langchain-middleware

Middleware d'approbation humaine, middleware personnalisé et modèles de sortie structurée pour les agents LangChain. HumanInTheLoopMiddleware interrompt l'exécution avant les appels d'outils dangereux, permettant aux humains d'approuver, de modifier les arguments ou de rejeter avec retour. Les politiques d'interruption par outil permettent de configurer différentes règles d'approbation selon le niveau de risque ; nécessite un checkpointer et un thread_id pour la persistance de l'état. Le modèle de reprise de commande continue l'exécution après les décisions humaines, avec prise en charge de la modification des arguments des outils...

npx skills add https://github.com/langchain-ai/langchain-skills --skill langchain-middleware
Middleware patterns for production LangChain agents:
  • HumanInTheLoopMiddleware / humanInTheLoopMiddleware: Pause before dangerous tool calls for human approval
  • Custom middleware: Intercept tool calls for error handling, logging, retry logic
  • Command resume: Continue execution after human decisions (approve, edit, reject)

Requirements: Checkpointer + thread_id config for all HITL workflows.


Human-in-the-Loop

Set up an agent with HITL middleware that pauses before sending emails for approval.
from langchain.agents import create_agent
from langchain.agents.middleware import HumanInTheLoopMiddleware
from langgraph.checkpoint.memory import MemorySaver
from langchain.tools import tool

@tool
def send_email(to: str, subject: str, body: str) -> str:
    """Send an email."""
    return f"Email sent to {to}"

agent = create_agent(
    model="gpt-4.1",
    tools=[send_email],
    checkpointer=MemorySaver(),  # Required for HITL
    middleware=[
        HumanInTheLoopMiddleware(
            interrupt_on={
                "send_email": {"allowed_decisions": ["approve", "edit", "reject"]},
            }
        )
    ],
)
Set up an agent with HITL that pauses before sending emails for human approval.
import { createAgent, humanInTheLoopMiddleware } from "langchain";
import { MemorySaver } from "@langchain/langgraph";
import { tool } from "@langchain/core/tools";
import { z } from "zod";

const sendEmail = tool(
  async ({ to, subject, body }) => `Email sent to ${to}`,
  {
    name: "send_email",
    description: "Send an email",
    schema: z.object({ to: z.string(), subject: z.string(), body: z.string() }),
  }
);

const agent = createAgent({
  model: "anthropic:claude-sonnet-4-5",
  tools: [sendEmail],
  checkpointer: new MemorySaver(),
  middleware: [
    humanInTheLoopMiddleware({
      interruptOn: { send_email: { allowedDecisions: ["approve", "edit", "reject"] } },
    }),
  ],
});
Run the agent, detect an interrupt, then resume execution after human approval.
from langgraph.types import Command

config = {"configurable": {"thread_id": "session-1"}}

# Step 1: Agent runs until it needs to call tool
result1 = agent.invoke({
    "messages": [{"role": "user", "content": "Send email to john@example.com"}]
}, config=config)

# Check for interrupt
if "__interrupt__" in result1:
    print(f"Waiting for approval: {result1['__interrupt__']}")

# Step 2: Human approves
result2 = agent.invoke(
    Command(resume={"decisions": [{"type": "approve"}]}),
    config=config
)
Run the agent, detect an interrupt, then resume execution after human approval.
import { Command } from "@langchain/langgraph";

const config = { configurable: { thread_id: "session-1" } };

// Step 1: Agent runs until it needs to call tool
const result1 = await agent.invoke({
  messages: [{ role: "user", content: "Send email to john@example.com" }]
}, config);

// Check for interrupt
if (result1.__interrupt__) {
  console.log(`Waiting for approval: ${result1.__interrupt__}`);
}

// Step 2: Human approves
const result2 = await agent.invoke(
  new Command({ resume: { decisions: [{ type: "approve" }] } }),
  config
);
Edit the tool arguments before approving when the original values need correction.
# Human edits the arguments — edited_action must include name + args
result2 = agent.invoke(
    Command(resume={
        "decisions": [{
            "type": "edit",
            "edited_action": {
                "name": "send_email",
                "args": {
                    "to": "alice@company.com",  # Fixed email
                    "subject": "Project Meeting - Updated",
                    "body": "...",
                },
            },
        }]
    }),
    config=config
)
Edit the tool arguments before approving when the original values need correction.
// Human edits the arguments — editedAction must include name + args
const result2 = await agent.invoke(
  new Command({
    resume: {
      decisions: [{
        type: "edit",
        editedAction: {
          name: "send_email",
          args: {
            to: "alice@company.com",  // Fixed email
            subject: "Project Meeting - Updated",
            body: "...",
          },
        },
      }]
    }
  }),
  config
);
Reject a tool call and provide feedback explaining why it was rejected.
# Human rejects
result2 = agent.invoke(
    Command(resume={
        "decisions": [{
            "type": "reject",
            "feedback": "Cannot delete customer data without manager approval",
        }]
    }),
    config=config
)
Configure different HITL policies for each tool based on risk level.
agent = create_agent(
    model="gpt-4.1",
    tools=[send_email, read_email, delete_email],
    checkpointer=MemorySaver(),
    middleware=[
        HumanInTheLoopMiddleware(
            interrupt_on={
                "send_email": {"allowed_decisions": ["approve", "edit", "reject"]},
                "delete_email": {"allowed_decisions": ["approve", "reject"]},  # No edit
                "read_email": False,  # No HITL for reading
            }
        )
    ],
)
### What You CAN Configure
  • Which tools require approval (per-tool policies)
  • Allowed decisions per tool (approve, edit, reject)
  • Custom middleware hooks: before_model, after_model, wrap_tool_call, before_agent, after_agent
  • Tool-specific middleware (apply only to certain tools)

Custom Middleware Hooks

Six decorator hooks are available. Two patterns:

  • Wrap hooks (wrap_tool_call, wrap_model_call): (request, handler) — call handler(request) to proceed, or return early to short-circuit.
  • Before/after hooks (before_model, after_model, before_agent, after_agent): (state, runtime) — inspect or modify state. Return None or a dict of state updates.
`@wrap_tool_call` intercepts tool execution. **Do NOT use `yield`** — it creates a generator and causes `NotImplementedError`.
from langchain.agents.middleware import wrap_tool_call

@wrap_tool_call
def retry_middleware(request, handler):
    for attempt in range(3):
        try:
            return handler(request)
        except Exception:
            if attempt == 2:
                raise

@wrap_tool_call
def guard_middleware(request, handler):
    if request.tool_call["name"] == "dangerous_tool":
        return "This tool is disabled"  # short-circuit
    return handler(request)
`createMiddleware({ wrapToolCall })` intercepts tool execution.
import { createMiddleware } from "langchain";

const retryMiddleware = createMiddleware({
  wrapToolCall: async (request, handler) => {
    for (let attempt = 0; attempt < 3; attempt++) {
      try { return await handler(request); }
      catch (e) { if (attempt === 2) throw e; }
    }
  },
});
`before_model` / `after_model` / `before_agent` / `after_agent` all share `(state, runtime)` signature.
from langchain.agents.middleware import before_model, after_model

@before_model
def log_calls(state, runtime):
    print(f"Calling model with {len(state['messages'])} messages")

@after_model
def check_output(state, runtime):
    print(f"Model responded")
All before/after hooks share the same `(state, runtime)` signature via `createMiddleware`.
import { createMiddleware } from "langchain";

const loggingMiddleware = createMiddleware({
  beforeModel: (state, runtime) => {
    console.log(`Calling model with ${state.messages.length} messages`);
  },
  afterModel: (state, runtime) => {
    console.log("Model responded");
  },
});
### What You CANNOT Configure
  • Interrupt after tool execution (must be before)
  • Skip checkpointer requirement for HITL
HITL middleware requires a checkpointer to persist state.
# WRONG
agent = create_agent(model="gpt-4.1", tools=[send_email], middleware=[HumanInTheLoopMiddleware({...})])

# CORRECT
agent = create_agent(
    model="gpt-4.1", tools=[send_email],
    checkpointer=MemorySaver(),  # Required
    middleware=[HumanInTheLoopMiddleware({...})]
)
HITL requires a checkpointer to persist state.
// WRONG: No checkpointer
const agent = createAgent({
  model: "anthropic:claude-sonnet-4-5", tools: [sendEmail],
  middleware: [humanInTheLoopMiddleware({ interruptOn: { send_email: true } })],
});

// CORRECT: Add checkpointer
const agent = createAgent({
  model: "anthropic:claude-sonnet-4-5", tools: [sendEmail],
  checkpointer: new MemorySaver(),
  middleware: [humanInTheLoopMiddleware({ interruptOn: { send_email: true } })],
});
Always provide thread_id when using HITL to track conversation state.
# WRONG
agent.invoke(input)  # No config!

# CORRECT
agent.invoke(input, config={"configurable": {"thread_id": "user-123"}})
Use Command class to resume execution after an interrupt.
# WRONG
agent.invoke({"resume": {"decisions": [...]}})

# CORRECT
from langgraph.types import Command
agent.invoke(Command(resume={"decisions": [{"type": "approve"}]}), config=config)
Use Command class to resume execution after an interrupt.
// WRONG
await agent.invoke({ resume: { decisions: [...] } });

// CORRECT
import { Command } from "@langchain/langgraph";
await agent.invoke(new Command({ resume: { decisions: [{ type: "approve" }] } }), config);

Plus de skills de langchain-ai

langgraph-docs
langchain-ai
We need to translate the given text from English to French. The text describes an agent skill for accessing LangGraph documentation. We must preserve the name "langgraph-docs" but it's not in the text, so we don't include it. We translate the text inside <text>. No extra labels, no markdown, just the translation. The text: "Access LangGraph documentation to build stateful agents and multi-agent workflows. Fetches official LangGraph Python docs covering state machines, graph-based agent design, and human-in-the-loop patterns Prioritizes relevant documentation by query type: implementation guides for how-to questions, concept pages for theory, tutorials for end-to-end examples, and API references for technical details Automatically selects 2–4 most relevant documentation URLs and retrieves their content to answer..." We need to translate accurately, preserving technical terms like "LangGraph", "state machines", "graph-based agent design", "human-in-the-loop", "API references", etc. Also preserve numbers like "2–4". The ellipsis at the end should be kept. Let
official
langgraph-human-in-the-loop
langchain-ai
Mettre en pause l'exécution du graphe pour un examen, une approbation ou une validation humaine, puis reprendre avec leur saisie. Nécessite trois composants : un checkpoint (InMemorySaver ou PostgresSaver), un ID de thread dans la configuration, et des charges utiles d'interruption sérialisables en JSON. interrupt(value) met en pause et affiche les données ; Command(resume=value) reprend et renvoie cette valeur au nœud mis en pause. Tout le code avant interrupt() se réexécute lors de la reprise, donc les effets secondaires doivent être idempotents (utiliser upsert, pas insert). Prend en charge les workflows d'approbation,...
official
web-research
langchain-ai
Utilisez cette compétence pour les demandes liées à la recherche web ; elle fournit une approche structurée pour mener une recherche web
official
langchain-oss-primer
langchain-ai
Commencez TOUJOURS ICI pour tout projet de construction d’agent LangChain, Deep Agents ou LangGraph. Point de départ obligatoire avant de choisir d’autres compétences ou d’écrire quoi que ce soit…
official
skill-creator
langchain-ai
Guide pour créer des compétences efficaces qui étendent les capacités de l'agent avec des connaissances spécialisées, des flux de travail ou des intégrations d'outils. Utilisez cette compétence lorsque l'utilisateur…
official
social-media
langchain-ai
Rédige des publications pour les réseaux sociaux adaptées à chaque plateforme, avec un contenu basé sur des recherches et des images d’accompagnement générées. Prend en charge les posts LinkedIn (1 300 caractères, ton professionnel) et les fils Twitter/X (280 caractères par tweet, format 1/🧵). Nécessite de déléguer la recherche à un sous-agent avant la rédaction, puis de lire les résultats pour garantir l’exactitude et la pertinence. Génère automatiquement des images sociales accrocheuses via l’outil generate_social_image, avec des compositions audacieuses et à fort contraste optimisées pour les petits...
official
deep-agents-memory
langchain-ai
Backends mémoire et fichiers enfichables pour Deep Agents avec options de routage éphémère, persistante et hybride. Quatre types de backends : StateBackend (éphémère, limité à un thread), StoreBackend (persistant entre sessions), FilesystemBackend (accès disque réel pour développement local) et CompositeBackend (routage de différents chemins vers différents backends). FilesystemMiddleware fournit six outils d'opérations sur fichiers : ls, read_file, write_file, edit_file, glob, grep. CompositeBackend utilise la correspondance par préfixe le plus long pour router...
official
deep-agents-orchestration
langchain-ai
Orchestrer des sous-agents, planifier des tâches en plusieurs étapes et exiger l'approbation humaine pour les opérations sensibles. Déléguer le travail à des sous-agents spécialisés via l'outil de tâche ; les sous-agents personnalisés prennent en charge des ensembles d'outils et des invites système isolés, tandis que le sous-agent "généraliste" par défaut hérite de la configuration de l'agent principal. Planifier et suivre des workflows complexes avec write_todos, en organisant les tâches dans les états en attente, en cours et terminés ; nécessite un thread_id pour la persistance entre les invocations. Mettre en œuvre...
official