Authorize a tool call with consent, an allowlist, and a replay-safe audit record before any side effect occurs.
Required APIdef authorize_tool_call(call, allowed_tools, sensitive_tools, consented, seen_ids):
return {'allowed': ..., 'reason': ..., 'audit': ...}BehaviorThink through the mechanism first if you want the extra reasoning step. It never blocks the editor.
authorize_tool_call({'id': '1', 'tool': 'search', 'args': {'q': 'x'}}, ['search'], ['delete'], False, [])approved calls carry a safe audit envelope
authorize_tool_call({'id': '2', 'tool': 'delete'}, ['delete'], ['delete'], False, [])['reason']sensitive actions require human authority
2 hidden edge tests run after the visible contract passes.
Run Tests to see the contract verdicts here.