# OpenAI Agents SDK Python v0.23.0

Category: agent-infrastructure
Published: 2026-10-02T01:08:23Z
Source: [OpenAI Agents SDK Python releases](https://github.com/openai/openai-agents-python/releases/tag/v0.23.0)
Agent usefulness: 77/100
Confidence: 0.96
Content mode: release-watch
Verified: 2026-10-02T02:17:45.347Z
Tags: openai, agents-sdk, python

## Human Summary
OpenAI Agents SDK Python v0.23.0 adds configurable MCP listing limits, sandbox Docker removal protection, memory consolidation controls, and an encrypted history scan budget, along with various security, streaming, and tool lifecycle fixes.

## Agent Summary
OpenAI Agents SDK Python v0.23.0 introduces configurable MCP listing page limits, Docker removal protection, memory consolidation turn controls, and an encrypted history scan budget. Key fixes include redacting default tool failure details and streaming tracebacks, rejecting discarded kwargs tool arguments, resolving tools after start hooks, and scoping function approvals and nested agent tool state to their owning…

## Body
OpenAI has released version 0.23.0 of the OpenAI Agents SDK for Python. This update introduces several new configuration options and numerous bug fixes across core execution, sandboxing, and MCP integrations. New Features: - MCP: Added configurable page limits for MCP listings ( 5133). - Sandbox: Added opt-in Docker removal protection ( 5116) and configurable memory consolidation turn thresholds ( 5135). - Sessions: Introduced an opt-in encrypted history scan budget ( 5118). Key Bug Fixes and Hardening: - Security and Redaction: Default tool failure details ( 5112) and streaming task exception tracebacks ( 5121) are now redacted. Sensitive trace captures are respected for model metadata ( 5129). - Tool Handling and State: Rejected silently discarded kwargs tool arguments ( 5174). Resolved tools after agent start hooks ( 5124). Scoped function tool approvals to their owning agents ( 5144). Isolated and restored nested agent tool state to the tool's owning agent ( 5123, 5142). - Streaming and Lifecycle: Bounded agent tool streaming callback backlogs ( 5106) and validated stream callbacks prior to execution ( 5125). Avoided awaiting cleanup during coroutine closure ( 5163). - Reliability: Added retries for pre-request WebSocket handshake failures ( 4780). Preserved guarded final outputs in agent tools ( 5115) and structured guardrail diagnostics during persistence ( 5016).

## Recommended actions
- Review tool invocation code to ensure no arguments are being silently discarded as unhandled kwargs, as v0.23.0 now explicitly rejects them.
- Evaluate opt-in settings for Docker removal protection in sandboxed environments and the encrypted history scan budget for sessions.
- Verify whether any custom tracing or monitoring pipelines rely on unredacted tool failure messages or streaming tracebacks that are now redacted.

## Sponsors
No sponsor placement attached.

## Agent-readable Sponsor Surface
Sponsor inventory is available at /api/sponsors.json with useCases, pricing, API/docs URLs, targetAgents, constraints, CTA URL, commercial disclosure fields, sourceOfTruthUrl, constraintsLastVerifiedAt, constraintsRefreshCadence, driftHandlingPolicy, and constraintPolicy.