Step-up auth & governance for agentic processes

Every agent action,
human-signed.

AI agents are entering systems built for people — and every privileged action ends at a wall designed for humans. SecondSign freezes the agent at that boundary. A human signs. The action completes — attested, audited, provable.

secondsign — live step-up
agent › exec_authenticated_action( "transfer/payroll.run" )
⟐ AUTH_STEP_UP_REQUIRED ticket: tkt_8f92a40b12 ttl: 300s
agent paused — no secrets, no standing credentials
human › secondsign approve tkt_8f92a40b12 ✓ passkey verified
agent › resume_stepup_session( tkt_8f92a40b12 )
✓ COMPLETED elevated token: 300s acr: mfa
✓ attestation signed by human:you@corp.com → audit log
The protocol

Don't automate authentication.
Route it.

SecondSign turns 2FA and step-up walls from automation blockers into governance primitives. Five states, one invariant: nothing privileged happens without a human signature.

01

Detect

Agent reaches a privileged action. Policy demands step-up.

02

Freeze

Execution state pauses. Ticket issued. No retries, no guessing.

03

Sign

Human verifies out-of-band — passkey, TOTP, push. Seconds of effort.

04

Resume

Short-lived elevated token. Expired in five minutes.

05

Attest

Signed record: who approved, what, when. Exportable. Courtroom-grade.

Why now

The identity layer for the
agentic decade.

45:1
Non-human identities already outnumber humans — and agents multiply it
$3–5B
NHI governance market by 2028–2030, compounding 25–35%
300s
Lifetime of an elevated token. Standing credentials: zero
100%
Of privileged actions traceable to a signed human approval
Principles

Built like it matters.
Because it does.

◈

The agent holds nothing

No 2FA seeds. No standing credentials. No long-lived tokens. Secret material never enters prompts, logs, or screenshots — by architecture, not policy.

▣

Everything is attested

Every privileged action resolves to a cryptographically signed human approval. SOC 2, EU AI Act, DORA — the audit trail is the product.

⬡

Runs where you run

MCP-native: OpenCode, Claude Desktop, LangChain, your harness. Local-first and air-gap compatible. Enterprise control plane when you're ready.

Standards, not hacks

Speaks the language your
IAM team already trusts.

SecondSign implements the identity stack your security team reviews today — no proprietary black boxes, no scraping, no bypassing.

OIDC Step-Up · RFC 9470 PAR · RFC 9126 RAR · RFC 9396 Token Exchange · RFC 8693 MCP · JSON-RPC 2.0 FIDO2 / WebAuthn
npm install @secondsign/mcp-harness copy
Node ≥ 20 · zero lifecycle scripts · zero telemetry · air-gap install supported
Lawful by construction

It strengthens authentication.
Never circumvents it.

SecondSign operates exclusively on systems you own, operate, or are contractually authorized to automate. Legacy session replay is disabled by default and gated behind explicit, auditable configuration. Targets you don't control are out of scope — in writing, by design.

Put a human on every privileged line.
Design-partner pilots are open — one agent identity, one workflow, 90 days, credited to your annual contract.
Talk to us