Skip to content

feat(eve): introduce authorizeResponse hook, track authz state - #1370

Draft
benpankow wants to merge 1 commit into
ben/hitl-v2-approve-cancelfrom
ben/hitl-v2-runtime
Draft

feat(eve): introduce authorizeResponse hook, track authz state#1370
benpankow wants to merge 1 commit into
ben/hitl-v2-approve-cancelfrom
ben/hitl-v2-runtime

Conversation

@benpankow

@benpankow benpankow commented Jul 29, 2026

Copy link
Copy Markdown
Collaborator

Summary

Adds optional authorization for the person responding to a tool approval. A tool can now optionally define authorizeResponse to verify that the authenticated responder may approve this specific call:

import { defineTool } from "eve/tools";
import { always } from "eve/tools/approval";

export default defineTool({
  description: "Refund a charge.",
  inputSchema: refundSchema,
  approval: {
    policy: always(),
    // authz impl, may be omitted for current no-authz behavior
    async authorizeResponse({ request, responder, session, auth }) {
      const identity = await auth.getToken(billingApproverAuth);

      if (
        await canApproveRefund({
          identity,
          responder,
          request,
          session,
        })
      ) {
        return "allowed";
      }

      return {
        status: "rejected",
        safeReason: "You are not permitted to approve this refund.",
      };
    },
  },
  async execute(input) {
    return refund(input);
  },
});

The callback receives:

  • request: the stable approval request, tool call ID, tool name, and tool input;
  • responder: the identity produced by the authenticated channel ingress;
  • session: read-only session identity, initiator, turn, and parent lineage;
  • auth: access to getToken and requireAuth, which utilizes existing authorization flow

If the responder needs to sign in, eve parks the approval, emits authorization.required, resumes the same responder-bound attempt after callback, and runs the currently deployed authorizer again.

TokenResult now exposes the account represented by the credential:

interface TokenResult {
  token: string;
  expiresAt?: number;
  providerSubject?: string;
}

For example, a GitHub authorization provider would return the responder's GitHub user ID .

Durable state

This PR adds framework-owned session state, separate from conversation history, for approval authorization. This holds pending approvals, records for failing/timing out/approved HITL attempts, and a final record which includes the approving/cancelling actor.

Behavioral choices

  • Multiple responders can validate independently against the same request.
  • Duplicate clicks from one responder are idempotent.
  • The first approved candidate or authenticated Cancel settles atomically.
  • Settled responses wait until every approval in the original model step is terminal before tool execution/model continuation resumes.

This PR does not contain Slack presentation or public candidate/settlement events; those are layered in the following PR.

Depends on the Approve/Cancel protocol PR: #1385.

Validation

Validated as part of the consolidated stack with:

  • pnpm --filter eve typecheck
  • pnpm --filter eve test:unit
  • focused candidate, input-request, dynamic-tool, and tool-auth tests

@vercel

vercel Bot commented Jul 29, 2026

Copy link
Copy Markdown
Contributor

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
eve-docs Ready Ready Preview Jul 30, 2026 6:20pm
eve-docs-4759 Ready Ready Preview, v0 Jul 30, 2026 6:20pm

Comment thread packages/eve/src/harness/tool-loop.ts Outdated
Comment thread packages/eve/src/harness/approval-candidates.ts Outdated
@github-actions

github-actions Bot commented Jul 30, 2026

Copy link
Copy Markdown
Contributor

Bundle + Package Summary: apps/fixtures/weather-agent

Key takeaways

  • No notable deltas vs ben/hitl-v2-approve-cancel (ec8ad62).

Delta vs ben/hitl-v2-approve-cancel (ec8ad62)

Area Metric Baseline Current Delta
Package Packed tarball 7.62 MB 7.63 MB +7.0 kB ⚠️
Package Unpacked publish size 28.80 MB 28.83 MB +29.4 kB ⚠️
Package Installed footprint 91.28 MB 91.30 MB +29.4 kB ⚠️
Package Published files 2876 2882 +6
Package Installed files 6665 6671 +6
Runtime Unique function payloads 2 2 0
Runtime Total function bytes 16.81 MB 16.85 MB +40.9 kB ⚠️
Runtime Public routes 11 11 0
Changed function payloads vs ben/hitl-v2-approve-cancel (ec8ad62) (2)
Function Status Baseline Current Delta Route changes
functions/__server.func changed 8.41 MB 8.43 MB +20.4 kB ⚠️ none
functions/.well-known/workflow/v1/flow.func changed 8.41 MB 8.43 MB +20.4 kB ⚠️ none

eve init install

Metric Baseline Current Delta
Installed footprint 129.68 MB 129.71 MB +29.4 kB ⚠️
Installed packages 128 128 0
dependencies 4 4 0
devDependencies 2 2 0
Dependency package bytes 43.14 MB 43.17 MB +29.4 kB ⚠️
devDependency package bytes 5.04 MB 5.04 MB 0 B ➖
Build Metadata
  • Preset: vercel
  • Nitro: nitro@3.0.260610-beta
  • Output directory: apps/fixtures/weather-agent/.vercel/output
  • Build metadata timestamp: 2026-07-30T18:23:51.105Z
  • Route aliases: 11 public, 1 internal (12 total aliases)
  • Vercel routes in config: 14
  • Severity legend: 🔴 dominant/large, 🟠 notable, 🟡 watch, ⚪ small
Package Drill-Down

Package Details

  • Package: eve@0.28.0
  • Package directory: packages/eve
  • Tarball: 7.63 MB (eve-0.28.0.tgz)
  • Unpacked payload: 28.83 MB across 2882 published files
  • Installed footprint: 91.30 MB across 6671 installed files
  • Installed root package: 27.48 MB
  • Installed dependencies: 63.83 MB
  • Runtime dependencies: 2
  • Peer dependencies: 5 (4 optional)

Installed footprint is measured from an isolated temporary npm install of the packed tarball.

Heavy installed dependencies

  • eve: 27.48 MB (30.1%)
  • @rolldown/binding-linux-x64-gnu: 19.28 MB (21.1%)
  • @rolldown/binding-wasm32-wasi: 10.66 MB (11.7%)
  • @napi-rs/wasm-runtime: 6.56 MB (7.2%)
  • ai: 6.53 MB (7.2%)
Publish payload breakdown
Published file size
🔴 dist/src/compiled/shadcn-registry/index.js       [########################] 13.15 MB 45.6%
🟠 dist/src/compiled/experimental-ai-sdk-code-mo... [###.....................] 1.51 MB 5.2%
🟡 dist/src/compiled/@vercel/sandbox/index.js       [#.......................] 632.5 kB 2.2%
🟡 dist/src/compiled/_chunks/workflow/undici-DWL... [#.......................] 502.4 kB 1.7%
🟡 dist/src/compiled/@chat-adapter/slack/index.js   [#.......................] 440.5 kB 1.5%
🔴 Other published files                            [#######################.] 12.60 MB 43.7%
Installed footprint breakdown
Installed package size
🔴 eve                             [########################] 27.48 MB 30.1%
🔴 @rolldown/binding-linux-x64-gnu [#################.......] 19.28 MB 21.1%
🔴 @rolldown/binding-wasm32-wasi   [#########...............] 10.66 MB 11.7%
🔴 @napi-rs/wasm-runtime           [######..................] 6.56 MB 7.2%
🔴 ai                              [######..................] 6.53 MB 7.2%
🔴 zod                             [####....................] 5.07 MB 5.5%
🔴 Other installed packages        [##############..........] 15.73 MB 17.2%
Runtime dependencies (2)
Package Range Notes
nitro 3.0.260610-beta
undici 8.9.0
Peer dependencies (5)
Package Range Notes
@opentelemetry/api ^1.0.0 optional peer
ai catalog:
braintrust ^3.0.0 optional peer
just-bash ^3.0.0 optional peer
microsandbox ^0.5.0 optional peer
eve init install drill-down

eve init install details

  • Command: eve init my-agent
  • Package manager: npm
  • Installed footprint: 129.71 MB across 8539 installed files
  • Installed packages: 128 total (122 transitive-only)
  • dependencies: 4 direct packages totaling 43.17 MB
  • devDependencies: 2 direct packages totaling 5.04 MB
  • Other transitive package files: 81.50 MB

Installed footprint is measured from an isolated temporary eve init my-agent using the current packed eve tarball.

Heavy installed dependencies

  • @typescript/typescript-linux-x64: 27.95 MB (21.5%)
  • eve: 27.48 MB (21.2%)
  • @rolldown/binding-linux-x64-gnu: 19.28 MB (14.9%)
  • @rolldown/binding-wasm32-wasi: 10.66 MB (8.2%)
  • zod: 9.02 MB (7.0%)
Installed footprint breakdown
Installed package size
🔴 @typescript/typescript-linux-x64 [########################] 27.95 MB 21.5%
🔴 eve                              [########################] 27.48 MB 21.2%
🔴 @rolldown/binding-linux-x64-gnu  [#################.......] 19.28 MB 14.9%
🔴 @rolldown/binding-wasm32-wasi    [#########...............] 10.66 MB 8.2%
🔴 zod                              [########................] 9.02 MB 7.0%
🔴 @napi-rs/wasm-runtime            [######..................] 6.56 MB 5.1%
🔴 ai                               [######..................] 6.53 MB 5.0%
🔴 Other installed packages         [###################.....] 22.23 MB 17.1%
dependencies (4)
Package Range Installed size Share
@vercel/connect 0.4.2 135.8 kB 0.1%
ai ^7.0.38 6.53 MB 5.0%
eve file:eve-0.28.0.tgz 27.48 MB 21.2%
zod 4.4.3 9.02 MB 7.0%
devDependencies (2)
Package Range Installed size Share
@types/node 24.x 2.54 MB 2.0%
typescript 7.0.2 2.50 MB 1.9%
Function Drill-Down

Payload Size Graph

Unique function payload size and share of total
🔴 functions/.well-known/workflow/v1/flow.func     [########################] 8.43 MB 50.0%
🔴 functions/__server.func                         [########################] 8.43 MB 50.0%

Top Function Payloads

🟠 functions/.well-known/workflow/v1/flow.func • 1 public route • 8.43 MB
Metric Value
Public routes /.well-known/workflow/v1/flow
Runtime nodejs24.x
Handler index.mjs
Payload 8.43 MB
Function files 8.43 MB across 43 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 2.33 MB (27.6%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                       [########################] 2.33 MB 27.6%
🟠 _chunks/runtime-artifacts.mjs   [################........] 1.59 MB 18.9%
🟡 _libs/undici.mjs                [##########..............] 980.5 kB 11.6%
🟡 _chunks/sandbox.mjs             [########................] 768.8 kB 9.1%
🟡 _libs/@ai-sdk/gateway+[...].mjs [####....................] 432.8 kB 5.1%
🟠 Other bundled files             [########################] 2.32 MB 27.6%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x",
  "maxDuration": "max",
  "experimentalTriggers": [
    {
      "type": "queue/v2beta",
      "topic": "__eve776561746865722d6167656e74_wkf_workflow_*",
      "consumer": "default",
      "retryAfterSeconds": 5,
      "initialDelaySeconds": 0
    }
  ],
  "environment": {
    "WORKFLOW_PRECONDITION_GUARD": "1"
  }
}

🟠 functions/__server.func • 10 public routes, 1 internal alias • 8.43 MB
Metric Value
Public routes /
/eve/v1/callback/[token]
/eve/v1/connections/[name]/callback/[token]
/eve/v1/health
/eve/v1/info
/eve/v1/session
/eve/v1/session/[sessionId]
/eve/v1/session/[sessionId]/cancel
/eve/v1/session/[sessionId]/stream
/eve/v1/session/reset
Internal aliases /__server
Runtime nodejs24.x
Handler index.mjs
Payload 8.43 MB
Function files 8.43 MB across 43 files
Traced dependencies 0 B
Signal 🟠 Bundled file index.mjs is 2.33 MB (27.6%)

🟠 🔎 Dependency Analysis

📦 Bundled files:

Bundled file size
🟠 index.mjs                       [########################] 2.33 MB 27.6%
🟠 _chunks/runtime-artifacts.mjs   [################........] 1.59 MB 18.9%
🟡 _libs/undici.mjs                [##########..............] 980.5 kB 11.6%
🟡 _chunks/sandbox.mjs             [########................] 768.8 kB 9.1%
🟡 _libs/@ai-sdk/gateway+[...].mjs [####....................] 432.8 kB 5.1%
🟠 Other bundled files             [########################] 2.32 MB 27.6%

🧾 Vercel Config

{
  "handler": "index.mjs",
  "launcherType": "Nodejs",
  "shouldAddHelpers": false,
  "supportsResponseStreaming": true,
  "runtime": "nodejs24.x"
}

Build Timing: e2e/fixtures/agent-tools-sandbox

This is an informational timing measurement inside eve build, from preflight through publication. Output-size measurement and profile writing are excluded.

Build mode: deployable Vercel build with sandbox template prewarm included.

  • Build pipeline: 2.09 s -> 2.06 s (-30.6 ms) vs ben/hitl-v2-approve-cancel (ec8ad62).
  • Timing is informational: shared GitHub runners are too variable for a hard timing budget.
Detailed phase timings vs `ben/hitl-v2-approve-cancel (ec8ad62)`
Phase Baseline Current Delta
extension.check 11.2 ms 11.9 ms +0.7 ms
project.resolve 3.7 ms 1.4 ms -2.3 ms
workspace.create 1.4 ms 1.2 ms -0.2 ms
host.prepare 201.3 ms 179.7 ms -21.6 ms
vercel.service-prefix.resolve 2.2 ms 2.6 ms +0.4 ms
nitro.create 205.0 ms 213.8 ms +8.8 ms
sandbox.prewarm 331.7 ms 276.3 ms -55.4 ms
nitro.cache.prepare 0.3 ms 0.3 ms 0.0 ms
nitro.prepare 0.9 ms 0.9 ms 0.0 ms
nitro.public-assets 0.8 ms 0.9 ms +0.1 ms
nitro.prerender 0.6 ms 0.5 ms -0.1 ms
nitro.bundle 1.30 s 1.34 s +41.0 ms
nitro.cache.write 0.7 ms 0.5 ms -0.2 ms
vercel.workflow-function.materialize 23.6 ms 21.4 ms -2.2 ms
agent-summary.emit 0.5 ms 0.5 ms 0.0 ms
nitro.close 0.1 ms 0.1 ms 0.0 ms
output.publish 3.5 ms 3.7 ms +0.2 ms
workspace.remove 2.3 ms 2.4 ms +0.1 ms

Signed-off-by: benpankow <ben.pankow@vercel.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant