Skip to content

Feature Request] Add NTI Callback Handler for Post-Quantum Agent Security #40927

Description

@abisheakp197

Submission checklist

  • This is a feature request, not a bug report or usage question.
  • I added a clear and descriptive title that summarizes the feature request.
  • I used the GitHub search to find a similar feature request and didn't find it.
  • I checked the LangChain documentation and API reference to see if this feature already exists.
  • This is not related to the langchain-community package.

Package (Required)

  • langchain
  • langchain-openai
  • langchain-anthropic
  • langchain-classic
  • langchain-core
  • langchain-model-profiles
  • langchain-tests
  • langchain-text-splitters
  • langchain-chroma
  • langchain-deepseek
  • langchain-exa
  • langchain-fireworks
  • langchain-groq
  • langchain-huggingface
  • langchain-mistralai
  • langchain-nomic
  • langchain-ollama
  • langchain-openrouter
  • langchain-perplexity
  • langchain-qdrant
  • langchain-typesafe
  • langchain-xai
  • Other / not sure / general

Feature Description

I would like LangChain to support a native, optional integration for NTI (Neutral Trust Infrastructure) as a security callback handler.

This feature would allow developers to enforce post-quantum cryptographic (PQC) signatures (Dilithium5/Kyber1024), zero-trust capability bounds, and BFT multi-agent consensus on agent tool executions before they happen. It provides an enterprise-grade, cryptographically verifiable security layer specifically designed for autonomous AI agents.

Use Case

As AI agents move from demos to production, they are increasingly executing real-world actions (e.g., financial transactions, modifying cloud infrastructure, accessing sensitive data). Current frameworks lack a standardized way to cryptographically verify an agent's identity and enforce strict policy bounds in real-time.

Without this, enterprises face significant security risks from prompt injection and unauthorized actions. This feature solves that by providing a drop-in callback handler that verifies Dilithium5 signatures and blocks unauthorized tool calls before execution. I need this because I am building NTI (ube-foundation) to secure agentic workflows, and a native LangChain integration would make it trivial for developers to adopt.

Proposed Solution

I have already prepared a PR that adds an NTICallbackHandler class to libs/langchain/langchain/callbacks/nti_callback.py.

It inherits from BaseCallbackHandler and overrides on_tool_start to build an ActionRequest, sign it using the ube-foundation PQC keypair, evaluate it against a TrustEngine, and raise a PermissionError if the policy decision is "Deny".

from langchain.callbacks.nti_callback import NTICallbackHandler
nti_handler = NTICallbackHandler(agent_id="finance_agent")
nti_handler.grant_capability("execute_transfer")
agent_executor = AgentExecutor(agent=agent, tools=tools, callbacks=[nti_handler])

### Alternatives Considered


Developers currently have to build custom security wrappers from scratch. This is error-prone, lacks enterprise-grade cryptography (like NIST PQC standards), and doesn't integrate natively with LangChain's callback system. Manual checks inside each tool function are messy and hard to maintain.

### Additional Context

The `ube-foundation` package is already available on PyPI (`pip install ube-foundation`) and crates.io. 

I have already prepared a PR for this integration and will link it below once this issue is created. 

Repository: https://github.com/abisheakp197/Neutral-Trust-Infrastructure

### Social handles (optional)

_No response_

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    externalfeature requestRequest for an enhancement / additional functionalitylangchain`langchain` package issues & PRs

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions