Arcezia / Integrations / LangChain and LangGraph
LangChain and LangGraph: check each tool call before it runs
Wrap your LangChain or LangGraph tools with Arcezia and each call is checked before it runs. Only ALLOW reaches the tool.
Setup
Before this: install the SDK, get a key and register a contract for your tool, as in Quickstart steps 1 to 5. SQL below is the contract domain from that Quickstart, and private_key is your signing key. Make one client and open the session:
from arcezia import Arcezia
az = Arcezia(task="look up orders", on_error="review", signing_key=private_key)
az.start_session(capability_envelope={
"allowed_domains": [SQL],
"allowed_action_types": ["execute_sql"],
"resource_scope": ["orders"],
})
Wrap the tools
from arcezia.integrations.langchain import ArceziaToolkit
safe = ArceziaToolkit(az).wrap([execute_sql], domain_overrides={"execute_sql": SQL})
safe[0].run({"query": "SELECT COUNT(*) FROM orders"}) # raises ToolException on REVIEW or BLOCK
graph_tools = ArceziaToolkit(az).wrap_for_langgraph([execute_sql],
domain_overrides={"execute_sql": SQL})
wrap_for_langgraph returns real LangChain tools with the original argument schema, so they plug into LangGraph’s ToolNode and create_react_agent.
What you get
- ALLOW: the tool runs.
- REVIEW: the tool does not run; the exception names what would release it.
- BLOCK: the tool does not run; the exception gives the reason.
On a new key a call usually comes back REVIEW first. The answer names what would release it, for example a contract for the tool or a signed scope for the session. See Handling the answers.
Same answers everywhere. Every hookup calls the same service with the same rules. Switching frameworks does not change a verdict.
Questions
How do I add human approval to a LangChain or LangGraph tool?
Wrap the tools with ArceziaToolkit. When a call needs a person, the wrapped tool does not run: it raises ToolException with [Arcezia REVIEW] and what would release it, for example approval:user. In LangGraph it arrives as an error tool message.
A person’s approval is a token your backend signs after the person clicks Approve. The agent cannot make one, and an approval the agent merely claims is refused. How to sign and attach it: Approvals.
What happens on BLOCK?
The tool does not run. The wrapper raises ToolException with [Arcezia BLOCK] and the reason.