Typed Python agent framework

How to use
Pydantic AI.

Building Python agents with strongly typed inputs, dependencies, tools, and outputs, then evaluating and running them with explicit token, request, tool, concurrency, and durability controls.

What it isPython agent framework for typed dependencies, validated tools and outputs, model portability, evaluation, observability, and durable execution Workflows2 UpdatedJuly 2026

Pydantic AI is a Python agent framework for typed dependencies, validated tools and outputs, model portability, evaluation, observability, and durable execution. Building Python agents with strongly typed inputs, dependencies, tools, and outputs, then evaluating and running them with explicit token, request, tool, concurrency, and durability controls. This guide covers the whole path in one place: official access, a first session that produces something reviewable, the checks that make output trustworthy, and the permissions worth limiting before you connect real work.

Troiana principle

AI should make the work easier to inspect. If the workflow removes the source, the owner, or the review step, redesign the workflow.

01

Access & setup

Find, install, and sign in to Pydantic AI

Get into the official Pydantic AI experience with the right account and a setup you understand.

  1. 01

    Start at https://pydantic.dev/ai/ and confirm the domain before entering account or payment information.

  2. 02

    Availability: Pydantic AI is installed as a Python package and used in code, tests, services, and supported durable-execution systems rather than through a standalone desktop app.

  3. 03

    A supported Python environment, model-provider credentials, typed application dependencies, secure tools and secrets, usage and concurrency limits, representative eval datasets, and production telemetry and recovery ownership.

  4. 04

    Sign in with the account you intend to keep using, then review plan, data, notification, and permission settings.

  5. 05

    Run one low-risk test task before connecting sensitive files, repositories, or workspace data.

  • Use official download pages.
  • Review permissions during setup.
  • Keep installers and applications updated.
02

First session

Your first useful Pydantic AI session

Learn the interaction loop using a small task with a clear outcome.

  1. 01

    Define the task, users, dependency and output types, data classification, model, tools, authorization, limits, retries, quality, safety, durability, observability, and rollback criteria.

  2. 02

    Create one agent with narrow instructions, typed runtime dependencies, an explicit output model, and the smallest toolset, keeping provider keys and user authorization outside prompts.

  3. 03

    Run representative and adversarial cases with token, request, tool-call, timeout, retry, and concurrency limits, validating both outputs and the tool-call trajectory.

  4. 04

    Inspect evals and traces for correctness, unsafe actions, schema retries, loops, failures, privacy, latency, and cost, then pin versions and canary behind independent authorization and fallback.

  • State the outcome before the background.
  • Provide the real source material.
  • Review the result before expanding the task.
03

Quality control

Check the quality of Pydantic AI output

Establish that an autonomous run did the right thing, not merely that it finished.

  1. 01

    Define what the run should achieve and what it must never touch before granting it a single tool.

  2. 02

    Read the full execution trace: which tools were called, with what arguments, and in what order.

  3. 03

    Verify the side effects directly in the target system rather than trusting the agent's own report of success.

  4. 04

    Confirm failures surfaced as failures — a silent retry loop or a swallowed error is more dangerous than a crash.

  5. 05

    Re-run the same task and compare: an agent that behaves differently across identical runs is not yet production-ready.

  • Verify side effects in the system of record, not in the agent's summary.
  • Require human approval for any irreversible or outward-facing action.
  • Log every tool call so a run can be reconstructed afterwards.
04

Privacy & permissions

Use Pydantic AI safely

Bound what an autonomous system can reach before you let it run unattended.

  1. 01

    Enumerate every tool, credential, and system the agent can reach, and remove the ones it does not need.

  2. 02

    Require explicit human approval for irreversible actions: sending, publishing, paying, deleting, or deploying.

  3. 03

    Run against non-production data until behaviour is predictable across repeated runs.

  4. 04

    Set hard limits on spend, iterations, and runtime so a failure loop cannot run unbounded.

  5. 05

    Treat anything the agent reads from the web or a document as data, never as instructions it may follow.

  • Pydantic validation confirms declared types and constraints, not factual correctness, permission, provenance, or harmless side effects. Model-generated tool calls remain untrusted. Enforce current user and tenant authorization inside tools, cap requests, tokens and calls, set timeouts and concurrency, use idempotency for writes, redact telemetry, test replay semantics, and account for integration-specific durability and retry limitations.
  • Follow your organisation's approved-use policy.
  • Never treat fluent output as authorization to act.
05

Core workflows

Step-by-step ways to use Pydantic AI for the work it does best.

Each workflow is a separate guide with its own steps and review checkpoints.

06

Official references

Check the current product documentation.

Features, plan limits, availability, and data controls change. These official pages are the starting points used for this guide.

Explore the Troiana AI Hub →