Skip to main content
Core

Custom Tools

Give an agent tools that run in your backend, with access to your APIs and secrets.

A custom tool is a function the model can call. It runs in the agent Actor on your worker, next to your server code, so it can use your APIs and secrets.

YOUR BACKENDAgent Actorget_ordercustom toolModel providerOrders APIAPI token

The model reads the tool’s description and calls it with arguments that match parameters. It reads content as the result, while details goes to clients for your UI. A thrown error, like the 404 in fetchOrder, becomes an error result: the model reads the message and can try something else. The signal argument aborts when the run is cancelled, so a Stop from the client also cancels the request.

Secrets

The orders API token stays in your backend. The tool reads it from the worker’s environment as ORDERS_API_TOKEN, and nothing else sees it:

Sees the token
Your tool codeYes, from process.env on the worker.
The modelNo. It sees the tool’s name, description, parameters, and results.
The session and connected clientsNo. They store and receive tool arguments and results.
The sandboxNo. Commands run with the sandbox’s own environment.

Tool results and error messages are stored in the session and sent to every connected client, so keep secrets out of both. For model keys, see LLM API Keys.

Custom tools work without a sandbox too. This agent has one, so the model can also use the built-in tools.

Next: Session Lifecycle, what happens while the agent answers a prompt.