← All Frameworks

LangChain Guardrails

AsyncCallbackHandler for pre-tool-call authorization

Python

LangChain is the most widely-used framework for building LLM applications with 90k+ GitHub stars. APort integrates as an AsyncCallbackHandler that intercepts tool execution before it happens, enforcing OAP policies on every tool call.

Quick Start

1. Create passport & config

setup
npx @aporthq/aport-agent-guardrails langchain

2. Install guardrails package

install
pip install aport-agent-guardrails-langchain

3. Add to your code

code
from aport_guardrails_langchain import APortCallback

agent = initialize_agent(
    tools=tools,
    llm=llm,
    callbacks=[APortCallback()]
)

Test the authorization boundary

Installer target: langchain. Aliases: none; use the target ID.

LangChain setup
npx @aporthq/aport-agent-guardrails langchain

Denied-action example

Read .env.aport-smoke-test with a passport that blocks .env* paths.

Expected policy result: deny. Use an empty test file. In warn mode the runtime may continue; enforce mode must stop the read. Hosted mode can record the decision; local mode does not prove hosted audit persistence.

Expected policy result, illustrative
{
  "policy_id": "data.file.read.v1",
  "allow": false,
  "reason": "oap.blocked_pattern"
}

How It Works

1

Passport

Your agent gets an OAP passport declaring its identity, capabilities, and operational limits.

2

Evaluate

Before every tool call, the guardrail evaluates it against the passport's policy. Locally or via hosted API.

3

Decision

Allow or deny with structured OAP reason codes. Signed decisions create an auditable trail.

Frequently Asked Questions

How do LangChain guardrails work?

APort provides an AsyncCallbackHandler that hooks into LangChain's on_tool_start event. Before any tool executes, the handler evaluates the call against your OAP passport's declared capabilities and limits.

Does this work with LangGraph?

Yes. Since LangGraph is built on LangChain, the APortCallback works in LangGraph workflows, ToolNodes, and agent executors without modification.

Ready to secure your LangChain agents?

Review the setup command and denied-action check before enforcing policy.

Start free for local or individual setup. Upgrade to Team for hosted org audit, signed decisions, GitHub guardrails, and shared enforcement across your team.