The outcome
Learn the interaction loop using a small task with a clear outcome.
Pydantic AI is a Python agent framework for typed dependencies, validated tools and outputs, model portability, evaluation, observability, and durable execution. Building Python agents with strongly typed inputs, dependencies, tools, and outputs, then evaluating and running them with explicit token, request, tool, concurrency, and durability controls. This guide narrows that broad capability into one repeatable outcome, with checkpoints that keep the source material and your judgment in the loop.
Before you begin
Set the boundary before the tool starts.
Choose one real task, identify who will use the result, and decide what evidence or test will make the result acceptable. Gather only the source material needed for that task. If the work contains confidential, personal, regulated, or client-owned information, confirm that the platform and account are approved before sharing it.
AI should make the work easier to inspect. If the workflow removes the source, the owner, or the review step, redesign the workflow.
Step by step
A workflow you can repeat.
- 01
Define the task, users, dependency and output types, data classification, model, tools, authorization, limits, retries, quality, safety, durability, observability, and rollback criteria.
- 02
Create one agent with narrow instructions, typed runtime dependencies, an explicit output model, and the smallest toolset, keeping provider keys and user authorization outside prompts.
- 03
Run representative and adversarial cases with token, request, tool-call, timeout, retry, and concurrency limits, validating both outputs and the tool-call trajectory.
- 04
Inspect evals and traces for correctness, unsafe actions, schema retries, loops, failures, privacy, latency, and cost, then pin versions and canary behind independent authorization and fallback.
Working standard
What good use looks like.
- State the outcome before the background.
- Provide the real source material.
- Review the result before expanding the task.
Pydantic validation confirms declared types and constraints, not factual correctness, permission, provenance, or harmless side effects. Model-generated tool calls remain untrusted. Enforce current user and tenant authorization inside tools, cap requests, tokens and calls, set timeouts and concurrency, use idempotency for writes, redact telemetry, test replay semantics, and account for integration-specific durability and retry limitations.
Official references
Check the current product documentation.
Features, plan limits, availability, and data controls change. These official pages are the starting points used for this collection.