LangGraph human approval without keeping the provider key in the graph
Where interrupt() fits, where credentials remain, and how to route a LangGraph tool through Anlyon's hosted action boundary.
LangGraph interrupt() pauses the graph. It does not move credentials. If the tool executes a Stripe call using a key in the graph process, that key stays in the process after approval. Route the operation through an Anlyon hosted action to keep the provider secret outside that runtime.
LangGraph's interrupt documentation, checked October 1, 2026, explains checkpointing, thread IDs and resuming with Command. Code before the interrupt runs again when the node resumes. Keep external writes out of that replayed section, and persist a stable business-operation identity.
Split the two responsibilities
LangGraph: conversation, graph state, optional user confirmation
-> named Anlyon action, narrow agent credential, stable operation identity
-> Anlyon policy and human decision when required
-> Anlyon resolves provider credential and dispatches
-> graph reads the invocation status
Your graph can carry an Anlyon key with actions:invoke. It should not carry the provider secret or administrative permissions that let it redefine the action or approve itself. Configure the action and secret separately using an operator credential.
Integration sequence
- Create a hosted action in a test environment using the quickstart. Require approval on the action or through a matching policy.
- Generate the operation identity in trusted application code and persist it with the business request. Do not ask the model to invent a new key for each attempt.
- Let the graph's tool call
actions.invoke()and save the returned invocation ID. See the Python integration pattern. - If approval is pending, return a pending state to the application. A reviewer decides in Anlyon's console or authorized API. A LangGraph resume flag is not that decision.
- Read the same invocation after approval. Approval and provider completion are separate events. Report
running,unknown,deniedandexpiredhonestly instead of saying the operation succeeded.
You do not need two approval prompts for every operation. Use a conversational interrupt only when your application needs that interaction in addition to the hosted enforcement.
Restart and timeout behavior
If a worker restarts after dispatch, recover by reading the saved invocation. Repeating a template invocation with the same request and idempotency key returns the current recorded state while the invocation exists. It does not resend the operation. An unknown result needs reconciliation. Governed adapters have their own operation key and effect recovery contract.
Keep state and resume authorization on your server. A client-provided approved: true value is not an authenticated reviewer, and a checkpoint is not proof that the provider write occurred.
Scope and availability
Anlyon governs calls routed through its hosted executor. A tool with direct provider credentials can bypass that path. Early Beta Access is free within hard limits, and the governed Stripe adapter accepts a live or a test key.
Python integration · OpenAI Agents SDK example · Vercel AI SDK example · Current terms
Frequently asked questions
Does LangGraph interrupt() isolate my API credentials?
No. It pauses graph execution for external input. If your resumed tool calls the provider with a key in its runtime, the key remains there. To move provider credentials out, call a separate service that holds them and enforces the action policy.
Can I combine LangGraph interrupts with Anlyon approvals?
Yes. Use an interrupt for conversational confirmation and Anlyon's hosted policy for the decision on the external call. A graph resume value does not approve an Anlyon request. An authorized reviewer must decide it through Anlyon.
