org.llm4s.agent.graph.middleware

Members list

Type members

Classlikes

A cross-cutting concern - approval, guardrails, logging, retry, rate limits - around an agent run, its model calls and its tool calls. Every hook passes through by default; override only those the concern needs.

A cross-cutting concern - approval, guardrails, logging, retry, rate limits - around an agent run, its model calls and its tool calls. Every hook passes through by default; override only those the concern needs.

Middleware run as a MiddlewareStack, ordered by registration and by runsBefore and runsAfter: the first in stack order is the outermost wrapper and runs beforeAgent first; unwinding, and afterAgent, run in reverse. A hook that throws fails the run with GraphError.MiddlewareFailed; a thrown cancellation cancels it.

wrapToolCall runs concurrently for the calls of one batch (up to RunBudgets.maxConcurrency), on task threads, so a middleware's own state must be thread-safe.

A wrapper should pass ToolOutcome.Fatal(CancelledError) through and not retry it: the call was cancelled, and a retry gets the same outcome without running the tool again.

Attributes

Supertypes
class Object
trait Matchable
class Any
Known subtypes
final class ApprovalMiddleware(requires: ToolCallRequest => Option[String], val id: MiddlewareId) extends AgentMiddleware

Asks for approval before a tool call runs. requires returns the reason to ask, or None to let the call through; a call that is already approved always passes. A tool's own approval request is unaffected.

Asks for approval before a tool call runs. requires returns the reason to ask, or None to let the call through; a call that is already approved always passes. A tool's own approval request is unaffected.

Attributes

Companion
object
Supertypes
class Object
trait Matchable
class Any

Attributes

Companion
class
Supertypes
class Object
trait Matchable
class Any
Self type
final class GuardrailMiddleware(input: Seq[InputGuardrail], output: Seq[OutputGuardrail], val id: MiddlewareId) extends AgentMiddleware

Runs input guardrails on the run's input (beforeAgent) and output guardrails on its final answer (afterAgent). Each list runs in order, each guardrail on the value the previous one returned, so a Fix transforms; a Warn passes. Failures are collected and fail the run with the error CompositeGuardrail.all reports. A guardrail does not suspend.

Runs input guardrails on the run's input (beforeAgent) and output guardrails on its final answer (afterAgent). Each list runs in order, each guardrail on the value the previous one returned, so a Fix transforms; a Warn passes. Failures are collected and fail the run with the error CompositeGuardrail.all reports. A guardrail does not suspend.

Attributes

Companion
object
Supertypes
class Object
trait Matchable
class Any

Attributes

Companion
class
Supertypes
class Object
trait Matchable
class Any
Self type
object MiddlewareId

Attributes

Supertypes
class Object
trait Matchable
class Any
Self type
final class MiddlewareStack

Middleware in the order they run, built and checked whole by MiddlewareStack.of.

Middleware in the order they run, built and checked whole by MiddlewareStack.of.

ordered(0) is the outermost wrapper: its next calls ordered(1)'s hook, and the last one's next calls the innermost function. beforeAgent runs in stack order and afterAgent in reverse; each stops at the first Left. Every hook invocation is guarded on its own: a throw becomes GraphError.MiddlewareFailed naming that middleware, and a thrown cancellation a CancelledError, restoring the interrupt flag at once, which each enclosing wrapper sees as its next's result. The innermost function is not guarded; its caller guards it.

Attributes

Companion
object
Supertypes
class Object
trait Matchable
class Any

Attributes

Companion
class
Supertypes
class Object
trait Matchable
class Any
Self type
final case class ModelRequest(messages: Vector[Message], tools: ToolSet)

One model call as a model wrapper sees it: the conversation so far and the tools offered.

One model call as a model wrapper sees it: the conversation so far and the tools offered.

Attributes

Supertypes
trait Serializable
trait Product
trait Equals
class Object
trait Matchable
class Any
Show all
final case class ToolCallRequest(spec: AgentToolSpec[_], call: ToolCall)

One tool call as a tool wrapper sees it, after its arguments were validated and decoded. It is read-only: a wrapper cannot change a call's arguments.

One tool call as a tool wrapper sees it, after its arguments were validated and decoded. It is read-only: a wrapper cannot change a call's arguments.

Attributes

Supertypes
trait Serializable
trait Product
trait Equals
class Object
trait Matchable
class Any
Show all

Types

opaque type MiddlewareId

Stable identifier of an AgentMiddleware in a MiddlewareStack; must match [a-zA-Z0-9_-]{1,64}, which MiddlewareStack.of checks. Persisted in approval requests.

Stable identifier of an AgentMiddleware in a MiddlewareStack; must match [a-zA-Z0-9_-]{1,64}, which MiddlewareStack.of checks. Persisted in approval requests.

Attributes