The outcome

Produce validated application data and safe tool use within explicit request, token, call, timeout, retry, and concurrency budgets.

Pydantic AI is a Python agent framework for typed dependencies, validated tools and outputs, model portability, evaluation, observability, and durable execution. Building Python agents with strongly typed inputs, dependencies, tools, and outputs, then evaluating and running them with explicit token, request, tool, concurrency, and durability controls. This guide narrows that broad capability into one repeatable outcome, with checkpoints that keep the source material and your judgment in the loop.

Before you begin

Set the boundary before the tool starts.

Choose one real task, identify who will use the result, and decide what evidence or test will make the result acceptable. Gather only the source material needed for that task. If the work contains confidential, personal, regulated, or client-owned information, confirm that the platform and account are approved before sharing it.

Troiana principle

AI should make the work easier to inspect. If the workflow removes the source, the owner, or the review step, redesign the workflow.

Step by step

A workflow you can repeat.

  1. 01

    Define typed dependencies, input and output models, invariants, users, tenant scope, tools, permissions, model, quality, safety, budgets, timeouts, retries, and failure behavior.

  2. 02

    Create the agent with narrow instructions and output type, inject authenticated dependencies at runtime, and expose only tools that validate arguments and authorize against current server state.

  3. 03

    Apply usage limits for requests, input and output tokens, and tool calls plus tool timeouts and shared concurrency limits, keeping write operations idempotent and approval-gated.

  4. 04

    Test valid, malformed, adversarial, oversized, unauthorized, cross-tenant, looping, parallel-tool, timeout, provider-error, schema-retry, cancellation, and duplicate-write cases.

  5. 05

    Evaluate outputs and trajectories, inspect redacted traces and costs, pin models and dependencies, canary deployment, and retain a deterministic non-agent fallback for critical paths.

Working standard

What good use looks like.

  • Types constrain shape, not authority.
  • Set usage and concurrency limits.
  • Keep writes idempotent and approval-gated.

Pydantic validation confirms declared types and constraints, not factual correctness, permission, provenance, or harmless side effects. Model-generated tool calls remain untrusted. Enforce current user and tenant authorization inside tools, cap requests, tokens and calls, set timeouts and concurrency, use idempotency for writes, redact telemetry, test replay semantics, and account for integration-specific durability and retry limitations.

Official references

Check the current product documentation.

Features, plan limits, availability, and data controls change. These official pages are the starting points used for this collection.