OpenAI Agents Python conditional approval and Sume dry_run
Openai-agents-python v0.22.3 aligns conditional approvals with validated tool arguments. For Sume tools, base the check on tools_schema and dry_run.

The v0.22.3 release of openai-agents-python lists a fix to "align conditional approvals with validated tool arguments". For Sume tools the practical rule is the same: decide whether to ask a human using the arguments the tool contract accepts, and use dry_run to get the cost before the question is asked.
The release notes only give the one-line title of that fix (PR 5066), so this post does not describe how the SDK implements it. The Sume side is from MCP tools and gates, read 2026-10-01.
What does the v0.22.3 release say?
Under "What's Changed" the first entry is "fix(core): align conditional approvals with validated tool arguments". That is the whole description in the notes. If your approval predicate runs on tool arguments, read the linked pull request before relying on a specific behavior.
Which Sume fields should a conditional approval read?
Sume publishes one contract per tool through tools_schema (fetch by name), so a predicate can be written against the same fields the server validates. The gates that matter for a paid call are below.
| Field or tool | What the docs say |
|---|---|
tools_schema | Fetch one tool contract by name. |
idempotency_key | Required on write and paid tools; stable key for transport and dedup, not human approval. |
dry_run=true | Optional admission and cost preview only; the job is not submitted. |
max_spend_usd | Optional; enforced only when provided. |
Does idempotency_key count as approval?
No. The docs describe it as a key for transport and dedup, not human approval. An approval step in your agent is a separate decision, and the key should be a stable value you generate once per intended create so a retry does not become a second paid job.
How do I show a cost before asking?
Call the create tool with dry_run=true first. It returns an admission and cost preview without submitting. The docs also say to prefer generation_admission_preview and/or dry_run before expensive bursts, and that ordinary single creates do not need that extra step. So a reasonable condition is: ask only when the call is a paid write and you are about to fan out several of them.
For the broader approval pattern, see OpenAI Agents SDK `require_approval` for Sume write tools.
What should I do after upgrading?
Re-run any approval tests that pass arguments the model might get wrong, such as a missing field or a wrong type. Check that the predicate sees the arguments in the shape the schema defines, and keep the idempotency_key out of the decision so retries behave the same as first attempts.
Sources
Related posts
More in Integrations
- Snapchat Ads MCP and hosted Sume tools in one agent
Snap's Ads MCP server answers campaign questions and is read-only at launch. Add Sume's hosted MCP in the same agent to turn the findings into creative.
- Tavus PAL MCP connectors vs Sume hosted MCP tools and gates
Tavus MCP connectors let a PAL call third-party MCP servers. Here is what Sume's hosted MCP at mcp.sume.com exposes and the gates a paid call needs.
- VS Code 1.140 session authorization server: what Sume issues
VS Code 1.140 proposes a field naming the authorization server behind a session. For Sume, that server is the MCP origin, mcp.sume.com.
- How to add an MCP server to ChatGPT with developer mode
Turn on ChatGPT developer mode, create an app for the server's URL, and sign in with OAuth. The steps, with Sume's hosted MCP server as the example.
Written by Sume