Innkeeper

2FA + Credential Escrow for Agents

Context-aware agent authentication

Innkeeper lets your agents make authenticated and authorized requests without ever receiving a credential.

Claude Code · ~/acmeExample session

Send Maria the corrected August invoice.

I’ll ask Innkeeper to authorize the email first.

mail.send · waiting for your phone

The Innkeeper Mac app showing connected credentials and the local request log.
Your Mac routes the request.Your iPhone has the final say.
Innkeeper on iPhone showing the email recipient, subject, body, and approval with Face ID.

How it works

Your agents make blank Authorization header requests that you sign.

  1. Your Mac + your iPhone

    01

    Pair once.

    Scan the QR code the app shows you. Your phone makes a key in the Secure Enclave, and that key is the whole account. No password.

  2. Claude Code

    › payments.send

    Waiting for your phone

    02

    The agent asks.

    A flagged call stops, and your phone gets the request: the tool, the arguments as they were written, who is asking, and how long it has left.

  3. The exact request. Your signature.

    03

    You read it. Face ID.

    Approve signs the exact bytes you read, with a key that never leaves the enclave. Change one character and the signature no longer matches. Deny needs no face.

  4. Decision recorded

    Verdict
    Approved
    Credential
    Not shared
    04

    It goes back signed.

    The verdict returns to the agent as an ordinary tool result. Innkeeper attaches the credential, so the agent never holds it. Every call is written down.

Illustrative request flow · Pair once, approve each flagged call.Get Started

The apps

On your Mac.
On your iPhone.

Connect your agents and keep the log on your Mac. Store your credentials and review requests on your iPhone.

Mac · Home

Requests and decisions, in plain words.

A local record of who asked, what you decided, and when.

A crop of the Mac Home screen showing credential names and the request log.

Mac · MCP settings

Connect your agents.

A crop of the Mac MCP settings showing agent configuration controls.

Mac · Menu-bar detail

Close the window. Keep it running.

Detail crop of the menu-bar app showing a waiting request.

iPhone · Approvals

The context before your yes.

The iPhone app displaying an email request and its exact details before Face ID approval.

Read the action, who it’s for, and what it will send. Your credentials are stored on the phone.

Why

Context-aware agent authentication

(because MFA isn't enough)

MFA proves a person is at the keyboard, once, at login. An agent working for you is never at the keyboard. It acts as you all day, through credentials it was handed, and a factor checked at the door has nothing to say about any of it. What that needs is authentication that knows the context of every call: what the action is, who is asking, on whose behalf, and whether it looks like something you would do.

Innkeeper is the first piece of that. A call that spends a credential, sends as you, or cannot be taken back stops on your phone. The request names who is asking and why, your answer is a signature over the exact bytes, and the agent never holds the credential. Every answer is written down, who, what, when, and how long you took, and that record is the shape of how you work.

That is what we are building. This is the part that stops the call and asks you.

Good to know

Less guesswork.
More control.

Does my agent get my credentials?

No. It can make approved requests without receiving them.

Can I say no?

Yes. You can deny a request from your iPhone.

Can I see what happened?

Yes. Review activity on your Mac.

Pricing

Start with what you need.

Individual

One person. One Mac. One iPhone.

$0

Forever. No card.

Start free

Enterprise

Custom approval rules, integrations, and support.

Custom

Let’s scope it together.

Book a call

Human-approved 2FA for agents.

Pair a phone, point Innkeeper at your server, and let your agents make authorized requests, securely.