Skip to main content
A tool is a model-callable application function with validated arguments. A toolkit supplies a collection of those functions. Start with the order lookup tutorial for a complete program; these patterns fit into an existing application.

Expose an authorized lookup

Host factory: supply a model and a lookup function already bound to the verified caller. The callback should enforce record ownership in your data layer. The caller owns the returned Agent and closes it after its runs finish.
Use a fixture such as { id: "ORD-1042", status: "shipped", deliveryDate: "Friday" } while developing. Ask about that ID, observe the tool call, and verify the answer agrees with the returned record. A schema validates the shape of an ID; the host lookup decides whether the caller may read it.

Choose toolkit tools deliberately

Host factory: the selected directory already exists. This read-only example enables the filesystem toolkit’s tools and leaves their implementation with the toolkit.
Close the returned Agent when its work ends. For remote toolkits, configure the service’s dependency and credentials before constructing tools. The toolkit pattern directory links to those provider-specific requirements.

Ask for a decision before an effect

Host factory: pass the action tool and an asynchronous decision function. This example delegates the decision to the caller; it does not automatically approve requests or invent an approval UI.
The name-only callback is enough for a local demonstration. A hosted approval needs the exact prepared arguments, verified reviewer identity, and pending-action ownership; use the full approval contract for that integration. Verify both branches with a simulated action: denial must leave its effect count at zero; approval permits execution. The harness workflow project makes both outcomes directly runnable without a model or payment service.

More patterns

  • Toolkits: public imports and available capabilities.
  • MCP: tools supplied by an external protocol server.
  • Jev toolkit: typed judgments exposed as tools.
  • Execution policy: host policy and effect authorization.