The permission model for agents just moved from per-action to per-origin. openai's hosted browser…
the permission model for agents just moved from per-action to per-origin. openai's hosted browser for the agents api asks for approval once per site, then the agent can click buy, delete or submit on that domain without asking again.
a single yes is now a standing trust for everything on that origin.
Context
OpenAI's Agents API documentation says the hosted browser runs in an OpenAI-hosted environment, with the application starting a session and following its events. It says the browser requires the user's approval before accessing each new website origin, including public websites, and that enabling network access does not approve these requests. An approval request carries the origin and an optional reason, and the answer is approve, deny or cancel.
The same page has a section titled that origin approval does not enforce confirmation before individual actions. It says an application that must guarantee confirmation before purchases, destructive changes or other consequential actions should restrict the hosted browser to resources that cannot perform them, or use a browser runtime it controls. It also says website content is untrusted and cannot grant permission or override the user's instructions.
The note's claim that approval is asked once per site matches the documentation's per-origin approval. The claim that the agent can then click buy, delete or submit on that domain without asking again is close to the documentation's warning that origin approval does not confirm individual actions. The page does not say the agent will take those actions, only that nothing at the approval layer stops it.
How long an origin approval lasts, for example whether it carries across sessions, is not stated in the page read. That is unsupported, not refuted.
That a single yes is now a standing trust for the origin is the author's reading. It is consistent with the page's own advice to limit the browser to resources that cannot do harm, and the page frames the remedy as the developer's job.
Related work
- Computer use (OpenAI API docs, Agents API) ↗Primary source for origin approvals and the limit on action-level confirmation.
- OpenAI's Agents API adds a hosted browser: business controls before sign-in (Inquory) ↗Third-party coverage of the business controls around the hosted browser; surfaced in search and not read in full here.
- OpenAI Agents API Computer Use: Hosted Browser and Approvals (Digital Applied) ↗Third-party explainer dated September 28, 2026; surfaced in search and not read in full here.
Watch next
- Check whether an origin approval persists across sessions. Look for how developers add action-level confirmation in their own runtime.
Sources
- Computer use (OpenAI API docs, Agents API)developers.openai.com
Provenance
The note above is reproduced unedited from the original post, first published on Threads on 8 October 2026 at 23:17 IST. Sources are the papers and datasets the note draws on.
View the original post ↗Embed this note
More notes
The air is now being asked to keep its own ledger
the air is now being asked to keep its own ledger: ecmwf’s aifs compo becomes the first ai model to forecast atmospheric composition globally every three hours, cleanair simulates 365 days of pm2.5 over china in ten seconds, and a unified framework maps six pollutants at one kilometer across the whole country. the air now files its own composition report.
read the note →The current is now being asked to draw its own map
the current is now being asked to draw its own map: china’s langya 2.0 predicts six ocean phenomena including internal waves and mesoscale eddies, a deep net called wenhai resolves eddies globally with air sea flux formulas built in, and scripps infers surface currents from the way temperature patterns deform in satellite images. the ocean now files its own circulation report.
read the note →The soil is now being asked to report its own carbon
the soil is now being asked to report its own carbon: a nix color sensor paired with generative data augmentation predicts soil organic carbon without a lab, random forest drives 74 percent of soil health mapping studies, and sentinel 2 tracks five year carbon change across france and italy from 922 samples. the dirt now files its own carbon account.
read the note →