OpenAI’s Agents SDK 0.23.0 adds opt-in Docker removal protection, tighter controls for agent tools and a substantial set of runtime and session changes. For developers building AI agents in Python, the release reaches into the unglamorous machinery that can make an agent safer to operate and easier to recover when something goes wrong.
OpenAI Watch analysis
What happened
The versioned release, dated 1 October, lists new features alongside fixes across sandboxing, sessions, realtime interactions, tracing and tool execution. Its release notes include several changes with direct implications for developers running agents and handling their state.
Our top picks
- Opt-in Docker removal protection
Developers can enable a guard against Docker workspace removal, adding a deliberate check before a destructive operation. - Agent-owned tool approvals
Function-tool approvals are now scoped to the agent that owns the tool, narrowing where an approval applies. - Bounded Realtime messages by default
Incoming WebSocket message size is capped by default, putting a limit on message size in realtime sessions. - Encrypted session-history safeguards
Session history now requires encrypted envelopes, and wrong-key operations preserve the encrypted SQLite history. - A configurable encrypted-history scan budget
Developers can set a scan budget for encrypted session history rather than relying on a fixed approach. - Tool-stream backlog limits
Agent tool streaming callback backlogs are bounded, addressing a potential source of accumulating work during runs. - More deliberate Realtime tool checks
Realtime tool output now passes through guardrails, extending checks into that interaction path. - More resilient handshakes and sessions
The release adds retries for pre-request WebSocket handshake failures and keeps Streamable HTTP sessions usable after a 5xx.
Why it matters
These changes are less about teaching an agent a new trick than improving the boundaries around what it can do and what happens when the plumbing misbehaves. Approval scope, workspace deletion, message limits and encrypted history are practical concerns for teams operating agents, not decorative extras for a changelog.
The notes describe changes to the SDK, not independent evidence of how they perform in production. Teams should check the details against their own workflows, especially before relying on new safeguards as a substitute for their existing controls.
Our read
This is a substantial, useful maintenance release with a clear theme: better-defined limits around agent tools, data and execution. The standout changes are the opt-in Docker protection and agent-scoped approvals. If you build with the SDK, review those alongside the session and Realtime changes before upgrading; the release offers real controls, but adopting them still takes a deliberate configuration choice.
What to watch
- How the new Docker removal protection is configured and which removal paths it covers.
- Whether teams enable and test the encrypted-history and approval-scope changes in existing workflows.
- Follow-on fixes or documentation that clarify the new Realtime limits and guardrails.
Discussion spark: Should agent safety controls such as tool-approval scope and workspace-removal protection be on by default, or should developers keep the final say?
Sources and evidence
- v0.23.0 (2 October 2026, 01:08 UTC)
OpenAI Watch is independently operated by WittyWires. It is not affiliated with, endorsed by, or operated by OpenAI.