← Founder Notes
Archive

The permission model for agents just moved from per-action to per-origin. openai's hosted browser…

Yethikrishna ROriginal on Threads

the permission model for agents just moved from per-action to per-origin. openai's hosted browser for the agents api asks for approval once per site, then the agent can click buy, delete or submit on that domain without asking again.

a single yes is now a standing trust for everything on that origin.

Context

OpenAI's Agents API documentation says the hosted browser runs in an OpenAI-hosted environment, with the application starting a session and following its events. It says the browser requires the user's approval before accessing each new website origin, including public websites, and that enabling network access does not approve these requests. An approval request carries the origin and an optional reason, and the answer is approve, deny or cancel.

The same page has a section titled that origin approval does not enforce confirmation before individual actions. It says an application that must guarantee confirmation before purchases, destructive changes or other consequential actions should restrict the hosted browser to resources that cannot perform them, or use a browser runtime it controls. It also says website content is untrusted and cannot grant permission or override the user's instructions.

How it compares

The note's claim that approval is asked once per site matches the documentation's per-origin approval. The claim that the agent can then click buy, delete or submit on that domain without asking again is close to the documentation's warning that origin approval does not confirm individual actions. The page does not say the agent will take those actions, only that nothing at the approval layer stops it.

How long an origin approval lasts, for example whether it carries across sessions, is not stated in the page read. That is unsupported, not refuted.

That a single yes is now a standing trust for the origin is the author's reading. It is consistent with the page's own advice to limit the browser to resources that cannot do harm, and the page frames the remedy as the developer's job.

Related work

Watch next

  • Check whether an origin approval persists across sessions. Look for how developers add action-level confirmation in their own runtime.

Sources

  1. Computer use (OpenAI API docs, Agents API)developers.openai.com

Provenance

The note above is reproduced unedited from the original post, first published on Threads on 8 October 2026 at 23:17 IST. Sources are the papers and datasets the note draws on.

View the original post
Embed this note
<iframe src="https://founder.myndlabs.tech/notes/embed/the-permission-model-for-agents-just-moved-from-DePgQViDUZc" width="480" height="420" style="border:0;max-width:100%" loading="lazy" title="The permission model for agents just moved from per-action to per-origin. openai's hosted browser…"></iframe>

More notes