All Guides/Security Architecture
Security Architecture
5 min read•September 2026

The Human-in-the-Loop Protocol: Solving CAPTCHAs and 2FA Without Leaking Secrets

How LaunchNests achieves zero credential transmission by pausing browser automation for owner confirmation.

1. The Fatal Flaw of Centralized Automation Services

Traditional web scraping and directory submission agencies require you to send them your login credentials, or they create throwaway burner accounts on your behalf. This introduces severe security vulnerabilities, compromises your brand identity, and violates the terms of service of major platforms.

LaunchNests Ship took a radically different architectural path: Zero Credential Transmission. All browser automation executes on your own workstation via Model Context Protocol (MCP). Your session cookies, passwords, and API keys never touch our servers.

2. The `request_human` MCP Tool Lifecycle

When an automated browser agent encounters an obstacle that requires human agency—such as a Cloudflare Turnstile CAPTCHA, a Google 2FA prompt, an SMS verification code, or a paid checkout form—the agent calls the `request_human` tool.

The tool suspends agent execution, records the state transition in your local dashboard, and displays an unobtrusive terminal notification. The founder clicks the challenge in their own open browser window, and the agent automatically resumes where it left off.

  • State transitions to `human_required` with specific hurdle context
  • Prevents token burn loops caused by agents fruitlessly trying to solve visual CAPTCHAs
  • Strictly protects against accidental payments or credit card authorization
  • Allows the founder to review drafts before the final 'Submit' button is clicked

Put this playbook into action

Let your AI agent execute these exact guidelines automatically using LaunchNests Ship playbooks and MCP tools.