Skip to content
AITroveRead. Build. Understand.
Make this comfortable

Spring AI tools: authorize each requested action after model selection

Last updated: 1 Oct 20264 min read
tutorial
IntermediateBy AITrove Editorial

The model can request a tool call, but the application executes it and must validate identity, arguments and side effects.

Download Spring source kit

Keep identity outside model arguments

A model-supplied tenant ID is untrusted. Supply the verified principal through application-owned tool context, resolve the target receipt under that principal, validate the requested action, then call a service with replay and version checks. Do not expose a generic SQL or HTTP tool where a narrow read or reserve operation is enough. Versioned writes prevent stale updates after authorization.

Return a bounded result

A tool result becomes model input. Return only fields needed for the answer, cap rows and bytes, and redact credentials. Audit the tool name, caller and outcome before trusting the final model response. A failed tool call must not be represented as a successful reservation. The current source kit does not run Spring AI or a live model; test this path with a fake model and then with the selected provider.

Boundary sketch

Java
Receipt reserve(VerifiedPrincipal caller, String receiptId,
                int units, long expectedVersion, String replayKey) {
    requireScope(caller, "receipt.write");
    return receiptService.reserveForTenant(caller.tenantId(),
        receiptId, units, expectedVersion, replayKey);
}

Cost and verification

A model may request multiple tools in one call, multiplying database and token work. Cap tool iterations and per-tool fan-out before allowing write tools. This sketch is not executed by the current Spring source kit; verify it against the chosen dependencies and deployment.

Common Mistakes

  • Do not accept tenant identity from model-generated tool arguments.
  • Do not give the model a broad database or network capability by default.
  • Do not treat a tool-call request as proof that its side effect committed.

Read next

Spring AI prompt injection: treat retrieved text as data, not authority, Spring AI ChatClient request budgets: bound latency, tokens and work per caller, Spring JDBC versioned tenant update: inspect the affected row count, Spring POST idempotency keys: bind replay to tenant and command.

spring
spring-boot
spring-ai
ai-tool-authorization
Storage details