Skip to content

OpenAI Agents API Enters Public Beta: What the Managed Agent Service Does and Where It Stops

  Posted on 10 Sep, 2026
  Tech News
OpenAI Agents API Enters Public Beta: What the Managed Agent Service Does and Where It Stops

On September 10, 2026, OpenAI released a new Agents API in public beta. The OpenAI API changelog describes it as a way to build agents on a managed Codex harness, with OpenAI handling session orchestration, context compaction and recovery. On September 29, 2026, the changelog records a further addition: computer use, which lets an agent complete tasks in a browser that OpenAI hosts.

In plain terms, OpenAI is offering to run the machinery of an AI agent for you. Until now, a company that wanted an agent, meaning software that pursues a goal over many steps and uses tools along the way, had to build or assemble that machinery itself as part of its custom software development work.

This is a beta, and it comes with data handling limits that will rule it out for some US and UK businesses today. Here is what has been published, what is still unsettled, and how to think about it.

What OpenAI released

OpenAI's Agents API overview says the API gives an application access to the Codex harness through an OpenAI-managed service. Codex is OpenAI's coding agent; the "harness" is the control software around the model that keeps it working through a long task. Under this arrangement OpenAI manages sessions, orchestration, context compaction and recovery, while your application supplies the tools and chooses where the agent's work is executed.

The status matters. The changelog calls this a public beta, and the documentation refers to beta endpoints throughout. A beta interface can change, and we did not find a stated date for general availability on the pages we read.

How the Agents API is organized

The overview describes four building blocks. They are worth knowing because they will appear in any proposal a developer sends you.

  • Agent: the definition, covering the model, its instructions, and the tools and MCP servers it may use. MCP, the Model Context Protocol, is a standard way to connect a model to outside systems.
  • Environment: an optional sandbox or computer where the agent can read files and run commands.
  • Session: a persistent instance of the agent working on a task across many interactions.
  • Events and items: the inputs your application sends in and the outputs the agent produces.

According to the overview, the managed harness supports programmatic tool calling, MCP server connections, web search, running code and commands in a sandbox, and file editing. The API keeps session state, so work can continue across turns without your application rebuilding the conversation each time.

Where the agent runs, and what it costs

The documentation offers two choices of environment: a sandbox hosted by OpenAI, which OpenAI provisions and manages, or a self-hosted environment that you operate. On billing, the overview states that model usage is charged at the selected model's normal API rates, with OpenAI's built-in tools and hosted containers charged at their standard rates. We did not find a separate fee for the Agents API itself on the overview page, but confirm current pricing with OpenAI before you budget.

Because billing follows model usage, the cost of an agent depends heavily on how long it works and which model it uses. An agent that runs for forty steps on a top-tier model costs far more than a single chatbot reply. That makes step limits and spend limits part of the design, not an afterthought.

Computer use: an agent that operates a browser

The computer use guide describes a beta capability, added on September 29, 2026, in which the agent navigates websites and works with browser interfaces in an OpenAI-hosted browser. The guide's examples use the gpt-6-astra model. Typical uses named in the guide are testing, collecting information and operating applications that only offer a user interface.

OpenAI's own safety guidance here is notably cautious. The guide says the browser requires the user's approval before it accesses each new website origin, including public sites. It tells developers to treat website content as untrusted, since a web page cannot grant permission or override the user's instructions. Sign-in is supported with email addresses, passwords and verification codes, but not with passkeys or QR codes.

The guide also makes clear that approving a site is not the same as approving an action. If your application must guarantee a confirmation step before a purchase, a deletion or another consequential action, OpenAI's advice is to restrict the hosted browser to resources that cannot perform those actions.

The limits that decide whether you can use it

One sentence in the overview will settle the question for many organizations. It states that the Agents API currently supports data residency only in the United States and does not support Zero Data Retention, and that choosing a self-hosted sandbox does not change this.

For a UK business, or a US business serving European customers, that raises questions about international data transfers. For any business in a regulated sector such as healthcare or financial services, the lack of a zero-retention option may conflict with internal policy or customer contracts. This is general information and not legal advice; take the specifics to whoever handles data protection for your organization.

How this fits with OpenAI's other agent tools

OpenAI's agent lineup is in motion. The Assistants API was shut down on August 26, 2026, and Agent Builder is scheduled to shut down on November 30, 2026, according to OpenAI's deprecations page. As we read that page, the migration guidance for Agent Builder points to the Agents SDK or ChatGPT Workspace Agents. The new Agents API is a separate beta product, not the listed replacement for either.

The overview also mentions an AWS service, Bedrock Managed Agents, as being built on the Agents API. We have not verified details on the AWS side.

What this means for your business

This section is our interpretation, offered as guidance.

A managed agent service removes real engineering work. Keeping a long-running agent on track, trimming its memory as the task grows and recovering after a failure are hard problems, and renting a solution can shorten a project. The trade is dependence. Your agent's behavior is then shaped by a harness you do not control, on a beta interface, from a vendor that has shut down one agent product this year and scheduled another for shutdown.

It also does not remove the work that is specific to you. Someone still has to define which tools the agent can call, what permissions those tools carry, which actions need a human sign-off, how results are logged and how failures are handled. Those decisions determine whether an agent is safe to put in front of customers. Our earlier article on AI agents, chatbots and workflow automation explains when an agent is the right tool and when a simpler workflow does the job.

What to do next

If you are exploring agents, the Agents API is reasonable to prototype with now, using test data. Pick a contained internal task, such as triaging a shared inbox or checking a staging website after each release, give the agent narrow permissions, and measure cost per completed task.

Before any production use, settle three questions: whether US-only data residency and the absence of zero retention are acceptable for the data involved; where human approval is required; and how you would move the agent elsewhere if the beta changes. Keeping your tools behind your own API, and your prompts and business rules in your own code, makes that last question much easier to answer.

Conclusion

OpenAI's Agents API entered public beta on September 10, 2026, offering a managed harness for long-running agents, and gained a beta browser-based computer use tool on September 29, 2026. It is billed at model and tool rates, currently keeps data in the United States and does not support Zero Data Retention. It is worth a prototype, and it deserves a careful review before it carries production or personal data.

If you would like help deciding whether an agent fits a process in your business, or building a pilot with sensible guardrails, you can get in touch with Entrant Technologies.

Entrant Technologies
Post written by
Entrant Technologies is one of the leading web, software, iPhone & Android app development company which deliver robust results for great brands worldwide. We deliver software solutions that meet the customers and business expectations.
View all posts by Entrant Technologies →
Latest Blogs
 
A software budget can go wrong before any code is written, at the moment someone prices and schedules a system that nobody has fully described yet. The discovery phase exists to close that gap. It is ...
on 06 Oct, 2026 Read More
 
Most growing businesses end up running four or five separate systems: a CRM for sales, accounting software for invoices, an online store, and something for stock, fulfillment or scheduling. Each works ...
on 05 Oct, 2026 Read More
 
A demo of an AI feature almost always looks good. Someone types five sensible questions, the answers read well, and the room agrees it is ready. Then real customers arrive with misspelled, half-explai ...
on 05 Oct, 2026 Read More