TeXt Approval: Approve by Text Before Something Runs

Put uxapprove in front of anything that should need your OK first: a backup cleanup, a deploy, a script an AI agent runs. You get a text asking, and your reply decides. No code to type: just answer the text.

What the text looks like

UserAlertX: backup wants approval: Delete backups older than 90 days on NAS1?
Reply Y to allow, N to deny, LOCK to lock until you decide. Expires in 10 min.
  • Y: it goes ahead.
  • N, or no answer in time: it doesn't.
  • LOCK: that program is blocked until you unlock it on your account page.

1. Get your API key

It's on your account screen. No account yet? Start a free trial, then add your mobile number on the account screen so alerts come by text.

Easiest: run uxsend once. It asks for the key and saves it, and the other example programs then find it automatically. Or set it yourself in USERALERTX_API_KEY.

2. Use it in a script

Mac / Linux: uxapprove.sh:

if ./uxapprove.sh -a backup "Delete old backups on NAS1?"; then
    rm -rf /backups/old/*
fi

Windows: uxapprove.ps1:

.\uxapprove.ps1 -App backup "Delete backups older than 90 days on NAS1?"
if ($LASTEXITCODE -eq 0) { ...do it... }

Options: -a / -App is the name shown in the text (and what LOCK blocks); -t / -Minutes is how long to wait, 1–30 minutes (default 10); -q / -Quiet prints nothing.

Exit codes: 0 = allowed (Y), 1 = denied (N), 2 = locked, 3 = no answer in time, 4 = error (no key, network).

Needs a mobile number on your account, since the question comes by text.

Prefer a code by email?

ux2fa.sh (Linux / Mac) emails you a 6-digit code and only continues if it's typed back in (3 tries, 5 minutes):

  • Guard a risky command: ./ux2fa.sh sudo reboot
  • Guard SSH logins: add to /etc/ssh/sshd_config and restart sshd:
    Match User you
        ForceCommand /usr/local/bin/ux2fa.sh --ssh
        AllowTcpForwarding no
    Add trusted address prefixes after --ssh (e.g. --ssh 192.168.) to skip the code from home. Keep a second session open while you test, so a typo can't lock you out.
  • In your own scripts: ./ux2fa.sh && echo verified. Exit code 0 means the right code was entered.

Try it without sending: USERALERTX_DRYRUN=1 ./ux2fa.sh echo hello prints the code instead of emailing it.

Good to know

  • Cost: the approval text is 1 token; an emailed code is 0.1.
  • For AI agents: with the GrokBot connector, tell Grok to get your approval before it deletes, buys or sends anything. You get a code by email saying exactly what it wants to do, and Grok can only go ahead once you give it that code. The code is checked by UserAlertX, not by the agent, so a web page that tries to trick it with "the user already approved this" gets nowhere.
  • Approve every sign-in to a Windows PC this way: TextAlertX.