OpenAI Agents Python conditional approval and Sume dry_run
Openai-agents-python v0.22.3 aligns conditional approvals with validated tool arguments. For Sume tools, base the check on tools_schema and dry_run.

The v0.22.3 release of openai-agents-python lists a fix to "align conditional approvals with validated tool arguments". For Sume tools the practical rule is the same: decide whether to ask a human using the arguments the tool contract accepts, and use dry_run to get the cost before the question is asked.
The release notes only give the one-line title of that fix (PR 5066), so this post does not describe how the SDK implements it. The Sume side is from MCP tools and gates, read 2026-10-01.
What does the v0.22.3 release say?
Under "What's Changed" the first entry is "fix(core): align conditional approvals with validated tool arguments". That is the whole description in the notes. If your approval predicate runs on tool arguments, read the linked pull request before relying on a specific behavior.
Which Sume fields should a conditional approval read?
Sume publishes one contract per tool through tools_schema (fetch by name), so a predicate can be written against the same fields the server validates. The gates that matter for a paid call are below.
| Field or tool | What the docs say |
|---|---|
tools_schema | Fetch one tool contract by name. |
idempotency_key | Required on write and paid tools; stable key for transport and dedup, not human approval. |
dry_run=true | Optional admission and cost preview only; the job is not submitted. |
max_spend_usd | Optional; enforced only when provided. |
Does idempotency_key count as approval?
No. The docs describe it as a key for transport and dedup, not human approval. An approval step in your agent is a separate decision, and the key should be a stable value you generate once per intended create so a retry does not become a second paid job.
How do I show a cost before asking?
Call the create tool with dry_run=true first. It returns an admission and cost preview without submitting. The docs also say to prefer generation_admission_preview and/or dry_run before expensive bursts, and that ordinary single creates do not need that extra step. So a reasonable condition is: ask only when the call is a paid write and you are about to fan out several of them.
For the broader approval pattern, see OpenAI Agents SDK `require_approval` for Sume write tools.
What should I do after upgrading?
Re-run any approval tests that pass arguments the model might get wrong, such as a missing field or a wrong type. Check that the predicate sees the arguments in the shape the schema defines, and keep the idempotency_key out of the decision so retries behave the same as first attempts.
Sources
Related posts
More in Integrations
- Oversized MCP result: Cline cache URI vs Sume 256 KiB limit
Cline caches oversized MCP output behind a cline://cache URI. Sume instead refuses at 256 KiB with mcp_output_too_large. Re-read narrower; never resubmit.
- Shopify events: event-id header gone, dedupe on Sume job_id
Shopify events no longer send shopify-event-id. On the Sume side, dedupe job webhooks on job_id and send an Idempotency-Key on every paid submit that may retry.
- Shopify product.variants.* trigger: one Sume image per variant
A product.variants.* Shopify events trigger can fire many times at once. Fan each event out to one Sume image job, and queue bursts on your side.
- Slack incoming webhook 1/sec: when 100 Sume jobs finish together
Slack incoming webhooks allow about 1 message per second. When 100 Sume jobs finish at once, store each webhook, then post to Slack from a paced queue.
Written by Sume