# How do I verify LangChain actions with Provely?

> Connect LangChain to Provely through the MCP server, the CLI, the SDK, the REST API. The guidance files, the hooks, and the CI gate.

Canonical: https://provely.sh/agents/langchain  
Last reviewed: 2026-09-05  

**LangChain connects to Provely through the MCP server, the CLI, the SDK, the REST API. The agent does the action. Provely verifies the outcome and signs a receipt. LangChain never holds the verifier credentials.**

A person verified the LangChain capabilities on 2026-10-10. Agent products change monthly. Re-verify before you build.

Source: https://provely.sh/agents (retrieved 2026-10-10)

## Which surfaces does LangChain use?

| Surface | Support | Detail |
| --- | --- | --- |
| [MCP server](/docs/mcp) | Supported | transport stdio, http |
| [CLI](/docs/cli) | Supported | Runs through the shell tool of the agent. |
| [SDK](/docs/sdk) | Supported | languages python, typescript; adapter `langchain` |
| [REST API](/docs/api) | Supported | Any HTTP call reaches the control plane. |

## Which guidance files does LangChain read?

Provely ships one Agent Skill for this host, so the agent knows to verify an outcome before it claims done. The renderer writes prompt fragment from one source. A new agent needs a profile, not core code.

<details>
<summary>Explain: each file, its path and its write mode</summary>

| Format | Path | Mode |
| --- | --- | --- |
| prompt fragment | `provely/prompt-fragment.md` | fragment |
| CI gate workflow | `.provely/ci/github-actions.yml` | fragment |

</details>

## How is a false completion claim blocked?

Guidance asks. A hook and the CI gate enforce. A host with neither still receives the verdict, and a person reads it before the work ships.

<details>
<summary>Explain: what each control does on this host</summary>

| Enforcement | Support | Detail |
| --- | --- | --- |
| Advisory guidance | Supported | The instruction files state the rules for every agent. |
| Lifecycle hooks | Supported | `wrap_tool_call` |
| CI gate | Supported | `provely verify --wait` fails the pipeline unless the verdict is VERIFIED. |

</details>

## How do I connect LangChain?

### Connect LangChain to Provely

1. **Install the CLI.** Run `npx provely --version`, or download the static binary.
2. **Register the MCP server.** Add the Provely server. Use `provely mcp` for stdio, or the hosted HTTP server with a bearer token. The tools are `begin`, `verify`, `status`, and `receipt`.
3. **Write the guidance files.** Run `provely init --agent langchain`. It writes `provely/prompt-fragment.md` (fragment), `.provely/ci/github-actions.yml` (fragment). The guidance carries one rule: a successful tool call is not completion.
4. **Install the hooks.** Enable the `wrap_tool_call` hooks. A hook calls the CLI and blocks a completion claim while an operation is PENDING.
5. **Add the CI gate.** Run `provely verify --wait <duration>` in the pipeline. The step fails unless the verdict is VERIFIED. Exit codes: 0 VERIFIED, 2 PENDING, 3 FAILED, 4 CONTRADICTED, 5 UNVERIFIABLE, 1 error.
6. **Report the verdict exactly as returned.** VERIFIED: "The action is verified complete. Receipt: <id>." PENDING: "The action is accepted but not yet verified. Operation: <id>."

## What else does the profile state?

- Verified 2026-10-10: this repository ships the interception point. provelyMiddleware goes through createMiddleware of the langchain package, and then to createAgent. Source: examples/typescript/langchain/main.ts.
- The middleware uses wrap_tool_call, which can stop a tool call before it runs. before_model, after_model, before_agent, and after_agent cannot. Source: https://docs.langchain.com/oss/python/langchain/middleware/custom.
- The interception point is code, not a script. It blocks only after the application passes the middleware to createAgent. An application that never passes it gets advisory guidance and the CI gate.
- A LangChain 1.x agent runs on @langchain/langgraph. A project that builds the graph itself with StateGraph or createReactAgent renders the langgraph profile.

> LangChain keeps its action credentials, and no surface returns the verifier credentials to it. Read [the credential boundary](/docs/security). An operation outlives the session that opened it. Read [the API reference](/docs/api).

### Which host versions does the profile cover?

`>=1.0.0`. The integrations team last verified the profile with langchain 1.5.10 and @langchain/core 1.2.9 on 2026-10-10.

## Read next

- [Verify Claude Code actions](https://provely.sh/agents/claude-code)
- [Verify Codex actions](https://provely.sh/agents/codex)
- [Verify Anthropic Claude API actions](https://provely.sh/verify/anthropic)
- [See every agent integration](https://provely.sh/agents)
- [Read the MCP server reference](https://provely.sh/docs/mcp)
- [Read the credential boundary](https://provely.sh/docs/security)
