LangChain and LangGraph
LangChain and LangGraph keep their chains, graphs, tools, callbacks, and memory.
DeepIntShield 2.8.3 binds their native OpenAI-compatible model clients to the
gateway. Select a configured provider with provider/model; the gateway owns
provider credentials and request translation.
Install and configure
Section titled “Install and configure”For LangChain model and embedding clients:
pip install "deepintshield[langchain]==2.8.3"export DEEPINTSHIELD_VIRTUAL_KEY="sk-ds-your-virtual-key"export DEEPINTSHIELD_BASE_URL="https://app.deepintshield.com"Use deepintshield[langgraph]==2.8.3 when your application also needs LangGraph.
Configure provider credentials on the gateway and permit the selected models on
your Virtual Key. The base URL above is the gateway origin.
Native model binding
Section titled “Native model binding”from deepintshield import DeepintShield
with DeepintShield.from_env() as shield: llm = shield.bind("langchain").model("anthropic/claude-sonnet-4-5") response = llm.invoke("Explain retrieval-augmented generation in one sentence.") print(response.content)shield.bind("langgraph") exposes the same .model() and .embedder() methods.
The returned model is a native langchain_openai.ChatOpenAI; reuse it in your
existing chains or graph nodes. Choose a model that supports the operation and
parameters you request. A provider-qualified ID may include deployment names,
version suffixes, or further slashes.
To use Responses with a supporting model and LangChain version:
llm = shield.bind("langchain").model( "openai/gpt-4o-mini", use_responses_api=True,)Framework-specific features outside the common OpenAI representation may need a native provider adapter and its matching gateway integration route. Common model binding does not make every provider support every tool, modality, or parameter.
Streaming and asynchronous calls
Section titled “Streaming and asynchronous calls”The model keeps LangChain’s native methods and response objects:
for chunk in llm.stream("Write a short welcome message."): print(chunk.content, end="", flush=True)In asynchronous code, use await llm.ainvoke(...) or iterate over
llm.astream(...) with async for. Keep the parent SDK client alive for the
application’s framework operations. Native clients and any custom HTTP clients
have their own lifecycle; manage the clients you construct independently.
Streaming guardrails inspect output incrementally. Content already delivered cannot be recalled; use nonstreaming inference or a buffering boundary if your application needs a complete output verdict before delivery. See streaming responses.
Embeddings and RAG
Section titled “Embeddings and RAG”embedder = shield.bind("langchain").embedder("cohere/embed-v4.0")vectors = embedder.embed_documents(["A document to index."])The binder returns native OpenAIEmbeddings and defaults
check_embedding_ctx_length=False, preserving raw text for the selected
provider’s tokenizer. Supplying your own embedding limits remains an application
choice. Select an embedding model; a chat model ID is not interchangeable.
Embedding routing does not filter retrieved documents or enforce a document’s access policy. Use the RAG helpers for explicit retrieval evaluation, filtering, and provenance where required.
Existing applications without the DeepIntShield package
Section titled “Existing applications without the DeepIntShield package”A native LangChain client can connect directly to the gateway:
import osfrom langchain_openai import ChatOpenAI
llm = ChatOpenAI( model="anthropic/claude-sonnet-4-5", base_url="https://app.deepintshield.com/v1", api_key=os.environ["DEEPINTSHIELD_VIRTUAL_KEY"],)print(llm.invoke("Hello!").content)Always supply the Virtual Key as the native client’s api_key; additional
headers alone do not satisfy a client’s constructor-level credential checks.
Native JavaScript clients use the same connection through
configuration.baseURL and their OpenAI API key setting.
Compatibility helper and provider-native routes
Section titled “Compatibility helper and provider-native routes”The existing shield.langchain(model=...) shortcut remains supported. It returns
ChatOpenAI pointed at /langchain, while shield.bind("langchain").model(...)
uses the common /openai connection. Both preserve provider-qualified model IDs.
The binder additionally supplies native embedding construction.
The /langchain compatibility prefix also exposes selected Anthropic, GenAI,
Bedrock, and Cohere wire formats. If you keep a provider-specific LangChain
class, configure its native authentication and endpoint options for that route
and verify its supported methods. Use the Anthropic,
GenAI, and
Bedrock guides for native protocol details.
Tools and Agentic governance
Section titled “Tools and Agentic governance”Changing the model endpoint routes inference through the gateway. LangChain or
LangGraph still executes application tools. A live DeepintShield client
installs the supported framework enforcement hooks; governed execution also
requires the workload’s Agentic identity, registration, and grants. These are
additional requirements beyond the inference connection variables.
Name the workload with agent_name or DEEPINTSHIELD_AGENT_NAME unless the
Virtual Key already resolves to a server-issued agent subject. Follow
Agents and Agentic governance for registration, approval,
and policy outcomes before enabling tool execution. Pass native .bind_tools(),
callbacks, and graph configuration through LangChain as usual; a model-generated
tool request is not authorization to execute the tool.
See providers and frameworks for all native binders and SDK error codes for direct SDK and governance failures.