Quick answer#
OpenAI Agents API is a credible option for developers who want OpenAI to operate the Codex agent harness, but it is not a free hosted worker or a ready-made business application. Introduced in public beta on September 10, 2026, it manages the agent loop while you supply tools, data, application behavior and an execution environment.[9][10]
There is no additional Agents API fee, but model tokens, tool usage and OpenAI-hosted sandbox containers are separate cost components. Self-hosting the sandbox changes where tools run; it does not move the managed control plane into your infrastructure or make this API eligible for Zero Data Retention.[9][10][12]
- Best for: a development team embedding long-running, tool-using OpenAI agents in its own application.
- Avoid if: your requirement is zero retention, non-US data residency for this API, a fixed all-in bill, or a finished assistant requiring no application engineering.[10]
- Main caution: OpenAI confirmed hosted-container overbilling in September and marked the incident resolved. That is a real billing incident, not evidence that every normal idle session incurs the widely circulated complaint amount.[23]
- Strongest managed-harness alternative: evaluate Claude Managed Agents if you prefer a Claude-centered application; keep your own loop when orchestration control is the priority.
Verified October 7, 2026. This is a source-based review of the public beta, current documentation, prices, terms, releases and independent commentary. We did not run paid agent sessions, audit customer invoices or benchmark task performance.
What you are buying: the managed Codex harness, not just an SDK#
The Agents API hosts and maintains an agent harness that coordinates model calls, tools and context. The launch describes automatic compaction, tool search, programmatic tool calling and subagents. OpenAI calls the underlying Codex harness open source, while the managed service operates that harness for you.[9]
That differs from calling a model endpoint and writing the loop yourself. It also differs from installing an Agents SDK in your own process. The value proposition is avoiding part of the orchestration and infrastructure work, not removing the application owner's responsibility for authorization, output validation and business actions.[9][10]
OpenAI offers its hosted sandbox, self-hosted environments and partner execution options. Its overview defines an environment as an optional sandbox or computer where the agent accesses files, loads skills and runs commands. Match the environment to the capabilities your task actually needs.[9][10]
Choose the layer deliberately. The Bedrock Managed Agents review covers an AWS-hosted OpenAI harness with its own preview boundaries. Shared model lineage does not establish identical endpoints, features, billing or contractual coverage.
Pricing: no API surcharge, three separate cost components#
The current overview says model usage follows the selected model's API rates, OpenAI tools use their standard rates, and OpenAI-hosted sandboxes use standard container rates. That last charge belongs in the estimate even if the task contains very little text.[10]
The developer rate card currently lists these container prices per 20-minute session per container:
- 1 GB: $0.03.
- 4 GB: $0.12.
- 16 GB: $0.48.
- 64 GB: $1.92.[11]
The same page says eligible container sessions are billed by the minute with a five-minute minimum. We preserve both statements rather than assume that every Agents API session receives a particular billing unit or memory tier. The table is a rate reference, not enough information to reconstruct an arbitrary sandbox invoice.[11][12]
Illustrative container-only calculation: 1,000 listed 20-minute units at the 1 GB rate equal $30; at the 4 GB rate they equal $120. These are arithmetic examples, not a claim about default allocation, idle metering, task duration or how many billable units a real workload creates. Model and tool charges are additional.[11]
For model-cost context, the current standard short-context GPT-6 Astra row lists $10 input, $1 cached input, $12.50 cache writes and $50 output per million tokens. The long-context and faster-service rows differ. Do not silently price a long, fast-mode workload at the short-context standard rate.[11]
Web search is listed at $10 per 1,000 calls plus search-content tokens at the applicable model rates. Use only the tools your workflow actually supports and invokes; a general rate-card row is not proof that every tool works through every API surface.[11]
The agent cost worksheet is useful here: separate inference, tools, execution, external services and operator time before comparing a managed service with a self-hosted loop.
Hidden costs: a session's token counter is not its final invoice#
An agent can make multiple model calls to finish one request. OpenAI explicitly says to estimate the whole task, including root-agent and subagent work, retries, sandbox compute and third-party services. A high cached-input percentage is not the same thing as a high percentage saving on the total bill.[13]
The observability guide labels session and turn usage as best-effort: it may be null, change as accounting arrives, and is not a final bill. Missing usage does not mean zero usage. It also says those usage fields do not expose a separate cache-write count, preventing exact calculation for pricing where that distinction applies.[13]
That has a practical consequence for agencies quoting fixed-price work: do not mark the cost final merely because the session returned a token total. Keep a provisional task estimate and reconcile it against the provider's accounting. Record unsuccessful work and retries rather than averaging only accepted outputs.
Our recommended cost record includes the session ID, model, service tier, delegated work, external-tool charges, execution environment and cleanup request. That is a proposed accounting design, not a claim that the API supplies a complete dollar-denominated cost ledger.
Sandbox lifecycle: task completion is not cleanup#
OpenAI-hosted sandboxes receive keep-alives, including between turns. If activity and keep-alives stop for an hour, the sandbox can be deleted; the timeout is not configurable. This is not a promise that every completed task is automatically cleaned up exactly one hour later.[12]
The documented cleanup action is to delete the session when finished. Save needed outputs first. If deletion returns 409 while setup or execution finishes, the hosted-sandbox guide recommends waiting and retrying with a limit on attempts. Closing an event stream does not cancel the task.[12]
Session management distinguishes cancelling a turn from deleting the session. Deletion removes the API resource and can leave physical cleanup continuing asynchronously. Design the application to track completion, cancellation, output retention and cleanup as different states.[27]
This is why the agent monitoring guide matters more than an uptime ping. A useful operational check asks whether the result was accepted and whether resource cleanup was requested, not simply whether an HTTP connection succeeded.
Benefits and current release changes#
The strongest benefit is access to an operated harness with context management and parallel subagents, so a team can spend more time on its tools and workflow. The launch includes favorable customer testimonials, but those are vendor-selected accounts, not our independent benchmark or a performance guarantee.[9]
Current documentation should take precedence over launch-day summaries. OpenAI's September 29 changelog added computer use to the Agents API, describing an OpenAI-hosted browser with website access approvals and sign-in handled by the application. A review written before that change can understate the current scope.[14]
That additional capability also creates an application responsibility. Before allowing a browser or tool to submit changes, define the approval boundary and record which identity it uses. The MCP security checklist provides a useful starting point for least-privilege access and untrusted tool output; a hosted harness does not decide your business's acceptable authority for you.
Security, residency and the self-hosting boundary#
The current Agents API overview says data residency is supported only in the United States and Zero Data Retention is not supported. It explicitly states that choosing a self-hosted sandbox does not make the API ZDR-eligible. The service retains session state to continue work across turns.[10]
Those are procurement gates, not small implementation details. A requirement that prohibits provider-held session state cannot be satisfied merely by moving the shell to a private machine. Verify the specific service's eligibility rather than borrowing a compliance claim from a different OpenAI product.
The Services Agreement says OpenAI does not use Customer Content to develop or improve the services unless the customer explicitly agrees. That is a different question from retention, residency and access needed to provide the service. The agreement also makes the customer responsible for evaluating the accuracy and appropriateness of output.[15]
Our assessment: the managed service can be sensible for approved data and bounded tools, but “self-hosted execution” should not be marketed internally as an entirely self-hosted agent. Draw the data-flow boundary before signing off on it.
Complaints: the September container-overbilling incident#
OpenAI's status page confirms an investigation into higher-than-expected charges for OpenAI-hosted containers in the Agent API on September 18. Updates said it was reviewing affected usage, calculating refunds and applying mitigation. The incident was marked resolved on September 19.[23]
An independent Awaited.dev analysis traces the discussion to a Reddit user's reported $1,600 bill and separates that report from the confirmed incident. We could read that analysis and the primary status page; the original Reddit page presented a human-verification challenge in our browser. We therefore do not present the user's exact invoice or refund as independently verified.[17][23]
The important distinction is a confirmed metering defect versus ordinary pricing. It would be misleading to use that reported dollar total as the expected cost of keeping normal idle containers. It would also be misleading to omit the incident when reviewing billing risk. The status page confirms the problem and mitigation, but not a completed refund for each customer.[23]
Our recommendation is to preserve session records and reconcile unexpected charges promptly. A lifecycle cleanup policy is still good application design, but it should not be described as a proven customer-side fix for OpenAI's metering bug.
Company, refunds, cancellation and contractual limits#
This is OpenAI's developer API service, not a ChatGPT consumer subscription. Its Services Agreement applies to APIs and describes usage-based charges calculated by OpenAI. Fees are generally non-refundable except as required by law or specifically permitted; a minimum commitment can be non-cancellable under the same qualifications.[15]
For customers governed by that agreement, invoice disputes must be raised within 30 days of issuance while undisputed amounts are paid. Check your actual order form, reseller arrangement and governing agreement rather than assuming every billing channel follows the same process.[15]
The service-credit terms name OpenAI OpCo, LLC or its affiliates. Credits are generally non-refundable, non-transferable and expire one year after purchase or issuance unless otherwise specified. Stopping new agent sessions is not the same thing as obtaining a refund for unused credits.[16]
The announced September incident refunds are a specific remediation, not a new general money-back guarantee. The Services Agreement also excludes beta/evaluation features from a particular termination right triggered by materially reduced functionality. Budget migration and revalidation work while the product remains in beta.[15][23]
Advertising evidence: OpenAI brand activity is not Agents API proof#
Our earlier advertising scan contained creative ID CR03970978679999168513 under advertiser AR02788840342533701633, OpenAI OpCo, LLC. The current transparency page still identifies that advertiser, but did not establish that the creative promotes the Agents API. We classify it as brand-level evidence only.[30]
The exact-phrase Meta lookup returned mixed third-party keyword matches, including training advertisements. That is not proof that OpenAI sponsored those results or is currently advertising this exact API. No exact-product OpenAI Agents API campaign was verified in this review.[32]
There is no ad-spend, conversion or revenue inference here. The confirmed product offer comes from OpenAI's official announcement and current documentation, not from assuming that a large advertiser promotes every service it sells.[9][10]
Alternatives: choose control, an operated harness or a finished agent#
Our strongest like-for-like shortlist alternative is Claude Managed Agents for a Claude-centered application. Compare runtime billing, spend controls, retention and supported execution environments using the same representative task. Do not infer an interchangeable session API or identical model behavior.
For a broader Google Cloud application platform, the Gemini Enterprise Agent Platform review covers runtime, governance and component-specific preview restrictions. That is a wider platform decision, not simply a cheaper way to call an OpenAI model.
For an operator who wants to use an agent rather than build a customer-facing API product, Hermes is a different route. Its official documentation describes an open-source agent with memory and tools. It does not claim compatibility with OpenAI's managed session contract.[19]
Choose the Hermes install guide when owning the runtime and configuration is desirable. Consider managed Hermes access when server maintenance is the obstacle. FlyHermes markets managed access, but that is not equivalent to buying a developer orchestration API or enterprise retention guarantee.[20]
Decision checklist before expanding a pilot#
This proposed acceptance test has not been run for this review:
- Confirm beta access, supported model, allowed data and the exact execution environment.
- Define one representative task, maximum business authority, an acceptance criterion and a human approval step for consequential writes.
- Capture all model calls and delegated work that the API exposes; label estimated cost provisional until billing reconciliation.
- Test a tool failure, stream disconnect, cancelled turn and cleanup retry. Check whether any recovery repeats a business action.
- Save needed outputs outside disposable execution state, then request deletion and verify the API resource is gone.
- Reconcile tokens, tools and container charges. Investigate anomalies against your records and the provider's incident history.
Decision: use the Agents API when the operated Codex harness saves meaningful engineering work and its data and beta constraints fit. Keep your own loop when you need orchestration control; choose a finished agent when the real goal is completing work rather than developing an agent service.
Sources#
[9] https://openai.com/index/introducing-the-agents-api — https://openai.com/index/introducing-the-agents-api/ [10] https://developers.openai.com/api/docs/guides/agents-api/overview — Agents API | OpenAI API [11] https://developers.openai.com/api/docs/pricing — Pricing | OpenAI API [12] https://developers.openai.com/api/docs/guides/agents-api/environments/openai-hosted — OpenAI-hosted sandboxes [13] https://developers.openai.com/api/docs/guides/agents-api/observability — Observability and usage | OpenAI API [14] https://developers.openai.com/api/docs/changelog — Changelog | OpenAI API [15] https://openai.com/policies/services-agreement — https://openai.com/policies/services-agreement/ [16] https://openai.com/policies/service-credit-terms — https://openai.com/policies/service-credit-terms/ [17] https://awaited.dev/releases/agents-api-container-billing-bug — OpenAI confirms an Agents API container billing bug [19] https://hermes-agent.nousresearch.com/docs — Hermes Agent Documentation | Hermes Agent [20] https://www.flyhermes.ai — FlyHermes.ai — Your Hermes Assistant [23] https://status.openai.com/incidents/01M2VA7X37P1ASADSNZ1CG4N4D [27] https://developers.openai.com/api/docs/guides/agents-api/sessions/manage [30] https://adstransparency.google.com/advertiser/AR02788840342533701633/creative/CR03970978679999168513 — openai-ads [32] https://www.facebook.com/ads/library/?active_status=active&ad_type=all&country=ALL&q=OpenAI%20Agents%20API&search_type=keyword_unordered — openai-meta