Prerequisites
Install and initialize the TypeScript SDK. The example uses that client asfw.
Wrap your model
Install compatible AI SDK and OpenAI provider packages. SetOPENAI_API_KEY in your service environment for the model provider.
Expected result
Allowed input reaches the model, and allowed output is returned only after classification. A blocked input or output throwsFirewallBlockedException. Handle it at your application boundary and return a safe response. Let API and network failures follow your error policy. See TypeScript errors.
Coverage
The middleware checks the latest user message or tool responses before each model call. With AI SDK 6, use the explicit output check above instead of relying on the middleware’sscanOutput option.
This example protects generated text. Classify tool-call arguments before executing a tool. Streaming output must be buffered and classified before delivery if you need to prevent blocked content from reaching the caller.
Every protected call must use the wrapped model. For models routed through Vercel AI Gateway, use the gateway guide.
Vercel AI SDK documentation