Skip to content
anavem.com

AI agent

OpenAI Agents SDK (Python)

Open-source Python SDK from OpenAI for multi-agent workflows with tools, handoffs, guardrails, sessions, human-in-the-loop, tracing, realtime and voice agents, and sandbox agents. It supports other model providers.

Maintainer
OpenAI (openai organisation on GitHub)
Licence
MIT (LICENSE file: "MIT License", Copyright (c) 2025 OpenAI)
Last release
v0.23.1, released 2026-10-02 (marked Latest on the GitHub releases page)
Last verified Jump to what it can access ↓

What it can access

An agent can take actions, not only answer questions, so what it is allowed to do on your behalf matters most. This is what the listing states, based on the sources below. Anavem does not rate it safe or unsafe: check it against what you plan to use it for.

Permissions it asks for

  • Tools let agents take actions; the docs list five categories: hosted OpenAI tools (execute on OpenAI servers), local/runtime execution tools (ComputerTool and ApplyPatchTool always run in your environment; ShellTool can run locally or in a hosted container), function tools, agents as tools, and an experimental Codex tool
  • Local ShellTool and ApplyPatchTool default to needs_approval=False, so the SDK can run your executor or editor without asking for approval (docs, tools page)
  • Sandbox agents can inspect files, run commands and apply patches in a workspace; supported clients named in the docs: UnixLocalSandboxClient, Docker, and hosted sandbox providers
  • The README lists MCP among the tool types (functions, MCP, hosted tools); guardrails and human-in-the-loop are listed as built-in mechanisms

Data it can reach

Docs state: the SDK runs in your Python application and needs the OPENAI_API_KEY environment variable for the OpenAI examples; it also supports the Chat Completions API and 100+ other LLMs. The tracing docs state tracing is enabled by default, traces are exported to the OpenAI backend by default, it can be turned off with OPENAI_AGENTS_DISABLE_TRACING=1, set_tracing_disabled(True) or RunConfig.tracing_disabled, and tracing is unavailable for organizations that use OpenAI's APIs under a Zero Data Retention (ZDR) policy. LLM inputs/outputs and function call inputs/outputs are stored in spans, and RunConfig.trace_include_sensitive_data (default True) controls whether that sensitive data is captured. With non-OpenAI models the docs say you can provide an OpenAI API key to the tracing exporter. The sandbox docs state UnixLocalSandboxClient adds no OS-level confinement on Linux and no network isolation on macOS, and recommend a Docker or hosted sandbox for untrusted commands. (README, openai.github.io docs, 2026-10-03)

How it is installed or connected

From the repository README (Python 3.10 or newer required), accessed 2026-10-03:

python -m venv .venv
source .venv/bin/activate  # On Windows: .venv\Scripts\activate
pip install openai-agents

With uv: uv init then uv add openai-agents. The README says to set the OPENAI_API_KEY environment variable before running the examples. Optional extras named in the README: openai-agents[voice], openai-agents[redis], and openai-agents[docker] for Docker sandboxes on Windows.

Limitations

  • SDK, not a hosted product: you write the agent code, host it and manage your own keys
  • The tools docs state SDK approval does not provide a sandbox; your implementation must enforce resource permissions and isolation for local tools
  • Tracing is enabled by default and exports to OpenAI; the tracing docs say it is unavailable under a Zero Data Retention policy and list ways to disable it
  • README: pull requests are limited to repository collaborators

Not sure what to look for? Read what to check before installing.

Quick answers

Who maintains this AI agent?
OpenAI (openai organisation on GitHub).
What can it access?
It asks for: Tools let agents take actions; the docs list five categories: hosted OpenAI tools (execute on OpenAI servers), local/runtime execution tools (ComputerTool and ApplyPatchTool always run in your environment; ShellTool can run locally or in a hosted container), function tools, agents as tools, and an experimental Codex tool, Local ShellTool and ApplyPatchTool default to needs_approval=False, so the SDK can run your executor or editor without asking for approval (docs, tools page), Sandbox agents can inspect files, run commands and apply patches in a workspace; supported clients named in the docs: UnixLocalSandboxClient, Docker, and hosted sandbox providers, The README lists MCP among the tool types (functions, MCP, hosted tools); guardrails and human-in-the-loop are listed as built-in mechanisms. Docs state: the SDK runs in your Python application and needs the OPENAI_API_KEY environment variable for the OpenAI examples; it also supports the Chat Completions API and 100+ other LLMs. The tracing docs state tracing is enabled by default, traces are exported to the OpenAI backend by default, it can be turned off with OPENAI_AGENTS_DISABLE_TRACING=1, set_tracing_disabled(True) or RunConfig.tracing_disabled, and tracing is unavailable for organizations that use OpenAI's APIs under a Zero Data Retention (ZDR) policy. LLM inputs/outputs and function call inputs/outputs are stored in spans, and RunConfig.trace_include_sensitive_data (default True) controls whether that sensitive data is captured. With non-OpenAI models the docs say you can provide an OpenAI API key to the tracing exporter. The sandbox docs state UnixLocalSandboxClient adds no OS-level confinement on Linux and no network isolation on macOS, and recommend a Docker or hosted sandbox for untrusted commands. (README, openai.github.io docs, 2026-10-03). We do not label anything safe or unsafe; read the official sources before you install.
What licence does it use?
MIT (LICENSE file: "MIT License", Copyright (c) 2025 OpenAI). Check the terms if you plan to use it commercially.
What are its limitations?
SDK, not a hosted product: you write the agent code, host it and manage your own keys. The tools docs state SDK approval does not provide a sandbox; your implementation must enforce resource permissions and isolation for local tools. Tracing is enabled by default and exports to OpenAI; the tracing docs say it is unavailable under a Zero Data Retention policy and list ways to disable it. README: pull requests are limited to repository collaborators.
When was it last released?
v0.23.1, released 2026-10-02 (marked Latest on the GitHub releases page). Verified Oct 3, 2026.

Sources

Other listings in the same category.

All AI agents →

AI tools in AI Automation & Agents

Verified tool profiles in the same category.

See category →