses without it. Five tools, in the order an agent calls them.
The proof.
An ES256 JWT with a kid in the header. Claims: iss · sub · aud (your agent id) · iat · exp · jti (your request id) · the verdict · the action. It attests that the person’s signed-in session answered this request; the passkey does not sign the action itself. Verify it against BotShield’s public JWKS in your own code before you execute. A model cannot verify a signature. Your executor can.
Who the agent can name.
Only an opaque id from the binding. The email field was removed from the tool surface on 9 August 2026: a deprecation note in a description does not stop a model, so the wrong call was made impossible rather than discouraged.
Auth and transport.
OAuth 2.0 client credentials at /token, discovery at /.well-known/oauth-authorization-server, the MCP endpoint at /mcp over Streamable HTTP. One key per agent, registered in the BotShield Console. Any MCP-capable harness, any model.
BotShield MCP Tools FAQ
Can the agent confirm on the person’s behalf?
What forces the agent to ask?
How is the human identified?
What is in the proof, and how do I verify it?
Can a proof be replayed?
How do verifiers learn a new signing key?
BotShield runs in your browser.
Sign in with Apple or Google, add a passkey, and approve what your agents ask — the same account the phone app will use.
Open app.botshield.ai →