AI agents are getting powerful. They send emails, move money, deploy code. OpenApe makes sure a human approves what matters — without slowing anything down.
"If lobsters 🦞 take over the world,
we need apes 🦍 for security."
— The OpenApe Manifesto
Today's AI agents can book flights, sign contracts, and push to production. But there's no standardized way to verify who authorized what. No audit trail. No approval flow. No kill switch.
OpenApe uses DDISA — a DNS-based protocol that turns your domain into an identity provider. No OAuth servers to maintain. No SDKs to integrate. Just a TXT record and you're live.
Identity discovery in one DNS lookup
phofmann@company.at
_ddisa.company.at TXT
idp=https://id.company.at
✓ Verified
Like MX records for email, but for agent identity. Works with any domain you own.
Your AI agent needs to perform a privileged action — send money, access data, deploy code.
The action hits a permission boundary. OpenApe checks: does this agent have a valid grant for this scope?
If no grant exists, the human owner receives an approval request — via Telegram, email, or any channel.
Grant once, for a time window, or always for this scope. Scoped, signed, auditable.
The action executes. Who approved it, when, and for what — all recorded. Dual accountability: agent owner + approver.
OpenApe doesn't slow your agents down — it makes them trustworthy.
Grants are tied to specific actions and scopes. An agent approved for "read calendar" can't suddenly "send emails".
No central registry. Your domain is your identity anchor. Like email's MX records, but for agent auth.
Approval requests arrive on Telegram, email, or any messaging surface. Tap to approve. Done.
Every grant is cryptographically signed with nonce and expiry. Can't be reused, forged, or replayed.
Dual accountability: who owns the agent AND who approved the action. Compliance-ready from day one.
Add a DNS TXT record. Deploy the IdP. That's it. No OAuth complexity, no vendor lock-in.
Some actions need a human every time. Others earn standing trust. OpenApe lets you decide.
Approve this specific action, this one time. Grant is consumed immediately. For high-risk operations like transfers or deployments.
Grant access for a time window — 15 minutes, 1 hour, 1 day. Perfect for work sessions or batch operations.
This agent can always perform this action. Revocable anytime. For routine, low-risk operations you trust completely.
OpenApe and the DDISA protocol are fully open source. Review every line. Fork it. Extend it. The security layer for AI agents shouldn't be a black box.
Add a DNS record. Deploy the IdP. Your agents are accountable in minutes.