OpenAI Agents SDK adds controls for discovery and session work
OpenAIโs Agents Python SDK adds optional discovery and history budgets, configurable memory turns and narrowly scoped Docker removal protection.

OpenAIโs Agents SDK for Python has gained configurable limits for tool discovery, encrypted conversation history and memory consolidation. The 0.23.0 GitHub release also introduces an optional Docker removal service, giving developers more control over work that happens around an agentโs main task.
The package available on PyPI is 0.23.1. Its files were uploaded on October 2 at about 15.42 UTC. The feature release appeared on GitHub earlier that day. ByteForward reviewed the published code and release records but has not run the SDK.
Tool discovery can stop at a chosen limit
The new MCP listing control lets developers set a maximum number of pages fetched automatically when discovering tools or prompts. It defaults to unlimited. A final page that exactly meets the configured limit succeeds, while a response requiring another page triggers an error instead of returning an incomplete list.
This setting bounds the number of successful discovery pages, not the amount of data in each page. It also does not apply to explicit resource pagination. Applications enabling it need to handle discovery failures rather than assume every server will expose all its tools within the chosen budget.
History and memory have separate budgets
Encrypted sessions gain an optional history scan budget that limits how many stored items a history read retrieves and unwraps. It is disabled by default. Overlapping scan windows count repeated items again. If a complete result cannot be established within the budget, an error is raised instead of returning partial conversation history.
The underlying session store must honor the requested retrieval limits. The setting does not establish a limit on bytes, elapsed time or backend work, and it does not apply to removing the most recent item. Teams should test it against their own history store and conversation lengths.
A separate memory consolidation setting makes the turn limit for phase two configurable. The default remains 500 model turns, matching the previously fixed value. This phase has its own limit because the outer agent runโs turn cap does not cover it.
A turn limit measures model iterations rather than time, tokens or money. When consolidation runs out of turns, earlier tool writes can remain even though the process has not recorded a successful consolidation. A team reducing the limit should check both the failure path and any changes already made.
Docker removal protection has a narrow operating scope
The optional Docker removal service pauses container processes while host workers perform recursive removals requested through the SDK. Its documented environment is a trusted private Linux Docker host using rootful Docker 26 or later, runc and the built in seccomp profile.
Writable shared mounts and custom security profiles are outside the supported configuration. The caller must set concurrency, entry visit and CPU limits. Reaching a limit can leave a removal partially completed, while an uncertain worker failure leaves the container paused for inspection. These details make deployment compatibility and recovery procedures important parts of adopting the feature.
The practical choice is which control fits the failure a team wants to contain. A large tool directory, expensive history retrieval and runaway consolidation are different problems. Start with representative workloads, record the expected failure behavior and choose each budget separately. Small limits may stop useful work just as effectively as unwanted work.
Check the package before upgrading
The 0.23.1 release notes explain that 0.23.0 had not reached PyPI at review time and identify 0.23.1 as the intended first registry publication of the series. The patch restores release tests and readiness checks. Those notes also flag migration requirements inherited from 0.23.0, including tool parameters, restored approvals, encrypted history and voice defaults. Check the installed version and relevant migration paths before upgrading.
These changes belong to the Agents SDK. ByteForwardโs earlier OpenAI Python client update covers typed results and file helpers in a separate package. Our Agents API coverage describes the hosted serviceโs browser control capabilities.
Hero image is original AI generated conceptual artwork created for ByteForward. The ceramic channels and adjustable gates do not depict a product interface or measured result.



