spoofedearly access

Only someone real can tell your agent to act.

Prompt injections, cloned voices and lookalike agents all fake the same thing: authority. Spoofed makes every high-risk action carry a signature from the person who asked for it, so a fooled agent still can't move money, send mail or delete data.

curl https://spoofed.ai/llms.txt
Request access
Built to be read by agents too
Same request on top. Only one can prove who sent it.

Anything that can be generated can be spoofed.

Faces, voices, writing style, agent names, tool descriptions: models produce all of them on demand, and detectors lose ground with every new generator. A signature is different. No model, however good, can produce one without the key.

Prompt injection
Text in an email, a web page or a tool result claims to speak for you, and your agent believes it.
Cloned voices
A few seconds of audio is enough to call finance as the CFO and ask for a wire.
Lookalike agents and tools
A server named like a trusted tool, or an agent card copied from a real one, collects what you hand it.
Synthetic people
Generated faces and documents pass checks that were built for a world without generators.

How it works3 of 3

Sign

Every agent gets a key, bound to the person or team that runs it. Every request it sends is signed with HTTP Message Signatures (RFC 9421), so the chain from person to agent to request can be checked.

Gate

High-risk tools run only with a mandate: a short-lived signature over the exact call. For the riskiest, a real person approves with a passkey, and what they see is what they sign.

Verify

Any service can check a mandate with public keys, offline. Keys stay on your devices and servers, so not even Spoofed can sign for you.

Some channels can't carry a signature yet: phone calls, video meetings, a scanned ID. There, Spoofed scores media for signs of generation and reports it as a signal, never as the guarantee.

Gate what can hurt. Leave the rest open.

docs.searchemail.sendpayments.transfercalendar.readrecords.deletedeploy.prod
Six tools, four gated. An injected instruction reaches the gate, not the money.

Who it protects

Agents
A fooled agent can't complete a gated action, because injected text can't produce a signature.
People
A clone of your face or voice can't approve anything. Only your passkey can, on your device.
Services
Know which agent is calling, for whom, and with what authority, before you let it act.
Robots, next
Machines that take commands in the physical world need the same proof. Same mandates, later.

Quickstartpreview · in early access

tools/transfer.ts
import { Spoofed } from "@spoofed/sdk";

const spoofed = new Spoofed({ apiKey: process.env.SPOOFED_API_KEY });

// The tool now runs only with a mandate for this exact call.
export const transfer = spoofed.gate("payments.transfer", {
  approval: "passkey", // a real person signs the amount and payee
  run: ({ amount, to }) => bank.transfer({ amount, to }),
});

// On the receiving side: check it offline, with public keys.
const mandate = await spoofed.verify(request);
if (!mandate.valid) return deny(mandate.reason);

Without a mandate, the call is refused with a reason an agent can act on:

POST /v1/tools/payments.transfer · 403
{
  "decision": "deny",
  "reason": "no_mandate",
  "action": "payments.transfer",
  "params": {
    "amount": 48000,
    "to": "acct_••4471"
  },
  "agent": {
    "id": "billing-agent@acme",
    "signature": "valid"
  },
  "mandate": null,
  "next": "request_approval",
  "request_id": "req_01JA7XK2Q9"
}

Principles

  • Proof over prediction.

    Guarantees come from signatures. Detection scores are labeled as signals, and never decide on their own.

  • Keys stay with you.

    Private keys live on your devices and servers. Verification needs only public keys, so it works without us.

  • What you see is what you sign.

    An approval shows the exact action and is bound to its parameters. Change the amount or the payee, and the signature fails.

  • Honest about limits.

    A compromised device can still sign, and ungated tools stay reachable. We show which actions are protected and which aren't.

Request accessearly access

We're working with teams whose agents touch money, mail, records or production. Tell us what yours can do, and we'll help you gate it.