> ## Documentation Index
> Fetch the complete documentation index at: https://silmaril.dev/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Vercel AI SDK

> Check model input and generated text before returning a Vercel AI SDK response.

## Prerequisites

Install and initialize the [TypeScript SDK](/docs/sdk/typescript#initialize). The example uses that client as `fw`.

## Wrap your model

Install compatible AI SDK and OpenAI provider packages. Set `OPENAI_API_KEY` in your service environment for the model provider.

```bash theme={"theme":"github-light-default"}
npm install ai@^6 @ai-sdk/openai@^3
```

Use middleware to check input, then classify the generated text before returning it. This example enforces both checks.

```typescript theme={"theme":"github-light-default"}
import { FirewallBlockedException, HookLabel } from "@silmaril-security/sdk"
import { wrapLanguageModel, generateText } from "ai"
import { openai } from "@ai-sdk/openai"

const model = wrapLanguageModel({
  model: openai("gpt-5.4"),
  middleware: fw.asMiddleware({ shadowMode: false, scanOutput: false }),
})

const response = await generateText({
  model,
  prompt: "Summarize the benefits of request validation.",
})

const result = await fw.classify(response.text, { hook: HookLabel.LLM_OUTPUT })
const blocked =
  result.prediction === "MALICIOUS" || result.governance?.action === "block"

if (blocked) {
  throw new FirewallBlockedException({
    score: result.score,
    threshold: result.threshold,
    promptText: response.text,
    hook: HookLabel.LLM_OUTPUT,
    result,
  })
}

console.log(response.text)
```

## Expected result

Allowed input reaches the model, and allowed output is returned only after classification. A blocked input or output throws `FirewallBlockedException`. Handle it at your application boundary and return a safe response. Let API and network failures follow your error policy. See [TypeScript errors](/docs/sdk/typescript#errors).

## Coverage

The middleware checks the latest user message or tool responses before each model call. With AI SDK 6, use the explicit output check above instead of relying on the middleware's `scanOutput` option.

This example protects generated text. Classify tool-call arguments before executing a tool. Streaming output must be buffered and classified before delivery if you need to prevent blocked content from reaching the caller.

Every protected call must use the wrapped model. For models routed through Vercel AI Gateway, use the [gateway guide](/docs/gateways/vercel).

[Vercel AI SDK documentation](https://ai-sdk.dev/docs)
