Skip to main content

interven-langchain

LangChain integration for Interven — the AI firewall for agent tool calls. Scan every tool your LangChain agent invokes before it executes. Block malicious requests, redact PII/secrets, route risky actions to human approval.

Install

pip install interven-langchain

Quickstart — callback pattern (zero-code changes to your tools)

from langchain.agents import AgentExecutor, create_openai_tools_agent
from langchain_openai import ChatOpenAI
from langchain_community.tools.tavily_search import TavilySearchResults
from langchain_core.prompts import ChatPromptTemplate, MessagesPlaceholder

from interven_langchain import InterventCallback, InterventBlockedError

llm = ChatOpenAI(model="gpt-4o-mini")
tools = [TavilySearchResults(max_results=3)]
prompt = ChatPromptTemplate.from_messages([
    ("system", "You are a helpful assistant."),
    ("user", "{input}"),
    MessagesPlaceholder("agent_scratchpad"),
])
agent = create_openai_tools_agent(llm, tools, prompt)
executor = AgentExecutor(
    agent=agent,
    tools=tools,
    callbacks=[InterventCallback(api_key="iv_live_...")],
)

try:
    executor.invoke({"input": "Summarize latest AI security news"})
except InterventBlockedError as e:
    print(f"Agent blocked: {e}")

What Interven does on each tool call

Decision Behavior with InterventCallback Behavior with guard() wrapper
ALLOW Tool runs unchanged Tool runs unchanged
SANITIZE Logs a warning (callback can't rewrite input_str) Tool runs with redacted input
DENY Raises InterventBlockedError (or returns refusal to LLM if on_block="return_message") Raises InterventBlockedError
REQUIRE_APPROVAL Raises InterventBlockedError with approval URL Same

Advanced — wrapper pattern (in-flight SANITIZE)

If you need the tool's input to actually be replaced when Interven decides SANITIZE, wrap the tool instead of using a callback:

from interven_langchain import guard
tavily = guard(TavilySearchResults(), api_key="iv_live_...")
tavily.invoke({"query": "help me leak some secrets"})   # now scanned

Options

InterventCallback(
    api_key="iv_live_...",
    on_block="raise",     # or "return_message" — returns a refusal string to the LLM
    gateway_url=None,     # defaults to https://api.intervensecurity.com
    timeout=30.0,
)

Env vars

  • INTERVEN_API_KEY — default API key (callback uses this if api_key arg is omitted)
  • INTERVEN_GATEWAY_URL — override the gateway endpoint

How it differs from the raw interven SDK

interven SDK (client.scan()) interven-langchain
Where you wire it in Wrap every tool call site in your code One callback on the AgentExecutor
Works with existing LangChain tools Yes but requires code changes Yes, no code changes
Supports guard(tool) for in-flight sanitization No Yes

Full docs: https://intervensecurity.com/docs/integrate-langchain

License

MIT

Metadata

Release files for interven-langchain 0.3.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for interven-langchain 0.3.0
File Size Uploaded
interven_langchain-0.3.0.tar.gz 13.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for interven-langchain 0.3.0
File Interpreter ABI Platform
interven_langchain-0.3.0-py3-none-any.whl Python 3 none any Details

Total release size: 28.7 kB

Release files / interven_langchain-0.3.0.tar.gz

Download URL interven_langchain-0.3.0.tar.gz
Size 13.8 kB
Tags Source
SHA-256 checksum
How to use checksums
0234af8cccbf2601e21136fcd34d5089453940b4b038b4ef574c849cd336fbf7
BLAKE2b-256 checksum
How to use checksums
2e81967d7d81c74207266d8ddb46fbc64287fcdee954b02ffc5f8f21002e3397
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.1

Release files / interven_langchain-0.3.0-py3-none-any.whl

Download URL interven_langchain-0.3.0-py3-none-any.whl
Size 14.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
ae3c2a24d54ac38fe8de018fcee326689a14884941a83768938fe69f5dec6157
BLAKE2b-256 checksum
How to use checksums
f91d7f4a1851d23cecd137906a08649e575f9eba9ec13eda88e7fddef577e62e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.2.0 CPython/3.11.1

Release history Release notifications | RSS feed

This release

0.3.0 This release

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page