Research preview · v0.2

Nothing moves
without your nod.

Nodd is the authorization layer for AI agents. Every action across your apps, data, and wallets is allowed, blocked, or waits for your nod — before it happens.

decision#0001
agent research-agent
action drive.read
presence active
requestpolicy ALLOW

The problem

AI permissions were designed for people, not autonomous agents. OAuth can connect a tool. It cannot decide whether an agent should read a confidential file at midnight, share customer data, or execute a high-value trade while you are away.

Authentication proves identity. Nodd controls behavior. The agent decides what to request; an independent layer decides whether that request may proceed.

How it works

One decision before every action

  1. 01

    Connect

    Link an app, wallet, data source, or agent. Provider credentials stay with Nodd — never with the agent.

  2. 02

    Define

    Describe what is allowed, limited, or forbidden — by resource, operation, amount, time, and presence.

  3. 03

    Evaluate

    Your agent sends the intended action to Nodd before execution. One call, every time.

  4. 04

    Decide

    Allow, block, or require human approval. Silence or absence never counts as consent.

  5. 05

    Record

    Request, decision, and execution outcome are written to an audit trail — as separate events.

By design

An agent's ability to take an action is not permission to take it. Everything in Nodd follows from that rule.

Read the paper

0call

Between your agent and every protected action.

0outcomes

Allow, block, or require approval. Nothing in between.

0unrestricted

Credentials handed to an agent. Keys stay in the executor.

Policy simulation

Simulated decisions · not live traffic

Use cases

Everywhere
agents act

Wherever an agent can read, write, send, deploy, or sign, Nodd puts one decision between intent and execution.

The gateway

Policy at the
point of action

Requests are authenticated, checked against your rules, and executed through controlled integrations — only when authorized.

GATEWAY MODE
REQUEST research-agent drive.read Nodd authenticate validate POLICY scope: 1 file op: read presence: active ALLOW executor runs APPROVAL passkey · revalidate BLOCK fail closed PROVIDER Drive audit trail · every decision

        
decision ALLOW

Read of one selected file, user active. Within scope.

Continuous
authorization

Permissions are evaluated when an action happens — not only when an account connects.

Presence-aware
protection

Different rules when you are active, away, offline, or locked. Being away never widens access.

Human
approval

Sensitive files, transfers, and destructive actions pause for passkey confirmation of that exact action.

Emergency
lock

Suspend every agent session and connected service from one control — with revocation behavior you can inspect.

Onchain control · Robinhood Chain

Policy-controlled
finance

Agents can move quickly without receiving unlimited control. Set trade limits, approved tokens and protocols, daily loss limits, slippage, schedules, and approval thresholds.

Policy treasury-agent
trade_limit
$500
slippage_max
1.0%
daily_loss_max
2.0%
assets
USDC · ETH · HOOD
schedule
09:00–17:00
presence
away
Requested action wallet.swap
$0vs $500 limit
pairUSDC → ETH
over limit+70%
Decision #8f21

APPROVAL_
REQUIRED

04:59

Waiting for your nod — a passkey confirmation. If nobody approves, the request expires. Silence is not consent.

Research trackWallet authorization is a planned extension. We will not claim live wallet protection until every signing path is identified and tested.

Request early access

0 unrestricted credentials

Security

Deny by default

If authorization can't be established, protected execution stops. An outage should never become a permission bypass.

Short-lived credentials

Agent credentials are scoped, rotated, and expire. A display name is never an identity.

Passkey approvals

Approvals bind to the exact action. Change the amount or recipient and the approval no longer counts.

Signed webhooks

Every decision event you receive is signed, so your systems can verify where it came from.

Session revocation

Revoke an agent in one step, with documented handling for queued requests and in-flight executions.

Decision logs

What was requested, what was decided, and what executed — recorded without copying your content.

Policy simulation

Replay real and hostile requests against a policy before it goes live — including the ones that should fail.

Developers

Ask before your
agent acts

A simple decision API sits between your agent and its tools. Connect any model, application, or smart account.

Send the intended action before you execute it. Nodd returns one of three decisions — and only allow means go.

Locate the action · check scope · check presence · decide.

When a policy requires a human, the request waits. The approval is bound to its parameters and expires; authority is checked again before execution.

Parameter-bound · single use · revalidated.

Pull an agent's authority in one call. Queued and pending requests are rejected; cached decisions are invalidated.

Revocation is not deletion — each is documented.

Query what your agents asked for and what happened. Requests, decisions, and outcomes are separate records — because an allowed action can still fail.

Structured metadata · explicit retention.

agent.tsAPI preview
const decision = await nodd.evaluate({
  agent:    "treasury-agent",
  action:   "wallet.swap",
  value:    850,
  presence: "away",
});

if (decision.outcome === "allow") await execute();
// → { outcome: "approval_required", id: "dec_8f21" }
// Wait for the user's passkey on this exact action
const result = await nodd.approvals.wait("dec_8f21", {
  timeout: "5m",
});

// Parameters changed? The approval no longer applies.
// → { status: "approved", revalidated: true }
// One control to stop an agent
await nodd.agents.revoke("treasury-agent", {
  reason: "suspicious activity",
  pending: "reject",
});

// → { revoked: true, rejected_pending: 3 }
const log = await nodd.audit.list({
  agent: "treasury-agent",
  since: "24h",
});

// → [{ requested, decided: "block", executed: false,
//      rule: "trade_limit", at: "2026-09-30T14:02Z" }, …]

Integrations

Nodd lives on the execution path — between your agents and the tools they touch, from Gmail and Drive to GitHub, databases, and smart accounts.

  • Google Drivedemo
  • Gmailplanned
  • Slackplanned
  • GitHubplanned
  • Postgresplanned
  • Notionplanned
  • Smart accountsresearch
  • Your APIconnector SDK

Principles

Rules we build by

A control that appears in an interface is not the same as a control that is enforced. These are the lines we hold.

A

Capability is not authority

Principle 01

What software can attempt, what you intend, and what it's permitted to execute are three different things. We keep them separate.

S

Silence is not consent

Principle 02

Being offline never widens an agent's permissions. Actions that need you wait — or expire.

E

Approvals are exact

Principle 03

You approve one action. If the resource, recipient, or amount changes, it's a new request.

F

Fail closed

Principle 04

When authorization can't be established, protected execution stops. Availability is traded for safety — on purpose.

FAQ

Common
questions

What Nodd does, what it doesn't, and where we are today. Something missing?

Ask on Telegram
What is Nodd?

An authorization gateway for AI agents. Your agent asks before it acts; Nodd checks the request against your policy and returns allow, block, or require approval. Authorized actions run through controlled integrations, so the agent never holds your provider credentials.

Does it replace OAuth?

No. OAuth connects a tool and proves identity. Nodd decides, per action, whether a connected agent should be allowed to do a specific thing right now. The two work together.

What does "presence-aware" mean?

Policies can depend on whether you are active, away, offline, or locked. Actions already permitted can proceed; actions that need you wait or expire. Being away never expands what an agent can do.

Where does Nodd not fit?

It is not device-wide security. It can't govern a separate connection an agent already holds, un-send information an agent already received, or judge whether an allowed action is a good idea. It protects the requests that pass through it.

What happens if Nodd is unavailable?

Protected actions fail closed: if a decision can't be established, execution stops. That costs availability during an outage, but prevents an outage from becoming a bypass.

What if an agent credential is stolen?

Agent credentials are scoped, short-lived, and revocable, which limits what a stolen one can reach. Within its valid scope it can still act — which is why least privilege matters.

What data does Nodd see?

Depending on the integration: account identifiers, agent credentials, policy settings, request metadata, and content returned by an app. Logs keep structured decision data, not full copies of your documents, with explicit retention periods.

Has Nodd been audited?

Not yet. No completed independent audit is claimed. When one happens, we'll publish its scope, version, findings, and remediation status.

Can Nodd protect my wallet today?

No. Wallet authorization is a research track. Before claiming it, we need to identify every signing path, enforce limits where signing actually happens, and test how a transaction might bypass them.

Which onchain controls are planned?

Restricted destinations, spending and trade limits, approved assets and protocols, slippage bounds, schedules, transaction-specific approvals, and narrowly scoped session permissions.

Why Robinhood Chain?

It's where our onchain work starts. The core gateway itself is chain-agnostic and doesn't require a blockchain at all.

Is there a $NODD token?

Any future token must have a role justified on its own. No allocation, staking program, governance right, fee-sharing, or return expectation is defined. Nothing on this site is an investment solicitation.

Do I need a token to use Nodd?

No. The app-access gateway works without a token or a blockchain. Owning a token will never grant access to anyone else's resources.

Early access

Let agents work.
Keep the final nod.

Continuous consent, programmable policies, and human control for the agentic economy. Join the builders' list.