These pages cover toolpass's permission checks: the engine behind Toolpass, guarded and
permission_check. For the secure-tools toolkit (scope limits, approval, the untrusted-input and
exfiltration guards, credential injection), see the package README.
toolpass answers one question before your agent acts for someone: may this user do this action on
this resource in this system? It asks the system itself, live, and answers allow, deny or
unknown. It is a Python package: the engine runs in your agent's process, or as a server that
agents in any language call.
- Permission checks: what they do, how they differ from policy engines and OAuth, and its security model.
- Quickstart: install toolpass, ask a question, guard an agent tool, and run it as a server, in five minutes.
- Architecture: the parts, how one check flows, what is cached, and the trust boundaries.
- Deploy: in-process, sidecar or shared service, TLS, Docker, pip, Kubernetes with Helm, scaling and a production checklist.
- Add toolpass to your agent: which tools to guard, where the user comes from, and the adapters for Strands, LangChain and LangGraph, MCP, the OpenAI Agents SDK, the Claude Agent SDK, Google ADK, CrewAI, Pydantic AI, LlamaIndex and the Vercel AI SDK.
- Operating: health, the decision log, what each
unknownmeans, and rotating secrets.
- Python API:
Toolpassin-process and remote,check,require,guarded, the framework adapters, and the Node client. - HTTP API:
POST /check, every decision code, fresh checks,GET /healthz. - Configuration:
toolpass.yaml, top-level and per-connection keys, and the same connections given in code. - Command line:
serve,validate,probe,checkandcatalog. - Integrations: the twenty-one systems, their status, and one page each.
- Packages and releases:
toolpass, the Node client, the image and the chart, and how they are released. - Helm chart values.
- Writing an integration.
- Testing: unit, spec-validated, property, framework, real-system, end-to-end and differential tests.
- Contributing and security reports.