A text box that proves a human typed it.

Add one script tag and your comments, posts, reviews or articles come with proof that a real person typed them: signed in, typed letter by letter, no paste, no AI, confirmed on their phone.

Free for humans · Works in any HTML form · React-friendly · Open-source SDK · MCP for AI coding agents

acme-forum.com/posts/42
Show HN: we built a forum for real people
|
Typing as @mayaProof of Type
Post comment
  1. 1They type on your site
  2. 2Pasting is refused
  3. 3They confirm on their phone
  4. 4Shown as typed by a human
  5. 5Your server checks the proof

Try it

The real input, signed in with your Proof of Type account and confirmed on your phone.

Live demo (this is the real input, embedded with the script below)

Why

Generated text is now free and endless. AI detectors guess from the finished words and get it wrong both ways. Proof of Type Input doesn't guess: it proves how the text was made. The person types it in our box, key by key; we time the typing on our own server; and they approve the exact text on their phone with Face ID or a fingerprint, in an app the phone's hardware vouches for. A script can't do the last step, and pasted or generated text never gets a proof.

How it works

  1. You embed the input with one script tag. It runs in a secure frame from proofoftype.com, so your page (or anything injected into it) can't fake keystrokes.
  2. The person signs in with their Proof of Type account (one popup) and types.
  3. They confirm on their phone: the Proof of Type app shows the exact text; Face ID or fingerprint signs it. On a computer they scan a QR code.
  4. You get the text + a proof token: a signed JWT naming who typed it, on which site, when, and a SHA-256 of the exact text.
  5. You verify it on your server with one API call, or offline with our public key, before you publish.

Quickstart

1. In any HTML form: the input fills two hidden fields and verifies before the form submits.

HTML
<script src="https://www.proofoftype.com/sdk/v1.js" async></script>

<form method="post" action="/comments">
  <div data-proofoftype data-name="comment"
       data-placeholder="Write a comment"></div>
  <button>Post</button>
</form>
<!-- On submit, the form gets two fields:
     comment        the text
     comment_proof  the signed proof token -->

2. Check the proof on your server before saving.

Node.js
// Server: check the proof before you save the text.
const res = await fetch('https://www.proofoftype.com/api/v1/verify', {
  method: 'POST',
  headers: { 'Content-Type': 'application/json' },
  body: JSON.stringify({
    token: req.body.comment_proof,
    text: req.body.comment,              // must be the exact text
    origin: 'https://your-site.com',     // must be your site
  }),
});
const r = await res.json();
if (!r.valid || !r.text_matches || !r.origin_matches) {
  return reply.status(400).send('Please verify you typed this.');
}
// r.proof.author: the Proof of Type username who typed it

Or drive it from JavaScript:

JavaScript API
<div id="editor"></div>
<script src="https://www.proofoftype.com/sdk/v1.js"></script>
<script>
  const input = ProofOfType.mount('#editor', {
    placeholder: 'Write your article…',
    maxWords: 2000,
    button: false,          // you drive verification
  });

  input.on('change', ({ words }) => console.log(words, 'words'));

  document.querySelector('#publish').onclick = async () => {
    const proof = await input.verify();   // person confirms on their phone
    await fetch('/api/articles', {
      method: 'POST',
      headers: { 'Content-Type': 'application/json' },
      body: JSON.stringify({ text: proof.text, proof: proof.token }),
    });
  };
</script>
React
import { useEffect, useRef } from 'react';

export function HumanInput({ onVerified, ...options }) {
  const ref = useRef(null);
  useEffect(() => {
    const input = window.ProofOfType.mount(ref.current, options);
    input.on('verified', onVerified);
    return () => input.destroy();
  }, []);
  return <div ref={ref} />;
}
Python
import hashlib, requests

r = requests.post("https://www.proofoftype.com/api/v1/verify", json={
    "token": form["comment_proof"],
    "text": form["comment"],
    "origin": "https://your-site.com",
}).json()
ok = r["valid"] and r["text_matches"] and r["origin_matches"]

Full details: API reference.

Build it with your AI coding agent (MCP)

Vibe coding a site? Connect the Proof of Type MCP server and ask your agent for "a comment box that proves a human typed it". It gets ready-to-paste code for your framework, can check proof tokens, and knows what a proof does and doesn't guarantee. Server: https://www.proofoftype.com/mcp (Streamable HTTP, no key).

Claude Code
claude mcp add --transport http proofoftype https://www.proofoftype.com/mcp
Cursor, VS Code, other MCP clients
{
  "mcpServers": {
    "proofoftype": { "url": "https://www.proofoftype.com/mcp" }
  }
}

Tools: get_quickstart(framework) · verify_proof(token, text, origin) · explain(topic). Agents can also read llms.txt.

Privacy and security

  • We never store the text typed on your site. Only its SHA-256 is signed into the proof.
  • Keystrokes are checked and discarded. The input sends your page the text only once it's verified, and only to your page's real origin.
  • Your site gets the person's Proof of Type username, never their email or account.
  • Each proof is single-use: one typing session, one signature on the phone, one proof.
  • Proof tokens are EdDSA (Ed25519) JWTs. Public keys: /.well-known/jwks.json.

FAQ

How do I know a comment or post on my site was written by a human and not AI?

Use Proof of Type Input as the text box. It only produces a proof when a signed-in person typed the text letter by letter in the box and approved that exact text on their phone with Face ID or a fingerprint. Pasted or generated text never gets a proof. Check the proof token on your server before you publish.

Is this an AI-text detector?

No. Detectors guess from the finished text and can be wrong either way. Proof of Type proves how the text was made: typed key by key in our input, with typing timed on our server, by a verified account, confirmed on a hardware-attested phone. There is nothing to guess.

Couldn't someone just retype text an AI wrote?

Yes. A person can retype words they got anywhere, and no tool can read minds. What Proof of Type proves is that a real, signed-in person typed every letter in real time and approved that exact text on their own phone, under their own name. That turns AI spam from free and endless into slow, personal and accountable: one person, one phone, real typing time per post. It proves effort and authorship by a person, not that the ideas are original.

Anything that runs in the browser can be faked. Can't an auto-typer script fake it?

A script can fake keystrokes in a page it controls. That's why the capture doesn't run in your page: it runs in Proof of Type's own frame, the typing is timed on our server (it can't be instant, replayed or pasted), and then the exact text must be approved on the author's phone with Face ID or a fingerprint, in an app the phone's hardware vouches for (Apple App Attest, Android key attestation). An auto-typer has no phone to approve with. Every proof needs a present person, under a real account, one text at a time, so automation can't run unattended or at scale. That's evidence you can verify, not a probability score.

How is this different from AI detectors, CAPTCHAs and typing-rhythm libraries?

AI detectors guess from the finished text. CAPTCHAs check that a visitor is not a bot, not who wrote the words. Typing-rhythm libraries run in your page, where scripts and extensions can fake the signals, and they produce a score, not a proof. Proof of Type runs the capture in its own secure frame, times the typing on its server, ties it to a verified person with a hardware-attested phone signature, and gives you a signed token anyone can verify. And it is an embeddable box, not a browser extension your users have to install.

What does my site receive?

The text and a proof token: a signed JWT (EdDSA) saying who typed it, on which site, when, and a SHA-256 of the exact text. You store both. Anyone can check the token with POST /api/v1/verify or offline with our public key at /.well-known/jwks.json.

Do you store the text people type on my site?

No. The text is checked when it is verified and only its SHA-256 goes into the proof. Typing data is never stored either.

Do my users need an account?

Yes: a free Proof of Type account and the Proof of Type app on their phone (iPhone or Android). That is what makes it a proof of a person, not just of a keyboard. Signing in takes one popup; each proof is one Face ID or fingerprint.

Why is it an iframe and not an open-source component?

The security has to run where your page can't change it: the keystroke capture, the typing timeline and the phone signature. The SDK, the React component and the verification helpers are open source (MIT); the checks run on Proof of Type.

Can people paste or use autocomplete?

Only links can be pasted. Autocorrect of a word you typed is allowed; predictive text, swipe words and dictation are not. That keeps the text the person's own keystrokes.

Does it work on phones?

Yes. On a phone browser the person types with their keyboard and confirms in the Proof of Type app. On a computer they scan a QR code with their phone.

What does it cost?

Free for humans.

What are the limits?

Up to 3,000 words per text (you set the maximum), 60 verifications per account per hour. A proof is single-use: one typing session backs one proof.

Latest update

v1.1.0 · 2026-10-11 · MCP server for AI coding agents. All updates