# Spoofed: Only someone *real* can tell your agent to act.

> Prompt injections, cloned voices and lookalike agents all fake the same thing: authority. Spoofed makes every high-risk action carry a signature from the person who asked for it, so a fooled agent still can't move money, send mail or delete data.

## Anything that can be generated can be *spoofed*.

Faces, voices, writing style, agent names, tool descriptions: models produce all of them on demand, and detectors lose ground with every new generator. A signature is different. No model, however good, can produce one without the key.

- **Prompt injection.** Text in an email, a web page or a tool result claims to speak for you, and your agent believes it.
- **Cloned voices.** A few seconds of audio is enough to call finance as the CFO and ask for a wire.
- **Lookalike agents and tools.** A server named like a trusted tool, or an agent card copied from a real one, collects what you hand it.
- **Synthetic people.** Generated faces and documents pass checks that were built for a world without generators.

## How it works

### Sign

Every agent gets a key, bound to the person or team that runs it. Every request it sends is signed with HTTP Message Signatures (RFC 9421), so the chain from person to agent to request can be checked.

### Gate

High-risk tools run only with a mandate: a short-lived signature over the exact call. For the riskiest, a real person approves with a passkey, and what they see is what they sign.

### Verify

Any service can check a mandate with public keys, offline. Keys stay on your devices and servers, so not even Spoofed can sign for you.

Some channels can't carry a signature yet: phone calls, video meetings, a scanned ID. There, Spoofed scores media for signs of generation and reports it as a signal, never as the guarantee.

## Who it protects

- **Agents.** A fooled agent can't complete a gated action, because injected text can't produce a signature.
- **People.** A clone of your face or voice can't approve anything. Only your passkey can, on your device.
- **Services.** Know which agent is calling, for whom, and with what authority, before you let it act.
- **Robots, next.** Machines that take commands in the physical world need the same proof. Same mandates, later.

## Quickstart (preview: the API is in early access)

### TypeScript

```ts
import { Spoofed } from "@spoofed/sdk";

const spoofed = new Spoofed({ apiKey: process.env.SPOOFED_API_KEY });

// The tool now runs only with a mandate for this exact call.
export const transfer = spoofed.gate("payments.transfer", {
  approval: "passkey", // a real person signs the amount and payee
  run: ({ amount, to }) => bank.transfer({ amount, to }),
});

// On the receiving side: check it offline, with public keys.
const mandate = await spoofed.verify(request);
if (!mandate.valid) return deny(mandate.reason);
```

### Python

```python
from spoofed import Spoofed

spoofed = Spoofed()  # reads SPOOFED_API_KEY

@spoofed.gate("payments.transfer", approval="passkey")
def transfer(amount: int, to: str):
    return bank.transfer(amount=amount, to=to)

# On the receiving side
mandate = spoofed.verify(request)
if not mandate.valid:
    deny(mandate.reason)
```

### curl

```bash
curl https://api.spoofed.ai/v1/mandates \
  -H "Authorization: Bearer $SPOOFED_API_KEY" \
  -d action=payments.transfer \
  -d params[amount]=48000 \
  -d params[to]=acct_4471 \
  -d approver=dana@acme.com
```

### MCP

```json
// Any MCP client: Claude, Cursor, your own agent
{
  "mcpServers": {
    "spoofed": {
      "url": "https://mcp.spoofed.ai",
      "headers": { "Authorization": "Bearer ${SPOOFED_API_KEY}" }
    }
  }
}

// Gated tools answer with an approval request the person
// signs with a passkey. Tools: spoofed_request_mandate,
// spoofed_verify, spoofed_check_agent
```

## Example response

```json
{
  "decision": "deny",
  "reason": "no_mandate",
  "action": "payments.transfer",
  "params": {
    "amount": 48000,
    "to": "acct_••4471"
  },
  "agent": {
    "id": "billing-agent@acme",
    "signature": "valid"
  },
  "mandate": null,
  "next": "request_approval",
  "request_id": "req_01JA7XK2Q9"
}
```

## Built for agents

- [llms.txt](https://spoofed.ai/llms.txt): A short map of the product and docs, for any model.
- [llms-full.txt](https://spoofed.ai/llms-full.txt): The whole site as one markdown file. Drop it in context.
- [index.md](https://spoofed.ai/index.md): This page as plain markdown. No scripts, no layout.
- MCP server (early access): Mandates and verification as tools your agent can call.

## Principles

- **Proof over prediction.** Guarantees come from signatures. Detection scores are labeled as signals, and never decide on their own.
- **Keys stay with you.** Private keys live on your devices and servers. Verification needs only public keys, so it works without us.
- **What you see is what you sign.** An approval shows the exact action and is bound to its parameters. Change the amount or the payee, and the signature fails.
- **Honest about limits.** A compromised device can still sign, and ungated tools stay reachable. We show which actions are protected and which aren't.

## Contact

Request access: hello@spoofed.ai
