How do I secure AI agents in production?
Screen inbound text, gate tools and MCP before side effects, and treat observe-only hooks as a diary.
Read guideArcjet Learning Center
Short, framework-specific recipes for Eve, Mastra, Claude Agent SDK, OpenAI Agents SDK, LangGraph JS, LangChain Python, and the Vercel AI SDK.
How-tos are short recipes for one enforcement point in a specific agent framework. They assume you already know the threat model and need the helper that sits on this channel, connection, or tool. Eve screens inbound channel text and gates connections that have no local execute. Mastra screens messages in processors and denies unwrapped MCP, workspace, and toolset tools on beforeToolCall. Claude Agent SDK screens prompts on UserPromptSubmit and denies unwrapped built-ins on PreToolUse. OpenAI Agents screens text with a direct guard() before run() and wraps authored invoke. LangGraph JS screens before graph.invoke and denies MCP inside ToolNode. LangChain Python and the Vercel AI SDK wrap authored tools. Each recipe names the helper, the deny shape, and the control that is not a policy gate.
Read the matching framework security guide in AI Security first. Then open the recipe for the surface you are wiring: inbound text, a connection, an authored tool, or an unwrapped MCP or built-in tool.
Screen inbound text, gate tools and MCP before side effects, and treat observe-only hooks as a diary.
Read guideScreen Slack or GitHub bodies with guardInbound after the signature check, before the Eve agent starts.
Read guideSecure Eve MCP and OpenAPI connections with guardApproval() on the connection's approval field.
Read guideGate Mastra MCP, workspace, and toolset tools with guardHooks so beforeToolCall can deny.
Read guideScreen inbound prompts on guardHooks({ inbound }) via UserPromptSubmit. A DENY erases the prompt before the model sees it.
Read guideDeny Bash on PreToolUse with guardHooks.
Screen text with guard() before run(), wrap authored tools with guardTool, and leave hosted tools off the deny list.
Read guideScreen input with a direct guard() before run(). Native inputGuardrails are OpenAI tripwires, not Arcjet.
Read guideScreen before graph.invoke, wrap authored tools with guardTool, and wrap ToolNode in place for MCP.
Read guideWrap ToolNode with guardToolNode in place — MCP and unwrapped tools run inside it; graph hooks cannot stop them.
Read guideUse guard_action, guard_tool, or ArcjetMiddleware plus ToolPolicy. ArcjetCaptureHandler cannot deny.
Read guideWrap Vercel AI SDK tools with guardTool, pass run context through toolsContext, and guard app-invoked work.
Read guideneedsApproval, requireApproval, and interrupt() pause for a person. They are not a remote allow or deny.
Read guide