SIGNAL
Tracking the global AI frontier — labs · research · agents · policy
Frontier Signal
Agents

OpenAI Agents SDK v0.23.0

OpenAI Agents SDK v0.23.0
Primary source github.com ↗

Published October 2, 2026 · Category: AI Agents

Overview

0.23.0 (2026-10-01)

Features

  • mcp: add configurable MCP listing page limits (#5133) (9a21ab1)
  • sandbox: add opt-in Docker removal protection (#5116) (ae5803f)
  • sandbox: allow configuring memory consolidation turns (#5135) (daa1bcb)
  • sessions: add an opt-in encrypted history scan budget (#5118) (a2fdb94)

Bug Fixes

  • avoid awaiting cleanup during coroutine closure (#5163) (719c4e7)
  • ci: update and group CodeQL actions together (#5262) (f76153c)
  • ci: validate release source before building distributions (#5220) (2747c1c)
  • core/extensions: respect sensitive trace capture for model metadata (#5129) (88b722d)
  • core: bound agent tool streaming callback backlogs (#5106) (f23da76)
  • core: isolate nested agent tool state across fresh runs (#5123) (46cc8d8)
  • core: preserve closed parent constraints in singleton allOf (#5131) (f010d18)
  • core: preserve guarded final outputs in agent tools (#5115) (f3a15f6)
  • core: preserve structured guardrail diagnostics and agent output during persistence (#5016) (51bcea7)
  • core: preserve tool identity during asynchronous enablement (#5136) (f2ae64c)
  • core: redact default tool failure details (#5112) (40956e0)
  • core: redact streaming task exception tracebacks (#5121) (c329e92)
  • core: reject silently discarded kwargs tool arguments (#5174) (a9b1ce7)
  • core: resolve tools after agent start hooks (#5124) (5237420)
  • core: restore nested agent tool state against the tool's own agent (#5142) (ad93f54)
  • core: retry pre-request WebSocket handshake failures (#4780) (265f16f)
  • core: scope function tool approvals to their owning agent (#5144) (de25d82)
  • core: select built-in shell and apply_patch tools by their own type (#4952) (eb68131)
  • core: serialize only traced fields in ModelSettings.to_traceable_dict (#5003) (57f0b38)
  • core: validate agent tool stream callbacks before execution (#5125) (fae72a4)
  • core: validate tool_use_behavior callback results (#5173) (5a2d63f)
  • deps-dev: bump coverage from 7.10.3 to 7.16.1 (#5152) (47c21ee)
  • deps-dev: bump cryptography from 50.0.0 to 50.0.1 (#5234) (e6c6806)
  • deps-dev: bump dapr from 1.16.0 to 1.18.3 (#5154) (e94309d)
  • deps-dev: bump pymongo from 4.16.0 to 4.18.1 (#5155) (971c5f3)
  • deps-dev: bump ruff from 0.9.2 to 0.16.8 (#5249) (9d2b318)
  • deps-dev: bump textual from 8.2.3 to 8.2.8 (#5248) (f2df6e4)
  • deps-dev: bump types-pynput from 1.8.1.20250809 to 1.8.1.20260712 (#5246) (582d048)
  • deps: bump actions/create-github-app-token from 2.2.2 to 3.2.0 (#5245) (e6467e2)
  • deps: bump anyio from 4.10.0 to 4.14.2 (#5091) (0910b46)
  • deps: bump astral-sh/setup-uv from 9.0.0 to 10.2.0 (#5252) (52aa07c)
  • deps: bump cbor2 from 5.9.0 to 6.1.4 (#5153) (34952bc)
  • deps: bump pyjwt from 2.13.0 to 2.15.0 (#5271) (dc81a17)
  • deps: bump runloop-api-client from 1.31.0 to 1.32.0 (#5156) (32edd3c)
  • deps: bump temporalio from 1.26.0 to 1.33.0 (#5233) (6b5bad7)
  • deps: bump the codeql group with 2 updates (#5273) (fffe955)
  • deps: bump urllib3 from 2.7.0 to 2.8.0 (#5256) (28e9f4f)
  • deps: update httpx2 requirement from >=2.12.0 to >=2.13.0 in /examples/realtime/twilio (#5147) (153b3f1)
  • deps: update httpx2 requirement from >=2.12.0 to >=2.13.0 in /examples/realtime/twilio_sip (#5151) (a62e594)
  • deps: update httpx2 requirement from >=2.13.0 to >=2.13.1 in /examples/realtime/twilio (#5266) (ed1145f)
  • deps: update httpx2 requirement from >=2.13.0 to >=2.13.1 in /examples/realtime/twilio_sip (#5269) (a5d7fd4)
  • deps: update httpx2 requirement in /examples/realtime/twilio (ed1145f)
  • deps: update httpx2 requirement in /examples/realtime/twilio_sip (a5d7fd4)
  • deps: update openai requirement from <4,>=3.17.0 to >=3.19.1,<4 in /examples/realtime/twilio_sip (#5270) (093e183)
  • deps: update openai requirement from <4,>=3.8.0 to >=3.17.0,<4 in /examples/realtime/twilio_sip (#5232) (5541111)
  • deps: update openai requirement in /examples/realtime/twilio_sip (093e183)
  • deps: update openai requirement in /examples/realtime/twilio_sip (5541111)
  • deps: update pyjwt requirement from >=2.13.0 to >=2.14.0 in /examples/realtime/twilio (#5149) (5ed5727)
  • deps: update pyjwt requirement from >=2.14.0 to >=2.15.0 in /examples/realtime/twilio (#5267) (0b60281)
  • deps: update pyjwt requirement in /examples/realtime/twilio (0b60281)
  • deps: update starlette requirement from >=1.6.0 to >=1.7.0 in /examples/realtime/twilio (#5265) (1e1cd73)
  • deps: update starlette requirement from >=1.6.0 to >=1.7.0 in /examples/realtime/twilio_sip (#5268) (36d7944)
  • deps: update starlette requirement in /examples/realtime/twilio (1e1cd73)
  • deps: update starlette requirement in /examples/realtime/twilio_sip (36d7944)
  • deps: update twilio requirement from <10,>=9 to >=9.11.1,<10 in /examples/realtime/twilio (#5148) (59d860f)
  • deps: update urllib3 requirement from >=2.7.0 to >=2.8.0 in /examples/realtime/twilio (#5231) (c513dd1)
  • deps: update urllib3 requirement in /examples/realtime/twilio (c513dd1)
  • deps: update uvicorn requirement from >=0.52.4 to >=0.53.0 in /examples/realtime/twilio_sip (#5150) (04e699f)
  • discard previous stream event aliases on model timeout (#5216) (de3b1d7)
  • escape terminal controls in result diagnostics (#5219) (e80737c)
  • examples: keep realtime debug error summaries payload-free (#5200) (e7d7097)
  • examples: keep Redis connection details out of diagnostics (#5205) (c2321d2)
  • examples: prevent auto-running the local Temporal shell workflow (#5218) (5b50815)
  • examples: restrict the Realtime demo to local bounded sessions (#5111) (4adad5e)
  • extensions: close owned event streams when runs fail (#5060) (d5abd9f)
  • extensions: honor run tracing policy in Codex command spans (#5138) (78e5b4d)
  • extensions: keep SQLite usage capture off the event loop (#4981) (8e338e5)
  • extensions: keep the current branch when a forced delete_branch fails (#5081) (165390c)
  • extensions: preserve filtered history during automatic compaction (#5103) (27625dd)
  • extensions: preserve subprocess errors for non-UTF8 stderr (#5186) (549fcee)
  • extensions: validate MongoDB session identifiers (#5104) (442469e)
  • keep the file when apply_patch does a case-only rename (#4890) (71306bf)
  • mcp: bind resumed MCP calls to their original recipients (#5119) (bd91ae6)
  • mcp: escape duplicate tool names in diagnostics (#5217) (fc4d832)
  • mcp: keep the Streamable HTTP session usable after a 5xx (#5061) (29aa40b)
  • mcp: preserve cache invalidation during refresh (#4807) (5e7afe4)
  • mcp: stop swallowing worker task cancellation (#5055) (c4c04b6)
  • memory: preserve encrypted SQLite history on wrong-key pops (#5083) (0f87da2)
  • memory: require encrypted envelopes for session history (#5204) (bb7cd2e)
  • migrate Vercel sandboxes to the owned provider client (#5255) (9706013)
  • normalize nullable Chat Completions token counts (#5238) (1ac6d82)
  • normalize nullable token counts in remaining provider paths (#5260) (1c5c275)
  • preserve completed tool results when resuming approvals (#5240) (872e2d6)
  • preserve function tool Annotated constraints (#5212) (ee9a12a)
  • preserve SDK error metadata after late tool timeouts (#5194) (160ed62)
  • preserve streamed cancellation and pending guardrail cleanup (#5224) (0d6b741)
  • realtime: bound incoming WebSocket message size by default (#5102) (5a80698)
  • realtime: end event iteration when session close starts (#5172) (f9108bd)
  • realtime: enforce Realtime tool output guardrails (#5127) (518b1f2)
  • realtime: name the agent whose turn ended in agent_end (#5073) (49660c5)
  • realtime: preserve heard audio during later responses (#5193) (86a13db)
  • realtime: redact exception details from Realtime tool error events (#5132) (a58d03c)
  • realtime: reset per-connection state on close (#5069) (a34b396)
  • redis: validate session keys before clearing (#5202) (b3d5c1d)
  • refresh encrypted session visibility before compaction (#5209) (92a2c60)
  • reject ambiguous canonical Docker removal paths (#5221) (0da7889)
  • reject premature Chat Completions stream EOF (#5211) (220e307)
  • responses: preserve terminal errors through stream cleanup (#5187) (2b0361d)
  • sandbox: add opt-in bounded workspace outbox reads (#5128) (465860b)
  • sandbox: bootstrap Docker workspace before removal binding (#5210) (f162205)
  • sandbox: check sandbox apply_patch approval scope (#5146) (d303ce8)
  • sandbox: enforce grants during recursive removal (#5206) (2f8c9ac)
  • sandbox: keep UnixLocal workspace-root removal off the event loop (#4941) (c467732)
  • sandbox: limit Darwin host PATH read grants to the child environment (#5139) (9316424)
  • sandbox: make Docker persist_workspace archives restorable by hydrate_workspace (#4834) (6492137)
  • sandbox: normalize UnixLocal snapshot special files and symlinks (#4831) (08e5c43)
  • sandbox: preserve multiline skill frontmatter descriptions (#5098) (9415f7e)
  • sandbox: preserve nested paths in workspace snapshots (#5189) (61e98ab)
  • sandbox: preserve symlink targets during snapshot restore (#5208) (00e2aa4)
  • sandbox: preserve UnixLocal hardlink snapshots and validate before clearing (#5188) (99f8d77)
  • sandbox: reject host sources in dictionary sandbox manifests (#5100) (a4fe85c)
  • sandbox: reject privileged storage with read-only host grants (#5117) (c641e39)
  • sandbox: reject special files in shared UnixLocal file I/O (#5177) (848ba47)
  • sandbox: scope exclusive Add File creation to UnixLocal (#4893) (ec8e836)
  • sandbox: validate host grants against normalized workspace roots (#5099) (91f5cfd)
  • schema: decode URI fragments before pointer traversal (#5272) (b64cad4)
  • sessions: accept namespaced compaction model names (#5225) (360d726)
  • sessions: add an optional compaction rollback item budget (#5137) (a264757)
  • sessions: close SQLiteSession connections owned by exited worker threads (#5090) (0b6fcd8)
  • sessions: match literal Unicode content in AdvancedSQLiteSession (#5143) (581863a)
  • sessions: recover fresh streamed handoffs after session append failures (#4835) (cd437f0)
  • sessions: recover handoffs after cancelled compaction (#5197) (802cc03)
  • sessions: reject blank SQLite branch names (#5179) (588826c)
  • sessions: reset compaction response chain on clear_session (#5000) (525cd20)
  • sessions: strip output-only metadata from compaction replay (#5196) (5cdcf84)
  • summarize verbose connector output (#5203) (8575b93)
  • tests: restore any_llm_model in sys.modules after stubbed imports (#5049) (65a9921)
  • tracing: keep the export batch when an item has values that aren't JSON serializable (#4984) (74461d0)
  • tracing: omit reasoning from default trace exports (#5108) (de0aa85)
  • tracing: preserve exporter overrides during shutdown (#5199) (4658a0e)
  • tracing: retry rate-limited trace exports (Fixes #5023) (#5052) (06298d5)
  • use gpt-transcribe as the default voice STT model (#5276) (430da63)
  • voice: finish streamed transcription on end of input (#5195) (c42f3c6)
  • voice: finish transcription iterators when sessions close during setup (#4995) (60ed116)
  • voice: honor pipeline tracing opt-out inside caller traces (#5120) (76547e5)
  • voice: preserve legacy positional config arguments (#5198) (5813d84)
  • voice: raise the builtin TimeoutError from _wait_for_event on 3.10 (#5075) (079b844)
  • voice: stop forcing the STT session logging header (#5114) (7fce7f6)

Source

Originally published at github.com.

Related Articles

F
Frontier Signal Desk

Frontier Signal tracks the global AI frontier — labs, research, agents, creation tools and real-world practice — straight from primary sources. Tip the desk: editorial@news.tunx.ai

Email the desk →
From our network: explore the AI assistant platform behind this site. Visit tunx.ai →
Note: This story is aggregated and summarized from the primary source linked above; the original publisher retains all rights. Details may evolve after publication — always confirm against the source. Nothing here is professional, legal or investment advice.

Related Stories

More from Agents →