My agent is blocked on a decision only my person can make
Your agent is about to deploy, send or delete, and only its person can say yes. It asks once, keeps working or stops, and gets the answer back when they tap it.
Use it when progress is blocked by a decision only a person can make and they aren't in the session: a background job, a coding agent working overnight, a workflow. Don't use it for notifications, marketing, or getting round a no. If the person is right there in the chat, just ask them.
1. Check you can ask
curl https://wayza.com/wayza/v0/asks/ready -H "Authorization: Bearer $WAYZA_KEY"
The answer's state is exactly one of these:
ready: ask away.needs_person_setup: your person has to do one thing first. Give themsetup_linkyourself, where you already talk to them. Wayza never sends it to anyone.needs_grant: you asked about someone other than your own person. This version reaches only your own connected person (capability: own_person_only).blocked:whysays what stops it.
2. Ask about one action
curl https://wayza.com/wayza/v0/asks -H "Authorization: Bearer $WAYZA_KEY" -H "Content-Type: application/json" -d '{
"question": "Deploy version 3 to production tonight?",
"consequence": "The service restarts and may be unavailable for about eight minutes.",
"action": { "type": "deploy", "environment": "production", "artifact": "v3.0.1" },
"request_id": "deploy-v3.0.1",
"expires_at": "2026-10-09T18:00:00Z"
}'
You get an id at once, with status: "pending". Carry on with other work, or stop.
| action.type | Fields |
|---|---|
deploy | environment, artifact |
send | audience, message_sha256 (hex SHA-256 of the exact message), count |
delete | target, count, ids_sha256 (hex SHA-256 of the sorted ids, one per line) |
Spend approvals aren't available yet. Every field is checked, and the person sees the question, the consequence and exactly what proceed allows. Asking again with the same request_id returns the same ask; the same request_id for a different action is refused.
3. Get the answer
Over MCP, subscribe to the ask.answered event; or poll:
curl "https://wayza.com/wayza/v0/asks/ID?wait=30" -H "Authorization: Bearer $WAYZA_KEY"
status is pending, answered, expired or cancelled. Once answered, answer is proceed or cancel. Only proceed means go: expired, cancelled and pending never do. Call an ask off with DELETE https://wayza.com/wayza/v0/approvals/ID.
Only your person's own tap answers. No AI can answer it for them, even one they allowed to approve things.
4. Check it before you act
The answered result carries signed_answer, signed with the home key in /.well-known/wayza.json. Its request is a SHA-256 fingerprint of what was asked, and that includes the action. So check that the action you are about to run is the one in the result, field for field: the same answer can't stand for another environment, artifact, audience, message or record set. The signature means Wayza recorded this person giving this answer to this exact question at this time. It does not say the answer is wise or true.
Make it a rule
Asking once is a demo; asking every time is a safeguard. Put the rule in your agent's own settings, not in what the model remembers: "ask through Wayza before every production deploy", "before any send to more than 100 people", "before deleting more than 10 records". Phone approvals already does this for Claude Code and Codex.
Never put secrets in an ask
Asks are stored on Wayza as plain text: encrypted in transit, not end to end. Anything that looks like a credential, token or private key is refused before it is stored, logged or sent, and nothing is changed for you. Ask again with a summary that leaves the secret out.
Over MCP
The same three tools: ask_person_ready, ask_person and get_ask. See Connect over MCP.