iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Laravel AI SDK 1.0 can pause an agent before a selected tool runs, letting an application approve the proposed call, reject it, or edit its arguments. That decision concerns the tool invocation; it does not grant a user access to the conversation or restrict which records the tool can reach. Those protections remain application responsibilities.
What does tool approval decide?
A tool may implement Laravel’s Approvable interface and use the InteractsWithApprovals trait. When the agent reaches that tool, it can pause before execution. The application receives the pending tool and its proposed arguments, then supplies a decision: approve the call, reject it with a reason, or edit the arguments before allowing it to run. Laravel introduced this flow with AI SDK 1.0, announced September 23, 2026 (Laravel’s v1.0 announcement; Laravel 13.x AI SDK documentation).
Approval can be conditional rather than automatic for every invocation. A tool’s needsApproval method can decide based on the request; it can return a boolean or an Approval object with a reason. Agent configuration can also override the behavior with requireApproval() or withoutApproval(). Unless the application sets a default, each pending tool call needs a decision.
A rejected call may return a result to the model, allowing the generation to continue. If rejection has no result, Laravel stops the generation loop after recording the rejection. Approval handling is documented as compatible with prompting, streaming, queueing, and broadcasting.
#1 Best Overall
Does approving a tool approve the data it can access?
No. Approval answers whether a proposed invocation may proceed with its arguments. It does not certify the data returned, prove that the user is entitled to see it, or impose a safe query scope on the tool.
| Decision layer | Question it answers | Where to enforce it |
|---|---|---|
| Tool approval | May this proposed call run with these arguments? | Approval behavior and the application’s decision for the pending call |
| Conversation authorization | May this authenticated user access and resume this conversation? | Application authorization, such as a Laravel policy or Gate check |
| Data authorization and scope | Which records or resources may the tool read or change? | Tool implementation, query scope, tenant checks, and least-privilege design |
Laravel’s documented resume route makes the separation concrete: it calls Gate::authorize('view', $conversation) before continuing the conversation with approval decisions. The application must still enforce that access check; receiving an approval decision is not a substitute for it (Laravel 13.x AI SDK documentation).
The same principle applies inside each tool. If a search tool should only return a user’s own records, its query must enforce that scope. Laravel’s documentation illustrates a similarity-search query scoped by user_id; that restriction comes from the application’s query, not from the approval interface. Apply policies, tenant boundaries, record filters, and safeguards appropriate to each operation.
How should I require approval before a tool changes or deletes something?
- Identify the risky operation. Implement the tool as approvable and define when it needs a decision. Use a conditional
needsApprovalcheck when the request determines the risk, or configure the agent to require approval for that tool. - Pause and inspect the proposed call. Present the pending tool and its arguments to the decision-maker. Allow them to approve, reject with a reason, or correct the arguments before execution.
- Keep the tool’s own safeguards. Validate its inputs and enforce authorization and data scope when it runs. Do not treat an approved argument as proof that its target record is accessible or that the requested action is permitted.
- Authorize the conversation on resume. Load the conversation history and check that the authenticated user may view and continue that conversation before applying approval decisions. Laravel recommends a conversational agent or supplying history from the frontend so the paused turn can resume with its history.
- Handle every pending call deliberately. A turn can have more than one pending call, and each requires a decision unless the application has established a default. Define whether a rejection returns a result to the model or stops the generation loop.
What changes to conversation history in v1?
Earlier storage represented tool calls and results as separate flat lists, with replay state in meta. That could obscure which round-trip produced a result and blur the distinction between an unexecuted call and one awaiting approval. Version 1 stores ordered round-trips in a steps JSON column, associating each tool result with the call that produced it (Laravel’s v1.0 announcement; Laravel 13.x AI SDK documentation).
Rank #3
The steps also make call state easier to interpret. The current documentation describes accessors such as toolCalls, providerToolCalls, and toolResults as flattening steps in order. An approval reason without a result identifies a call waiting for approval; a call with a result has been executed. If a turn fails, completed steps remain. A call left without a result after failure is marked interrupted when the conversation resumes, because Laravel cannot determine whether it ran.
Do I need to change database queries when upgrading?
If custom raw SQL reads or writes the old tool_calls or tool_results storage, update it for the v1 steps structure. Laravel’s v1 announcement says the upgrade guide includes a backfill migration to run once before deployment. Review any code that depends on the old fields or assumes calls and results are separate ordered lists; the change affects storage semantics as well as column names (Laravel’s v1.0 announcement).
Rank #4
For a new installation, Laravel’s documentation shows composer require laravel/ai and publishing the SDK configuration and migration files with the provider’s Artisan command. The implementation details cited here are from the Laravel 13.x documentation. Laravel 13.x requires PHP 8.3 or later; these sources do not establish a complete compatibility matrix for every Laravel or PHP version (Laravel AI SDK documentation; Laravel 13 release notes).
Is AI SDK 1.0 only about tool approvals?
No. Approval is a consequential v1 feature, but Laravel describes the SDK as a broader provider-integrated toolkit. Its documented capabilities include agents and tools, structured output, embeddings, audio and image generation, reranking, files, and vector stores. The approval feature governs selected tool calls; it is not a general security layer for the rest of those capabilities (Laravel AI SDK documentation; Laravel 13 release notes).
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

