Raposa gives a named person on your team the approve button for your agents' high-stakes actions, and records every decision in a hash-chained audit trail you can export and verify.
n8n Verified Community Node
Your agent hits a high-stakes action — a payment, a deploy, a customer email. Instead of guessing, it calls Aval. The authorized person approves or rejects in one click. The decision lands in a hash-chained audit log: editing any past entry breaks verification from that point on.
The n8n-nodes-raposa package passed n8n's verification. On n8n Cloud an instance owner installs it once from the nodes panel (search “raposa”), then everyone in the instance can use it; on self-hosted, enable Verified Community Nodes first. The node gives any workflow the Raposa approval gate — create, get and wait (Ask and Wait). Current releases ship with npm provenance, which links the package to its source commit and CI build.
Every plan gets the whole product — API, approval console, approve from email, Telegram or Slack, named approver groups with N-of-M, reminders and escalation, signed webhooks, hash-chained audit and export, MCP server and SDKs. Plans differ in how many decisions you run per month and how fast we answer. No card to start, and the free tier does not expire.
The moment the payment clears you get an email with a one-time link that reveals your key and webhook secret — keys never travel in mail. Cancel any time from the receipt.
Availability, recovery and response times — with the numbers we measure. Early-access pricing — locked for 12 months for founding customers. Run over your limit and we tell you, we do not cut you off mid-month.
Because a pause is not evidence. When an SDK holds a tool call and waits, the record of that decision lives inside its runtime and disappears with it — no signature, nothing to hand an auditor, nothing that survives switching frameworks.
| Approval pause in an agent SDK | Raposa Aval | |
|---|---|---|
| Who approved, when, on what grounds | in your logs, if you wrote them | recorded, signed, exportable |
| Can the record be altered afterwards | yes, like any log line | hash-chained — any edit breaks verification |
| Works across frameworks | only inside that runtime | one HTTP call from anything |
| Notification to your systems | you build it | HMAC-signed webhook with retries |
| Data location and paperwork | wherever the vendor runs | servers and database in the EU (Germany), sub-processors listed, DPA ready to sign |
| Approving from a phone | open the runtime | signed email links, a Telegram card or a Slack message — opening never decides, the button does |
| Two signatures, named groups | you build it | approvers: ["finance"], required: 2 — every signer on record |
| Nobody answers | it waits, or dies | reminder once, escalation to a second person, then expiry — all audited |
| Wiring it in | — | MCP server for Claude Code / Cursor — local (uvx raposa-mcp) or remote over HTTP for Claude.ai, ChatGPT and Smithery — Python and TypeScript SDKs, n8n node |
Every line in the right column is a passing test, run daily and published with its name: raposa.group/compare.
If nobody will ever ask you to prove who approved a payout, you do not need us — use the SDK pause and keep your money.
Refunds, payouts, limit changes — executed by agents, approved by accountable humans, provable to auditors.
Agents ship code and run migrations. Production-touching steps wait for a human sign-off with full trace.
Outbound commitments, signatures, customer communications — nothing legally binding leaves without a person.
Require human approval before an AI agent makes a payment, refund or payout.
Human sign-off before an agent deploys, runs a migration or ships code.
Add human approval gates to any AI agent with one API call.
More: verifiable audit trail · compare LangChain, OpenAI Agents SDK, Temporal.
We use measurement cookies (Meta Pixel, Google Analytics) to see which campaigns bring visitors. Nothing loads until you agree. See our Cookie notice.