> Fetch clean Markdown by appending `.md` to any page URL under https://signalwire.com/docs or requesting it with the HTTP header `Accept: text/markdown`. The root index at https://signalwire.com/docs/llms.txt lists the available documentation indexes. # validateToolToken > Validate a per-tool HMAC token attached to a SWAIG function call. [define-tool]: /docs/server-sdks/reference/typescript/agents/agent-base/define-tool Validate a per-tool HMAC token attached to an incoming SWAIG function call. Returns `false` for unknown tools, short-circuits to `true` for tools registered with [`secure: false`][define-tool], and otherwise delegates to `SessionManager.validateToolToken`. Raw-dict descriptors (e.g. `DataMap` output) are always treated as secure. > **Note** > > Called automatically by the SWAIG dispatch path before a tool handler runs. > You rarely need to invoke it directly; it is exposed for custom dispatch logic > and test harnesses. ## **Parameters** **`functionName`** `string` — required Name of the SWAIG function the token was issued for. --- **`token`** `string` — required HMAC token to validate. Missing tokens on secure tools return `false`. --- **`callId`** `string` — required Call ID the token is bound to. Empty strings are forwarded unchanged and rejected by the underlying validator. --- ## **Returns** `boolean` -- `true` when the token is valid for the given function and call, or when the tool is registered as non-secure. > Validate a per-tool HMAC token attached to a SWAIG function call.