Learn More

Open Source HUMAN Security Alternatives

A curated collection of the 1 best open source alternatives to HUMAN Security.

The best open source alternative to HUMAN Security is OneHuman. If that doesn't suit you, we've compiled a ranked list of other open source HUMAN Security alternatives to help you find a suitable replacement.

HUMAN Security alternatives are mainly CAPTCHA & Bot Protection Tools. Browse these if you want a narrower list of alternatives or looking for a specific functionality of HUMAN Security.

Piotr Kulpinski's profile

Written by Piotr Kulpinski

Detects AI agents acting as customers, masks private fields, holds risky actions for a passkey, and signs every decision on your own server.

Screenshot of OneHuman website

When a customer lets Claude or ChatGPT log into your app using their own credentials, your app can't tell the difference between the person and the agent. OneHuman sits inside your product, after login, and decides what each agent can see and do.

It's built for B2B SaaS, fintech, and banks where customers are already sending AI agents into their accounts. You don't control which agent they use, but you do control your app.

Three things happen before the agent's first click:

  • Detection. OneHuman spots the agent the moment it attaches to the session, before it interacts with anything.
  • Masking. Emails, phone numbers, and balances turn to dots. The rest of the app keeps working normally.
  • Passkey gates. Exports, payments, and other risky actions pause and ask the account owner to confirm with Touch ID or a passkey.

Every decision, allow or block, is signed on your server. That gives you a verifiable audit trail, not just a log.

Without it, an agent can read every field on screen, export all contacts in one click, and leave no proof of who approved it. Bot protection and WAFs don't help here because the agent arrives with a valid login, not as an unknown visitor.

The SDK and middleware are Apache-2.0; the engine is source-available under BUSL-1.1, which permits production use. Your servers, your database, nothing leaves them. A watch-only mode lets you run it for 30 days without blocking anything, so you can see which agents are already inside your product and what they're touching before you enforce any rules.

Rules are written in JSON, one line per route to protect. A verify command checks your setup against four conditions before you go live.

In their own tests, OneHuman caught 4 of 4 AI agents and misread 2 of 397 human clicks as automated. When it's uncertain, it returns "unknown" rather than flagging a real user, and the account owner can always confirm with a passkey.

Share: