Skip to content

Integrations

Each adapter turns decision tools into its framework's own tools, and a tool-call check into the framework's own approval hook where it has one. Every framework also reaches MIMIR through its own MCP client; examples/ has a native, an MCP and a checked agent for each one.

Framework Install Tools Tool-call check
OpenAI Agents SDK mimir-decisions[openai-agents] as_function_tool guard: escalations pause the run for approval
LangChain, LangGraph mimir-decisions[langchain] as_structured_tool ToolCallCheckMiddleware: escalations interrupt with the human-in-the-loop request
PydanticAI mimir-decisions[pydantic-ai] as_toolset guard: escalations end the run with DeferredToolRequests
CrewAI mimir-decisions[crewai] as_crewai_tool tool_call_hook: escalations go to your approver
Google ADK mimir-decisions[adk] as_adk_tool tool_call_callback: escalations ask for ADK confirmation
Microsoft Agent Framework mimir-decisions[agent-framework] as_function_tool ToolCallCheckMiddleware: only certified calls run
LlamaIndex mimir-decisions[llamaindex] as_llamaindex_tool none: no hook before a tool call
smolagents mimir-decisions[smolagents] as_smolagents_tool none: no hook before a tool call
from agents import Agent
from mimir.integrations.openai_agents import as_function_tool

agent = Agent(name="support", tools=[as_function_tool(route_ticket)])

mimir.integrations.openai_agents

Decision tools as OpenAI Agents SDK function tools, and tool-call checks as approvals.

as_function_tool gives a FunctionTool taking the decision tool's arguments and returning its result as JSON; invalid arguments go back to the model as a message. guard returns a copy of any function tool that a ToolCallCheck gates: an escalated call pauses the run for a person (RunState.approve or RunState.reject), and a denied call is rejected with the check's reason, which the model reads.

as_function_tool

as_function_tool(tool: DecisionTool) -> FunctionTool

The function tool of tool, with its argument schema. The SDK takes only strict output schemas and a result's probabilities are an open mapping, so none is declared.

guard

guard(
    tool: FunctionTool, check: ToolCallCheck
) -> FunctionTool

A copy of tool whose calls check allows, denies or escalates for approval. The check replaces the tool's own needs_approval; its guardrails run before the check's.

mimir.integrations.langchain

Decision tools as LangChain tools, and tool-call checks as agent middleware.

as_structured_tool gives a StructuredTool for create_agent and LangGraph's ToolNode: the model reads the result as JSON, and the typed result is the tool message's artifact. Invalid arguments become an error tool message.

ToolCallCheckMiddleware decides each call a check applies to. A denied call becomes an error tool message carrying the check's reason. An escalated call interrupts the graph with the request of LangChain's HumanInTheLoopMiddleware, so the same reviewers and UIs handle it; the run resumes with Command(resume={"decisions": [{"type": "approve"}]}), or a reject decision with an optional message. Interrupts need the agent to have a checkpointer.

ToolCallCheckMiddleware

Bases: AgentMiddleware[AgentState[Any], Any, Any]

Agent middleware applying a ToolCallCheck before each tool call it covers.

as_structured_tool

as_structured_tool(tool: DecisionTool) -> StructuredTool

The LangChain tool of tool, with its argument schema.

mimir.integrations.pydantic_ai

Decision tools as a PydanticAI toolset, and tool-call checks as a toolset wrapper.

as_toolset gives a FunctionToolset whose tools take the decision tools' argument schemas and return their typed results. Invalid arguments ask the model to retry.

guard wraps any toolset so a ToolCallCheck decides each call. A denied call fails with the check's reason, which the model reads. An escalated call requires approval: the run ends with DeferredToolRequests (declare it in the agent's output_type) whose metadata holds the reason, and resumes with DeferredToolResults approving or denying the call.

CheckedToolset dataclass

Bases: WrapperToolset[Any]

A toolset whose calls a ToolCallCheck allows, denies or sends for approval.

as_tool

as_tool(tool: DecisionTool) -> Tool[Any]

The PydanticAI tool of tool, with its argument schema and typed result.

as_toolset

as_toolset(
    tools: Iterable[DecisionTool],
) -> FunctionToolset[Any]

A toolset of the PydanticAI tools of tools, in order.

guard

guard(
    toolset: AbstractToolset[Any], check: ToolCallCheck
) -> CheckedToolset

toolset, with every call decided by check first.

mimir.integrations.crewai

Decision tools as CrewAI tools, and tool-call checks as a before-tool-call hook.

as_crewai_tool gives a BaseTool taking the decision tool's arguments and returning its typed result, declared as the tool's result_schema.

tool_call_hook gives a hook for register_before_tool_call_hook. CrewAI hooks can only let a call run or block it, and a blocked call reads to the model as CrewAI's own blocked message. A denied call is blocked. An escalated call goes to approve, which returns whether a person allowed it (for a console, context.request_human_input); without approve it is blocked.

CrewDecisionTool

Bases: BaseTool

A CrewAI tool answering with a DecisionTool, named and described after it.

as_crewai_tool

as_crewai_tool(tool: DecisionTool) -> CrewDecisionTool

The CrewAI tool of tool.

tool_call_hook

tool_call_hook(
    check: ToolCallCheck, *, approve: Approver | None = None
) -> ToolCallHook

A before-tool-call hook applying check; escalations go to approve.

mimir.integrations.google_adk

Decision tools as Google ADK tools, and tool-call checks as a before-tool callback.

as_adk_tool gives a tool whose declaration carries the decision tool's argument schema and whose response is the result as a JSON object. Invalid arguments give an error response the model reads.

tool_call_callback gives a before_tool_callback for an LlmAgent. A denied call is skipped with an error response carrying the check's reason. An escalated call asks for confirmation through ADK's own flow, as tools built with require_confirmation do: the run emits an adk_request_confirmation call and resumes when the reply confirms or rejects it.

ADK 2.10 marks JSON Schema declarations and tool confirmation experimental and warns on use.

AdkDecisionTool

Bases: BaseTool

An ADK tool answering with a DecisionTool, named and described after it.

as_adk_tool

as_adk_tool(tool: DecisionTool) -> AdkDecisionTool

The ADK tool of tool.

tool_call_callback

tool_call_callback(
    check: ToolCallCheck,
) -> ToolCallCallback

A before_tool_callback applying check to every tool call.

mimir.integrations.agent_framework

Decision tools as Microsoft Agent Framework function tools, and tool-call checks as function middleware.

as_function_tool gives a FunctionTool validated by the decision tool's argument model and returning its result as JSON.

ToolCallCheckMiddleware decides each call a check applies to before it runs. A denied or an escalated call is not run, and the model reads the check's reason instead of a result. The framework's approval requests from middleware go through its private security layer, so an escalation does not pause the run; give tools that must pause approval_mode="always_require".

ToolCallCheckMiddleware

Bases: FunctionMiddleware

Function middleware applying a ToolCallCheck before each call it covers.

as_function_tool

as_function_tool(tool: DecisionTool) -> FunctionTool

The function tool of tool.

mimir.integrations.llamaindex

Decision tools as LlamaIndex tools, for FunctionAgent, ReActAgent and AgentWorkflow.

The model reads the result as JSON and the typed result is the tool output's raw_output. Invalid arguments give an error output the model reads. LlamaIndex has no hook that gates a tool call before it runs, so tool-call checks are not adapted.

LlamaDecisionTool

Bases: AsyncBaseTool

A LlamaIndex tool answering with a DecisionTool, named and described after it.

as_llamaindex_tool

as_llamaindex_tool(tool: DecisionTool) -> LlamaDecisionTool

The LlamaIndex tool of tool.

mimir.integrations.smolagents

Decision tools as smolagents tools, for ToolCallingAgent and CodeAgent.

The tool takes one context input and returns the result as a JSON object described by its output_schema, so a CodeAgent reads result["status"] and result["answer"]. smolagents reports invalid arguments to the model as a tool error. Its callbacks run after each step, not before a tool call, so tool-call checks are not adapted.

SmolDecisionTool

Bases: Tool

A smolagents tool answering with a DecisionTool, named and described after it.

as_smolagents_tool

as_smolagents_tool(tool: DecisionTool) -> SmolDecisionTool

The smolagents tool of tool.