Integrations¶
Each adapter turns decision tools into its framework's own tools, and a tool-call check
into the framework's own approval hook where it has one. Every framework also reaches
MIMIR through its own MCP client; examples/
has a native, an MCP and a checked agent for each one.
| Framework | Install | Tools | Tool-call check |
|---|---|---|---|
| OpenAI Agents SDK | mimir-decisions[openai-agents] |
as_function_tool |
guard: escalations pause the run for approval |
| LangChain, LangGraph | mimir-decisions[langchain] |
as_structured_tool |
ToolCallCheckMiddleware: escalations interrupt with the human-in-the-loop request |
| PydanticAI | mimir-decisions[pydantic-ai] |
as_toolset |
guard: escalations end the run with DeferredToolRequests |
| CrewAI | mimir-decisions[crewai] |
as_crewai_tool |
tool_call_hook: escalations go to your approver |
| Google ADK | mimir-decisions[adk] |
as_adk_tool |
tool_call_callback: escalations ask for ADK confirmation |
| Microsoft Agent Framework | mimir-decisions[agent-framework] |
as_function_tool |
ToolCallCheckMiddleware: only certified calls run |
| LlamaIndex | mimir-decisions[llamaindex] |
as_llamaindex_tool |
none: no hook before a tool call |
| smolagents | mimir-decisions[smolagents] |
as_smolagents_tool |
none: no hook before a tool call |
from agents import Agent
from mimir.integrations.openai_agents import as_function_tool
agent = Agent(name="support", tools=[as_function_tool(route_ticket)])
mimir.integrations.openai_agents ¶
Decision tools as OpenAI Agents SDK function tools, and tool-call checks as approvals.
as_function_tool gives a FunctionTool taking the decision tool's arguments and returning
its result as JSON; invalid arguments go back to the model as a message. guard returns a
copy of any function tool that a ToolCallCheck gates: an escalated call pauses the run for
a person (RunState.approve or RunState.reject), and a denied call is rejected with the
check's reason, which the model reads.
as_function_tool ¶
as_function_tool(tool: DecisionTool) -> FunctionTool
The function tool of tool, with its argument schema. The SDK takes only strict output
schemas and a result's probabilities are an open mapping, so none is declared.
guard ¶
guard(
tool: FunctionTool, check: ToolCallCheck
) -> FunctionTool
A copy of tool whose calls check allows, denies or escalates for approval. The
check replaces the tool's own needs_approval; its guardrails run before the check's.
mimir.integrations.langchain ¶
Decision tools as LangChain tools, and tool-call checks as agent middleware.
as_structured_tool gives a StructuredTool for create_agent and LangGraph's ToolNode:
the model reads the result as JSON, and the typed result is the tool message's artifact.
Invalid arguments become an error tool message.
ToolCallCheckMiddleware decides each call a check applies to. A denied call becomes an error
tool message carrying the check's reason. An escalated call interrupts the graph with the
request of LangChain's HumanInTheLoopMiddleware, so the same reviewers and UIs handle it; the
run resumes with Command(resume={"decisions": [{"type": "approve"}]}), or a reject
decision with an optional message. Interrupts need the agent to have a checkpointer.
ToolCallCheckMiddleware ¶
Bases: AgentMiddleware[AgentState[Any], Any, Any]
Agent middleware applying a ToolCallCheck before each tool call it covers.
as_structured_tool ¶
as_structured_tool(tool: DecisionTool) -> StructuredTool
The LangChain tool of tool, with its argument schema.
mimir.integrations.pydantic_ai ¶
Decision tools as a PydanticAI toolset, and tool-call checks as a toolset wrapper.
as_toolset gives a FunctionToolset whose tools take the decision tools' argument schemas
and return their typed results. Invalid arguments ask the model to retry.
guard wraps any toolset so a ToolCallCheck decides each call. A denied call fails with the
check's reason, which the model reads. An escalated call requires approval: the run ends with
DeferredToolRequests (declare it in the agent's output_type) whose metadata holds the
reason, and resumes with DeferredToolResults approving or denying the call.
CheckedToolset
dataclass
¶
Bases: WrapperToolset[Any]
A toolset whose calls a ToolCallCheck allows, denies or sends for approval.
as_tool ¶
as_tool(tool: DecisionTool) -> Tool[Any]
The PydanticAI tool of tool, with its argument schema and typed result.
as_toolset ¶
as_toolset(
tools: Iterable[DecisionTool],
) -> FunctionToolset[Any]
A toolset of the PydanticAI tools of tools, in order.
guard ¶
guard(
toolset: AbstractToolset[Any], check: ToolCallCheck
) -> CheckedToolset
toolset, with every call decided by check first.
mimir.integrations.crewai ¶
Decision tools as CrewAI tools, and tool-call checks as a before-tool-call hook.
as_crewai_tool gives a BaseTool taking the decision tool's arguments and returning its
typed result, declared as the tool's result_schema.
tool_call_hook gives a hook for register_before_tool_call_hook. CrewAI hooks can only let
a call run or block it, and a blocked call reads to the model as CrewAI's own blocked
message. A denied call is blocked. An escalated call goes to approve, which returns whether
a person allowed it (for a console, context.request_human_input); without approve it is
blocked.
CrewDecisionTool ¶
Bases: BaseTool
A CrewAI tool answering with a DecisionTool, named and described after it.
tool_call_hook ¶
tool_call_hook(
check: ToolCallCheck, *, approve: Approver | None = None
) -> ToolCallHook
A before-tool-call hook applying check; escalations go to approve.
mimir.integrations.google_adk ¶
Decision tools as Google ADK tools, and tool-call checks as a before-tool callback.
as_adk_tool gives a tool whose declaration carries the decision tool's argument schema and
whose response is the result as a JSON object. Invalid arguments give an error response the
model reads.
tool_call_callback gives a before_tool_callback for an LlmAgent. A denied call is
skipped with an error response carrying the check's reason. An escalated call asks for
confirmation through ADK's own flow, as tools built with require_confirmation do: the run
emits an adk_request_confirmation call and resumes when the reply confirms or rejects it.
ADK 2.10 marks JSON Schema declarations and tool confirmation experimental and warns on use.
AdkDecisionTool ¶
Bases: BaseTool
An ADK tool answering with a DecisionTool, named and described after it.
tool_call_callback ¶
tool_call_callback(
check: ToolCallCheck,
) -> ToolCallCallback
A before_tool_callback applying check to every tool call.
mimir.integrations.agent_framework ¶
Decision tools as Microsoft Agent Framework function tools, and tool-call checks as function middleware.
as_function_tool gives a FunctionTool validated by the decision tool's argument model and
returning its result as JSON.
ToolCallCheckMiddleware decides each call a check applies to before it runs. A denied or an
escalated call is not run, and the model reads the check's reason instead of a result. The
framework's approval requests from middleware go through its private security layer, so an
escalation does not pause the run; give tools that must pause approval_mode="always_require".
ToolCallCheckMiddleware ¶
Bases: FunctionMiddleware
Function middleware applying a ToolCallCheck before each call it covers.
mimir.integrations.llamaindex ¶
Decision tools as LlamaIndex tools, for FunctionAgent, ReActAgent and AgentWorkflow.
The model reads the result as JSON and the typed result is the tool output's raw_output.
Invalid arguments give an error output the model reads. LlamaIndex has no hook that gates a
tool call before it runs, so tool-call checks are not adapted.
LlamaDecisionTool ¶
Bases: AsyncBaseTool
A LlamaIndex tool answering with a DecisionTool, named and described after it.
as_llamaindex_tool ¶
as_llamaindex_tool(tool: DecisionTool) -> LlamaDecisionTool
The LlamaIndex tool of tool.
mimir.integrations.smolagents ¶
Decision tools as smolagents tools, for ToolCallingAgent and CodeAgent.
The tool takes one context input and returns the result as a JSON object described by its
output_schema, so a CodeAgent reads result["status"] and result["answer"]. smolagents
reports invalid arguments to the model as a tool error. Its callbacks run after each step,
not before a tool call, so tool-call checks are not adapted.
SmolDecisionTool ¶
Bases: Tool
A smolagents tool answering with a DecisionTool, named and described after it.
as_smolagents_tool ¶
as_smolagents_tool(tool: DecisionTool) -> SmolDecisionTool
The smolagents tool of tool.