samples/claude-code/ in the repository
(veriqa.app/source), is MIT-licensed and is meant to be reworked for
your own needs. Its README is the setup guide.
Three demos
The costly run takes two approvers in turn — a developer, then a manager — each from their own
messenger account enrolled beforehand. A confirmation from any other account refuses the action.
How it works
- A hook of the plugin matches the action against its rules. Nothing matches — Claude Code goes on as usual.
- A rule matches — the plugin creates a confirmation with
POST /api/transaction/confirmation(client credentials), and the call is refused for now. - Claude shows the QR code Veriqa returned. The plugin ships a small MCP tool that takes only the transaction id and returns that image unchanged, so the agent copies nothing.
- Claude repeats the call, and this time the plugin waits for the outcome with
GET /api/transaction/{id}/result. The action runs only onconfirmed; declined, expired, a confirmation from the wrong account or an unreachable host all refuse it.
Why not the harness’s own “Allow” button
- A named person. The host checks which messenger account confirmed, not merely that someone pressed a button.
- Someone other than the developer. A chain asks a second person, so nobody signs off their own spending.
- A trail outside the agent’s session. Approvals are recorded on the Veriqa host, not in a local transcript the same user can edit.
- A question the agent does not write, answered on a separate device over a channel the agent does not control.