llms.txt Content
# AgentSIM
> OTP sessions for browser agents. Programmable US numbers for two jobs: running browser-agent / CI OTP workflows, and red-teaming your own SMS-OTP fraud defenses. Provision a disposable programmable US number, wait for SMS, parse the OTP, record the outcome, and release — over SDK, REST, webhooks, or MCP. For authorized testing of systems you own or are permitted to test.
## What It Does
AgentSIM provisions a temporary programmable US number, waits for the inbound SMS, runs a multi-stage OTP parser, and records a delivery outcome — without a human watching an inbox. One engine, two authorized use cases:
- **Browser-agent & CI OTP workflows.** When a browser agent or test suite hits an SMS step on an app you own, AgentSIM handles the number, the wait, and the parse so the run can continue.
- **Fraud & security testing.** Fraudsters create accounts and pass SMS verification with disposable, programmable numbers at scale. AgentSIM gives fraud, risk, and trust-&-safety teams the same numbers, under their control, so they can red-team their own ATO and signup-fraud detection.
One session = one provision, one OTP attempt, one observed outcome, one release. $0.99/session after a 10-session free tier.
## Authorized Use Only
AgentSIM is for **authorized security testing of systems you own or are permitted to test**, and for OTP workflows on auth providers you control. These are programmable (not real-SIM) numbers, so they behave like an attacker's — which is exactly what you want when simulating one.
**Not for** creating accounts on third-party services you do not own, bypassing anti-abuse systems at Google, Meta, Stripe, or banks, bulk account creation, ban evasion, or any use that violates a target service's terms or applicable law.
## Where It Works (Today)
AgentSIM is appropriate for owned/controlled OTP workflows and services empirically known to accept programmable / agent-pooled US numbers. The empirical support map is maintained in docs/su