Skip to content

How Chao Uses Tools ​

Chao can use authorized Chainabit and connector capabilities while answering a message. Clients integrate with the observable contract: progress arrives through the session SSE stream, writes follow the session's approval mode, and every action remains scoped to the authenticated account and workspace.

Observable lifecycle ​

A tool-assisted turn may emit these public events:

EventMeaning
tool.startedA tool call began.
tool.progressOptional progress suitable for a transient status message.
tool.approval_requiredThe run is waiting for a user decision.
tool.approval_responseThe approval decision was recorded.
tool.completedThe tool call finished successfully.
tool.failedThe tool call failed. The payload contains a public error, not an internal exception.
tool.degradedThe capability completed with a documented limitation.
message.deltaIncremental assistant text.
message.completedThe assistant message is complete.
run.settlement.completedThe run's usage settlement is complete.

Treat events as an open set. Ignore unknown event types, deduplicate by event ID, and reconnect with Last-Event-ID. See SSE Streaming for the full transport contract.

text
tool.started
tool.completed
message.delta
message.completed
run.settlement.completed

Session modes and writes ​

The session mode controls how proposed writes are handled:

ModeWrite behavior
autoPermitted writes may execute without an approval pause. Policy can still require approval or block a tool.
approvalApproval-gated writes pause and emit tool.approval_required.
planProposed writes are collected as plan steps instead of being executed.

Update the mode through PATCH /ai/sessions/:sessionId. A mode never grants a capability: authentication, entitlement, workspace membership, and tool policy are still enforced.

Connector recovery ​

A connector call can pause with a structured requirement:

RequirementClient action
needs_connectionAsk the user to connect the requested service.
needs_reconnectAsk the user to repair the selected connection.
needs_connector_selectionAsk the user to choose an authorized connection.
needs_agent_attachmentAsk an authorized user to attach the connection to the agent.

Use the identifiers and actions returned by the API. Do not construct internal tool names, choose a different connection silently, or infer that a write succeeded. After the requirement is resolved, use the continuation contract returned with the run; repeated continuation requests are idempotent.

Approval decisions ​

Approve or reject a pending tool call with the run and tool-call identifiers from the event stream:

http
POST /api/v1/ai/runs/{runId}/tools/{toolCallId}/approve
POST /api/v1/ai/runs/{runId}/tools/{toolCallId}/reject
Authorization: Bearer YOUR_ACCESS_TOKEN
Content-Type: application/json

Approval applies only to that pending call. A successful approval response means the decision was recorded; continue reading the stream for the execution result.

Failure handling ​

  • A blocked tool is a policy outcome, not a signal to bypass the policy with another endpoint.
  • A failed tool does not necessarily fail the whole assistant run. Wait for the terminal run or message event.
  • A disconnected SSE client does not cancel the server-side run. Reconnect to observe it, or call the explicit cancel endpoint.
  • Do not display raw tool input or output unless the event contract marks it as public display data.

Built with purpose.