frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: CoSig – WebAuthn co-signing for MCP tool calls

https://github.com/skyforest/cosig
3•_skyforest•1h ago
I built CoSig because I kept running into the same problem while working with MCP servers: there's no standard way to require cryptographic proof that a human actually authorized what your AI agent just did (or is about to do).

This matters more than it sounds. Your compliance team will eventually ask "who approved the deletion of those customer records?" Your auditors will want to know who signed off on that production deploy. Your incident response playbook assumes a human made a decision somewhere. With vanilla MCP, the answer is "the AI did it because the AI was told it could"... which is not an answer that satisfies a SOX auditor, a HIPAA compliance review, or your own postmortem.

The solution I landed on: WebAuthn co-signing. You put @require_approval() on the sensitive FastMCP tools. When an agent tries to call one, execution blocks, a URL gets surfaced, and the human approves by tapping a hardware security key (YubiKey, etc.) or their device's built-in biometrics (Touch ID, Windows Hello). The signature is tied to that specific request, with a counter that prevents replay and gets stored in an append-only audit log. Then the tool runs.

It's two repos: a lightweight Python SDK (pip install cosig) and CoSig Cloud, a self-hosted Next.js + FastAPI backend you run on your own infrastructure. Nothing phones home. Your audit logs stay yours.

This is alpha, v0.2.0a1. APIs will change and a security review is recommended before production use. But the core flow works and there's a demo linked below showing it end-to-end.

I'd especially like to hear from people building MCP servers for regulated industries, or anyone who's already thought through the "who authorized this AI action" problem and landed somewhere different.

SDK: https://github.com/skyforest/cosig Backend: https://github.com/skyforest/cosig-cloud Demo: https://www.youtube.com/watch?v=7AeMJ3ViV5E

Agent Pro – Automate your desktop from your phone (no setup)

1•ypadamat•15s ago•0 comments

The Longing (1999)

https://www.cluetrain.com/book/longing.html
1•herbertl•52s ago•0 comments

Fed Pricing Reveals Market Expectations About the AI Adoption Pace

https://www.apolloacademy.com/fed-pricing-reveals-market-expectations-about-the-ai-adoption-pace/
1•akyuu•1m ago•0 comments

Show HN: IronCurtain: A secure* runtime for AI agent loops

https://github.com/provos/ironcurtain
1•nielsprovos•1m ago•1 comments

Coding with agents feels like a chess simul

https://tobeva.com/articles/chess-simul/
1•pbw•2m ago•0 comments

Every Electric will pay you to use a battery

https://www.greenjuice.wtf/every-electric/
1•DamonHD•2m ago•0 comments

Next-Token Predictor Is an AI's Job, Not Its Species

https://www.astralcodexten.com/p/next-token-predictor-is-an-ais-job
1•fulafel•3m ago•0 comments

Show HN: Stop Overpaying for Digital Services, Find Cheap App Subscription Price

https://www.findcheapsubs.com
1•tatefinn•4m ago•0 comments

Labor Secretary's Top Aides Forced Out

https://www.nytimes.com/2026/03/03/us/politics/labor-secretarys-top-aides-forced-out.html
2•duxup•5m ago•0 comments

Schema Diagrams: Bi-Di Visualization for the Schema Languages That Need It Most

https://www.chiply.dev/post-schema-diagrams
1•chiply•5m ago•0 comments

Compassdle

https://compassdle.blendaddict.com/
1•blendaddict•5m ago•0 comments

Cold Comforts

https://asenseofwander.substack.com/p/cold-comforts
1•herbertl•5m ago•0 comments

API for ring-lwe/module-lwe post-quantum

https://docs.open-encrypt.com
1•jacksongwalters•6m ago•1 comments

Show HN: Free SEO checker for structured data, meta tags and Core Web Vitals

https://seo.codequest.work/en
1•imai_director•7m ago•0 comments

DMX – A Cognitive Compiler for Enterprise Infrastructure [pdf]

https://devmatrix.dev/DMX_Breaking_The_Compiler_Wall.pdf
1•aeghysels•7m ago•1 comments

Thoughts on the Witness (2016)

https://fgiesen.wordpress.com/2016/01/30/thoughts-on-the-witness/
1•Tomte•8m ago•0 comments

Show HN: Demucs music stem separator rewritten in Rust – runs in the browser

https://github.com/nikhilunni/demucs-rs
1•nikhilunni•8m ago•0 comments

Show HN: Herniated disc made me build a back-safe kettlebell app

https://kbemom.com/
1•blacktarmac•8m ago•0 comments

Why Your BI Stack Knows More About Your Processes Than You Think

https://www.exasol.com/blog/process-mining-with-exasol/
3•exagolo•8m ago•0 comments

Are We Engineers?

https://www.hillelwayne.com/post/are-we-really-engineers/
1•alpaylan•11m ago•0 comments

I replaced grep-based code exploration with a knowledge graph – 10x less token

https://github.com/DeusData/codebase-memory-mcp
2•DeusData•11m ago•2 comments

How to protect your privacy at a protest

https://proton.me/blog/how-to-protect-privacy-at-protests
2•mikece•12m ago•0 comments

The digital grass isn't greener. It isn't grass

https://architectelevator.com/transformation/digital-grass-greener/
1•saikatsg•12m ago•0 comments

Show HN: I built a skill that lets your OpenClaw call you on the phone

https://clawr.ing
2•thisismyswamp•13m ago•1 comments

Book Notes: Anything you want (Derek sivers)

https://faizank.substack.com/p/anything-you-want-a-tiny-book-with
2•fazkan•14m ago•0 comments

Iran Is Only the Beginning

https://sphera.substack.com/p/iran-is-only-begging
2•KyleVlaros•14m ago•0 comments

Show HN: SEL Deploy – Tamper-evident deployment timeline (Ed25519, hash-chained)

1•chokriabouzid•16m ago•0 comments

Show HN: Scanning 277 AI agent skills for security issues

https://www.clawdefend.com/
1•pakmania•16m ago•1 comments

Why glibc is faster on some GitHub Actions Runners

https://codspeed.io/blog/unrelated-benchmark-regression
4•art049•16m ago•0 comments

Show HN: A text-to-motion-graphics engine

1•Vraj911•16m ago•0 comments