Function calling in code
Define the order-status tool caller input contract
Page 2 hardens the boundary around the order-status function-calling assistant so bad inputs fail before the interesting algorithm runs.
1Learn the idea
Read
Define what may enter
The accepted input remains: chat messages, tool schema, and a fake order store. Keep parsing and normalization in functions that do not score, train, or call a model. That split lets a test fail the boundary without blaming the core logic. The user-facing decision stays: let the model request a read-only get_order_status tool, then answer from the tool result.
Read
Reject at the boundary
const tools=[{name:'get_order_status', args:['orderId']}];
function allow(name){ if(!tools.some(t=>t.name===name)) throw new Error('tool not allowlisted'); }
allow('get_order_status'); console.log('allowlist ok');
Expected evidence: tool allowlist ok. If the contract is silent on a bad value, later debugging will look like an algorithm bug when it is really a data bug.
Read
Keep transforms testable
Write one assertion for a neighboring valid input to the order-status tool caller so tightening the boundary does not over-reject. Document field names and types the way a teammate would need them on day two of function-calling-code—not as comments you plan to delete.
Read
Lab notebook: name the fields
List every field in orders map + tool schema for get_order_status and mark each as required, optional, or forbidden. Required fields must fail loudly when missing; optional fields need defaults you can quote in a test; forbidden fields (secrets, raw PII, path escapes) must never be accepted silently. This list is the contract for the order-status tool caller.
Add one sentence about encoding, units, or timezones if relevant to chat messages, tool schema, and a fake order store. Contracts that ignore units create “correct” programs that still ship wrong decisions when someone tries to let the model request a read-only get_order_status tool, then answer from the tool result.
Read
Worked judgment
Write the error string you want for the most likely bad input. Prefer ValueError('threshold out of range')-style messages over generic invalid input. The contract’s job is to make executing a hallucinated tool name, or answering status without a tool call harder to confuse with a model or algorithm bug later.
Read
Why this stage matters for the order-status tool caller
At the data contract stage for function-calling-code, the job is narrower than finishing a product demo. You are creating one progressive evidence piece about orders map + tool schema for get_order_status that later pages inherit without redefining success. Keep that fixture small enough to inspect by hand, keep outputs copy-pasteable as text, and refuse to narrate this baseline as if it were a production SLA: assistant that answers without tools on the same prompts.
For this page specifically, success looks like malformed inputs rejected with field-named errors while still centering the user decision to let the model request a read-only get_order_status tool, then answer from the tool result. If you cannot point to a file, command, or assertion that proves that for the order-status tool caller, stay on this page instead of advancing.
Glossary: tool · Glossary: structured output · Cheatsheet: production ops signals
Go deeper
Before you start
Why this matters
Invent one malformed input that the order-status function-calling assistant might accidentally accept. Predict the exception or rejection message. After you run the contract code, compare your prediction with the real failure text.
In the wild
See how this idea shows up as a product and a company — then come back to the lesson. Skills transfer across vendors.
Related lessons
Check your understanding
Page assessment
Answer from memory. Completion is saved from this evidence, not from opening the next page.
All responses are required.