OPENAI DEVDAY 2026 · AGENTS API • 10 min read •

OpenAI Agents API: Codex's harness as a service

The OpenAI Agents API is Codex's harness sold as a service. OpenAI runs sessions, orchestration and context for you, and resumes the work after a failure. You supply the tools and choose where the agent runs code. The public beta opened on 10 September, and DevDay added computer use. An EU company should start with one line in the docs, though: US-only data residency, no Zero Data Retention.

OpenAI Agents API: the managed Codex harness, computer use in an OpenAI-hosted browser, the Decisions API on Luna and US-only data residency

The Agents API appeared in the DevDay 2026 announcements with a new feature, but the product is almost three weeks old. Below I split it into what the harness does for you and what stays on your plate. I have not run it yet, so this is based on OpenAI's and AWS's documentation.

I cover the models, Codex and ChatGPT for business in separate posts, and a round-up of every DevDay 2026 announcement in one place ties the series together.

What is the OpenAI Agents API?

The docs define it briefly: your application gets the Codex harness through an API that OpenAI manages. A harness is everything around the model: the loop that calls the model and tools, the context and the session. OpenAI hosts that Codex instance, and your agent's session lives in it. You provide tools and decide where the agent works.

There are three environment modes. With none, the agent has no computer, so no Bash and no files. With openai_hosted, OpenAI creates and maintains the sandbox. With self_hosted, your code starts the environment and connects it to the session: a laptop, a Docker container or an AWS Lambda function. Partners such as Cloudflare, E2B, Modal and Vercel also provide sandboxes.

What does the harness now do for you?

The agent runs commands and code in a sandbox, applies skills and instructions, and reaches data through tools or MCP servers. You can steer it while it works. When the context fills up, it summarises its earlier work. It splits a task, hands parts to subagents and resumes the session where it stopped.

Today each of those is code you maintain. The worst is usually a failure halfway through a task, when someone rebuilds the agent's state by hand. Here OpenAI does that. MCP servers are reached from OpenAI's infrastructure or from your environment, or run in the sandbox as a stdio process. Reusable credentials go in vaults.

Subagents take one configuration field. By default at most six run at once, not counting the coordinator, and they share one environment's files. They do not support function tools, so only the main agent calls your functions. Before you switch them on, check when splitting work across several agents pays off and when it multiplies the sources of error.

Computer use: what did 29 September add?

The agent gets a browser running in an OpenAI-hosted environment. You add the computer_use tool, pick the OpenAI sandbox and enable its desktop. The agent can then work on web pages in that browser.

Approvals need the most attention. Before the agent visits a new origin, the browser asks the user, public websites included. Network access alone approves nothing. But approving an origin does not enforce confirmation of each action. If the agent can reach a shop's admin panel, the API will not stop it before it clicks "Order". That gate is yours to build.

Your application handles sign-in, and only the main agent can request it. Email, password and verification codes work; passkeys and QR codes do not. What you type stays out of the model's input and the session history. OpenAI's recap lists the Pro 500 and Enterprise plans next to computer use. I read that as a condition for Codex and ChatGPT Work.

What stays yours, and what do you lock in?

The harness takes infrastructure off your hands, but the decisions stay with you. You decide which tools the agent uses, which sites it visits and when it must ask a human. You also write the tests that show whether it does the job well.

OpenAI's launch post quotes customers, such as SafetyKit's 60% lower cost per case. Those are customer numbers published by the vendor; only your own test suite on your data shows what it does for you. Monitoring is yours too. The API sends session webhooks and exports OTLP traces, and you decide what raises an alarm.

That leaves lock-in. Sessions, their configuration and history live at OpenAI. The loop is Codex, the model is billed at OpenAI's API rates, and although the harness code is public in openai/codex, one vendor runs the service. I have laid out five integration layers, from tool format to telemetry, that you rewrite when you change provider. The Agents API adds a sixth: session state.

How much does the Agents API cost?

OpenAI adds no fee for the API itself. You pay for tokens at your chosen model's rates, for OpenAI's tools at their standard rates, and for an OpenAI-hosted sandbox at container rates.

The smallest container, 1 GB, costs $0.03 per 20 minutes. The default sandbox has 2 vCPU and 4 GB, so the same 20 minutes cost $0.12. The largest, 16 GB, costs $0.48. Eligible sessions are billed per minute, with a five-minute minimum. There is no separate browser rate, so for now you see tokens and container time.

Can an EU company use the Agents API?

The docs are explicit. The Agents API supports data residency only in the United States and does not support Zero Data Retention. So the agent's configuration and session history sit with OpenAI in the US, and there is no mode in which OpenAI does not retain them. A self-hosted sandbox does not change that, because OpenAI's harness still runs the session.

For some Polish companies that settles it. If a data processing agreement, a security policy or a regulated client requires EU residency or zero retention, the Agents API is out for now. The fallback is your own harness on the regular API. Its Europe region (EEA and Switzerland) serves GPT-6.1 Sol, GPT-6 Sol and GPT-6 Luna. First, though, OpenAI has to approve your company for abuse monitoring controls, and you sign a retention amendment. Rates then go up by 10%. Either way, show that sentence to your data protection officer before any personal data goes in.

FOR AI ARCHITECTS AND CONSULTANTS

Designing or deploying agents for clients? In our collective of AI consultants you prepare for AI vendor partner certifications and learn with other consultants. When a suitable client brief arrives, we may invite you to a project.

What is the Decisions API?

In the Decisions API, GPT-6 Luna answers questions you define by picking from a closed list of answers. You supply context as text or images. The result helps you classify content, route a request or choose an agent's next step.

It is in limited preview, with a broad release planned in the coming days, and has no docs or price yet. OpenAI says a task takes 150 ms here, against 1.6 s through the regular GPT-6 Luna API. The chart does not say how that was measured, so I treat it as a vendor claim.

Choosing from a closed list is an old pattern. With three categories and a thousand labelled examples, a small trained model that costs next to nothing per call is often enough. Before you pay for the Decisions API, check when a classifier trained on your own labels beats a language model.

Bedrock Managed Agents: OpenAI's harness in AWS

The full name is Amazon Bedrock Managed Agents, powered by OpenAI. AWS announced it on 28 April 2026 as a limited preview and still labels it Preview. At DevDay OpenAI described it as the core of the Agents API adapted to AWS.

OpenAI's harness and the model run in Amazon Bedrock. AgentCore Runtime or your own infrastructure runs commands and tools, and access goes through AWS IAM. AWS says the agent runtime and model inference remain inside AWS. OpenAI says the agents run entirely in AWS and points to AWS's guidance on sessions, files and logs.

Can you run it in the EU? I found nothing on that from AWS. The tutorial shows only us-east-1, and the session runs where the runtime is. No price sheet either; the tutorial lists charges for the Runtime, CodeBuild and model calls. It suits a company already in AWS that wants the agent in its own account.

Newsletter

The Agentic Architect

Practical patterns, case studies and AI news. Zero spam, once a week.

You'll get one email to confirm. Unsubscribe with one click. Privacy policy

Agents API, your own harness or Bedrock?

OpenAI compares the three layers directly. The Agents API needs the least integration work, the Agents SDK keeps the loop in your application, and the Responses API needs the most work. Here is how I choose.

Agents API, your own harness or Bedrock Managed Agents
OptionPick it whenWatch out for
Agents API You want to ship a client agent with a sandbox, subagents and a browser quickly. Data may sit in the US, and ZDR is not required. Public beta. Data in the US only, no ZDR. Sessions and history at OpenAI.
Your own harness (Agents SDK, Responses API or another) Data requirements rule out the Agents API, or you want to control the loop and the choice of model yourself. You write and maintain sessions, context and failure recovery yourself. The EU region of OpenAI's API needs OpenAI's approval and costs 10% more.
Bedrock Managed Agents The company works in AWS and wants OpenAI's harness with the runtime and inference in AWS and access through IAM. Preview. Only us-east-1 in the tutorial. No price sheet for the service itself.

The same harness powers Codex. Want to see it working before you write an integration? Start with Codex in the cloud, where tasks start from an environment the whole team shares.

One task for this week. Take an agent you maintain yourself and write down how much of its code handles sessions, context, failures and subagents. Then ask your data protection officer whether that data may go to the US without ZDR. If yes, you have a pilot candidate. If not, stay with your own harness.

Sources and fact-check date

As of 29 September 2026.

Frequently asked questions

What is the OpenAI Agents API?

It is an API that gives your application the Codex harness, managed by OpenAI. OpenAI runs sessions, orchestration and context, and resumes the agent's work after a failure. You supply the tools and choose the environment: an OpenAI sandbox, your own, or none. The public beta has been open since 10 September 2026.

How much does the Agents API cost?

OpenAI charges no extra fee for the API itself. You pay for the chosen model's tokens, for tools at their standard rates and for the sandbox at container rates. The default 4 GB sandbox costs $0.12 per 20-minute session, and eligible sessions are billed per minute.

Does the Agents API support Zero Data Retention?

No. According to the docs, the Agents API supports data residency only in the US and does not support Zero Data Retention. A self-hosted sandbox does not change that. If a company requires data in the EU or zero retention, the Agents API does not meet that requirement today.

How does the Agents API differ from the Agents SDK and the Responses API?

In the Agents API OpenAI runs the agent loop, and sessions and their history stay on the service side. The Agents SDK runs inside your application, and you control the loop. The Responses API takes the most work, because you write the orchestration yourself, with optional help from OpenAI.

What is the Decisions API?

It is a new OpenAI API in which GPT-6 Luna picks an answer from a list you define. It is meant for classifying content, routing requests and choosing an agent's next step. It is in limited preview. As of 29 September 2026 there are no docs and no price.

Szymon Paluch

ex-CTO · Beta Impact Szymon Paluch, OpenAI Select Partner

Designing client agents on the Agents API?

The Certified AI Consultant Program is a collective of AI consultants. We prepare for AI vendors' partner certifications, today the Claude certifications through our partner organization, and we learn from each other. After a separate profile assessment you may be invited to a client project. Applying is free; you pay only after you are accepted.

See the program for AI consultants
Related posts
OpenAI DevDay 2026: Every Announcement and What It Means
OpenAI Dots: ChatGPT's always-on agents, and who can use them
ChatGPT Space, Pages, plugins: what DevDay 2026 changes at work