QRAuth – Open-source QR verification with passkeys and device trust
Auth0 for physical authentication, but Auth0 and Clerk already solve web identity well.

WebAuthn beats CAPTCHA, paid checks, Worldcoin—biometrics never leave device.
Security-conscious users, developers integrating human verification, privacy advocates
Worldcoin · Civic
humanpass uses WebAuthn/passkeys to verify there's a real person behind the screen. You authenticate with your device's biometrics, get a temporary link (expires in 60 seconds), and share it anywhere. Whoever clicks it can see the verification is real.
Your biometrics never leave your device — the server only receives a cryptographic assertion. No signup, no email, no passwords. The only data stored is a random user ID and a public key.
Some technical details: - Built with Hono on Cloudflare Workers, D1 for storage, Workers KV for ephemeral links - Blocks known virtual/emulator authenticators by AAGUID - No analytics, no third-party scripts - Chrome extension for one-click verification - AGPL-3.0 licensed
Live at human-pass.org. Would appreciate feedback on the threat model and attack surface.
Auth0 for physical authentication, but Auth0 and Clerk already solve web identity well.
WebAuthn decorators add YubiKey approval gates to MCP tools, but alpha-stage and requires external cloud server.
Agents can now hire humans via API—solves real autonomous execution bottleneck.
First open standard for agent identity—solves a real security gap Cisco documented.
TLS for MCP agents with ECDSA passports and L0-L4 trust levels, zero dependencies.
Human-agent task marketplace before the agent economy is proven.