5 min read
SDKs and automation
Use Leash with OpenAI, Anthropic, Vercel AI SDK, LangChain and CI.
On this page
Keep your application's SDK
Run your application with leash run. It supplies session-specific OPENAI_BASE_URL or ANTHROPIC_BASE_URL and LEASH_LOCAL_TOKEN. Set x-leash-local-token and disable SDK retries so deliberate blocks are immediately visible. Import provider credentials into the local vault once, or use your authorized environment.
OpenAI
import OpenAI from "openai";
const client = new OpenAI({ apiKey: process.env.OPENAI_API_KEY,
baseURL: process.env.OPENAI_BASE_URL,
defaultHeaders: { "x-leash-local-token": process.env.LEASH_LOCAL_TOKEN },
maxRetries: 0 });
await client.chat.completions.create({ model: "gpt-4o", max_tokens: 100,
messages: [{ role: "user", content: "Say hello" }] });Anthropic
import Anthropic from "@anthropic-ai/sdk";
const client = new Anthropic({ apiKey: process.env.ANTHROPIC_API_KEY,
baseURL: process.env.ANTHROPIC_BASE_URL,
defaultHeaders: { "x-leash-local-token": process.env.LEASH_LOCAL_TOKEN },
maxRetries: 0 });
await client.messages.create({ model: "claude-sonnet-4-20250514",
max_tokens: 100, messages: [{ role: "user", content: "Say hello" }] });Vercel AI SDK
import { createOpenAI } from "@ai-sdk/openai";
import { generateText } from "ai";
const provider = createOpenAI({ apiKey: process.env.OPENAI_API_KEY,
baseURL: process.env.OPENAI_BASE_URL,
headers: { "x-leash-local-token": process.env.LEASH_LOCAL_TOKEN } });
await generateText({ model: provider.chat("gpt-4o"), prompt: "Say hello",
maxOutputTokens: 100, maxRetries: 0 });LangChain JavaScript
import { ChatOpenAI } from "@langchain/openai";
const model = new ChatOpenAI({ model: "gpt-4o", maxTokens: 100, maxRetries: 0,
configuration: { baseURL: process.env.OPENAI_BASE_URL,
defaultHeaders: { "x-leash-local-token": process.env.LEASH_LOCAL_TOKEN } } });
await model.invoke("Say hello");Protect CI agent calls
Install the verified proprietary CLI archive supplied by your deployment into a private runner prefix using the quickstart. Customer CI does not need Leash source or a database owner URL. Never give provider credentials to untrusted pull-request code.
- name: Run protected agent
env:
OPENAI_API_KEY: ${{ secrets.OPENAI_API_KEY }}
LEASH_HOME: ${{ runner.temp }}/leash-state
LEASH_OFFLINE: "1"
run: leash run --cap 5 -- node ./your-agent.mjs
- name: Export audit
if: always()
env:
LEASH_HOME: ${{ runner.temp }}/leash-state
run: leash status --json > leash-status.jsonSomething unclear?Help us improve this guide