✍️Writing & Content22🎨Image Generation32🎬Video & Animation64🎵Audio & Music48💬Chatbots & Assistants35💻Coding & Development139📈Marketing & SEO52Productivity132🎯Design & UI/UX48📊Data & Analytics31📚Education & Research24💼Business & Finance49🏥Healthcare & Wellness18🔍Search & Knowledge13🤖AI Agent Infrastructure18🛡️AI Security & Testing2🧊3D & Spatial12🔎SEO Tools4🏡Real Estate4🗃️Data Extraction1🧠ADHD & Focus Tools9
Listed in AI Security & Testing with 2 other toolsPart of 891+ curated AI tools on AISO
Axtary logo

Axtary

Payload-bound authorization for AI agents — human approval is cryptographically tied to the exact action, so a changed payload is denied

0
freemiumLocal $0, no account required: published CLI, SDK, local proxy, and MCP wrapper; local policy and exact-payload checks; local action ledger and verification tools; credential-free playground. Founding Team $499/month after a 30-day pilot: hosted exact-payload approvals, team dashboard, verified ledger sync, guided setup for one workflow, direct support. Enterprise custom scoped agreement. There is no self-serve checkout — pilot scope, support, and success criteria are agreed in writing first.View full pricing →

Visit Axtary

https://axtary.com

About Axtary

Axtary is content authorization for AI agents: it checks the exact diff, message, query, or tool payload before a connector executes, rather than granting an agent blanket permission to use a tool. Routine actions follow policy and pass automatically; higher-risk actions require human approval of that specific payload. The mechanism is payload binding. When a human approves an action, the approval is cryptographically bound to a hash of the normalized payload — not to a summary of it, and not to a classification of the message. If anything in the payload changes after approval, adapter-side verification recomputes the hash, sees the mismatch, and rejects the call before the provider is ever contacted. Their own demo runs this deliberately: same actor, same task, same tool, same target, but the Slack message body swapped from a benign PR notice to one exfiltrating staging credentials — the recomputed hash no longer matches the approved one, and the call is denied before slack.chat.postMessage executes, with both hashes recorded in the ledger. The practical consequence is that if an agent is mistaken or compromised, its authority is limited to the exact action a human actually reviewed. Every attempt, approved or denied, is recorded. The ActionPass artifact works across SDKs, proxies, and MCP wrappers, with constraint examples covering GitHub pull requests scoped by branch, file, path and tests, Slack messages scoped by channel and recipient, Linear issue updates scoped by project and field, AWS and GCP reads scoped by project, bucket, region, and prefix, and MCP tool calls bound to a server identity. Everything is reproducible locally with a tamper flag.

Key Features

Exact-payload inspection before a connector executes
Approval bound to a canonical payload hash, not a summary or classification
Adapter-side verification that rejects any post-approval payload change
ActionPass artifact usable across SDKs, proxies, and MCP wrappers
Fine-grained constraints for GitHub, Slack, Linear, AWS, GCP, and MCP tool calls
Immutable ledger recording every attempt with both hashes on a mismatch
Free local CLI, SDK, proxy, and MCP wrapper with no account
Locally reproducible tamper demos

Axtary Pros & Cons

Pros

  • +Payload-hash binding is a real defense against post-approval tampering
  • +Full local tier runs free with no account or credentials
  • +Tamper demos are reproducible on your own machine, not just marketing claims
  • +Constraints are specific per provider rather than generic tool allowlists

⚠️ Cons

  • No self-serve checkout — the paid tier requires a written pilot agreement
  • $499/month covers only one agreed non-production workflow to start
  • Early access, so integration coverage is still narrow
  • Adds an approval step that will slow high-frequency agent workflows

Who Is Axtary Best For?

👤Teams giving agents write access to GitHub, Slack, or cloud resources
👤Security engineers who need evidence of what an agent was actually authorized to do
👤Anyone worried about prompt injection changing an action after a human approved it

Tags

agent securityauthorizationmcphuman in the loopaudit ledgerprompt injectionapproval
🏷️

Is this your tool?

Claim your listing to get a Featured badge, edit your description, and stand out from competitors. All plans include a permanent dofollow backlink to your site.

Claim Now →

ChatGPT already recommends Axtary. Does it recommend yours?

If you're building in AI Security & Testing, run a free AI-visibility scan on your own product — we ask ChatGPT across 5 prompt angles and score how often you get named. ~30 seconds, no signup, no card.

Stay updated on AI Security & Testing tools — join our weekly newsletter

One concise email with fresh launches, trending picks, and featured standouts.

Agent connectivity: not yet verified