跳转至

工具

工具让智能体能够执行操作:例如获取数据、运行代码、调用外部 API,甚至使用计算机。SDK 支持五个目录:

  • 由OpenAI托管的工具:与模型一起在OpenAI服务上运行。
  • 本地/运行时执行工具:ComputerToolApplyPatchTool 始终在你的环境中运行,而 ShellTool 可以在本地或托管容器中运行。
  • Function calling:将任意 Python 函数封装为工具。
  • Agents as tools:将智能体公开为可调用工具,而无需完整的任务转移。
  • 实验性 Codex 工具:通过工具调用运行限定于工作区的 Codex 任务。

工具类型选择

将本页面用作目录,然后跳转到与你所控制运行时相匹配的章节。

如果你想要…… 从这里开始
使用由OpenAI管理的工具(网络检索、文件检索、Code Interpreter、托管MCP、图像生成) 托管工具
使用工具搜索将大型工具集合推迟到运行时加载 托管工具搜索
通过生成的 JavaScript 协调多个工具调用 编程式工具调用
在自己的进程或环境中运行工具 本地运行时工具
将 Python 函数封装为工具 工具调用
让一个智能体在不进行任务转移的情况下调用另一个智能体 Agents as tools
从智能体运行限定于工作区的 Codex 任务 实验性 Codex 工具

托管工具

使用 OpenAIResponsesModel 时,OpenAI 提供了一些内置工具:

高级托管搜索选项:

  • 除了 vector_store_idsmax_num_resultsFileSearchTool 还支持 filtersranking_optionsinclude_search_results
  • WebSearchTool 支持 filtersuser_locationsearch_context_size
from agents import Agent, FileSearchTool, Runner, WebSearchTool

agent = Agent(
    name="Assistant",
    tools=[
        WebSearchTool(),
        FileSearchTool(
            max_num_results=3,
            vector_store_ids=["VECTOR_STORE_ID"],
        ),
    ],
)

async def main():
    result = await Runner.run(agent, "Which coffee shop should I go to, taking into account my preferences and the weather today in SF?")
    print(result.final_output)

托管工具搜索

工具搜索让 OpenAI Responses 模型能够将大型工具集合推迟到运行时加载,使模型仅加载当前轮次所需的子集。当你有大量工具调用、命名空间组或托管MCP服务,并且希望在不预先公开每个工具的情况下减少工具架构所占的 token 时,这非常有用。

如果候选工具在构建智能体时已经确定,请优先使用托管工具搜索。如果你的应用需要动态决定加载哪些内容,Responses API 也支持由客户端执行的工具搜索,但标准 Runner 不会自动执行该模式。

from typing import Annotated

from agents import Agent, Runner, ToolSearchTool, tool_namespace
from agents.decorators import tool


@tool(defer_loading=True)
def get_customer_profile(
    customer_id: Annotated[str, "The customer ID to look up."],
) -> str:
    """Fetch a CRM customer profile."""
    return f"profile for {customer_id}"


@tool(defer_loading=True)
def list_open_orders(
    customer_id: Annotated[str, "The customer ID to look up."],
) -> str:
    """List open orders for a customer."""
    return f"open orders for {customer_id}"


crm_tools = tool_namespace(
    name="crm",
    description="CRM tools for customer lookups.",
    tools=[get_customer_profile, list_open_orders],
)


agent = Agent(
    name="Operations assistant",
    model="gpt-5.6-sol",
    instructions="Load the crm namespace before using CRM tools.",
    tools=[*crm_tools, ToolSearchTool()],
)

result = await Runner.run(agent, "Look up customer_42 and list their open orders.")
print(result.final_output)

注意事项:

  • 托管工具搜索仅适用于 OpenAI Responses 模型。当前 Python SDK 支持依赖于 openai>=2.25.0
  • 在智能体上配置延迟加载的工具集合时,只添加一个 ToolSearchTool()
  • 可搜索的工具集合包括 @function_tool(defer_loading=True)tool_namespace(name=..., description=..., tools=[...])HostedMCPTool(tool_config={..., "defer_loading": True})
  • 延迟加载的工具调用必须与 ToolSearchTool() 配合使用。仅包含命名空间的设置也可以使用 ToolSearchTool(),让模型按需加载正确的工具组。
  • tool_namespace()FunctionTool 实例归入一个具有共享名称和描述的命名空间。当你有许多相关工具(例如 crmbillingshipping)时,这通常是最合适的方式。
  • OpenAI 的官方最佳实践指南是尽可能使用命名空间
  • 在可能的情况下,优先使用命名空间或托管MCP服务,而不是大量单独延迟加载的函数。它们通常能为模型提供更好的高级搜索界面,并节省更多 token。
  • 命名空间可以混合包含立即可用和延迟加载的工具。没有 defer_loading=True 的工具仍可立即调用,而同一命名空间中的延迟加载工具则通过工具搜索加载。
  • 根据经验,每个命名空间应保持相对精简,最好少于 10 个函数。
  • 具名 tool_choice 不能以单独的命名空间名称或仅延迟加载的工具为目标。请优先使用 autorequired 或真正的顶层可调用工具名称。
  • ToolSearchTool(execution="client") 用于手动编排 Responses。如果模型发出由客户端执行的 tool_search_call,标准 Runner 会引发异常,而不会替你执行。
  • 工具搜索活动会出现在 RunResult.new_itemsRunItemStreamEvent 中,并具有专用的项目和事件类型。
  • 有关命名空间加载和顶层延迟加载工具的完整可运行代码示例,请参阅 examples/tools/tool_search.py
  • 官方平台指南:工具搜索

编程式工具调用

编程式工具调用让受支持的 OpenAI Responses 模型能够生成 JavaScript,以调用符合条件的工具、组合其输出,并向模型返回一个结果。它适用于范围明确的工作流,这些工作流可受益于循环、分支、并行调用或中间计算,而无需在每次工具调用后都与模型往返交互。

生成的程序在全新的托管 V8 环境中运行。它不具备 Node.js API、文件系统或网络访问权限,也不是持久进程。该程序只能与明确允许的工具交互。

from pydantic import BaseModel

from agents import (
    Agent,
    ModelSettings,
    ProgrammaticToolCallingTool,
    Runner,
)
from agents.decorators import tool


class InventoryOutput(BaseModel):
    sku: str
    available_units: int


@tool(allowed_callers=["programmatic"])
def get_inventory(sku: str) -> InventoryOutput:
    return InventoryOutput(sku=sku, available_units=42)


agent = Agent(
    name="Inventory planner",
    model="gpt-5.6",
    model_settings=ModelSettings(tool_choice="programmatic_tool_calling"),
    tools=[get_inventory, ProgrammaticToolCallingTool()],
)

result = Runner.run_sync(agent, "Check inventory for desk-lamp and summarize it.")
print(result.final_output)

注意事项:

  • 编程式工具调用仅适用于受支持的 OpenAI Responses 模型。Chat Completions 模型和非 Responses 后端会拒绝 ProgrammaticToolCallingTool()tool_choice="programmatic_tool_calling"
  • 一个智能体最多只能添加一个 ProgrammaticToolCallingTool()。该智能体还必须公开至少一个可通过编程方式调用的工具、一个 ToolSearchTool(),或由提示词管理的工具集合。
  • allowed_callers 控制工具的调用方式。省略该参数时,仅允许模型直接调用。使用 ["programmatic"] 可仅允许程序访问,使用 ["direct", "programmatic"] 则允许两种方式。
  • 可选择启用此功能的 SDK 工具类型包括 FunctionToolCustomToolShellToolApplyPatchToolHostedMCPToolCodeInterpreterTool。函数、自定义、shell 和补丁应用工具直接公开 allowed_callers。对于托管MCP和 Code Interpreter,请在 tool_config 中设置 allowed_callers
  • 对于 @function_tool(allowed_callers=[...]),Pydantic 模型、TypedDict 或 dataclass 等结构化返回注解会自动转换为严格的对象输出架构,并在值返回给程序之前进行验证。如果函数没有可用的注解,请使用 output_type=...;如果你已有严格的对象架构,则可使用较低层级的 output_json_schema={...} 作为替代方案。output_typeoutput_json_schema 互斥。返回普通 strAnyNone 时仍不指定类型。
  • 由程序拥有的 SDK 工具仍使用常规 Runner 生命周期。工具输入和输出安全防护措施、钩子、超时、并发限制、重试、审批、会话以及 RunState 暂停/恢复行为仍然适用,并且 SDK 会保留每个子调用与程序调用方之间的关系。
  • 对审批敏感或影响较大的工具通常更适合作为直接调用保留,以便人员在每项操作成为大型程序的一部分之前进行审查。如果由程序拥有的调用因审批而暂停,请通过 RunState 处理中断,并照常恢复原始运行。
  • 编程式工具调用可以与托管工具搜索结合使用。生成的程序必须先由模型加载延迟工具,然后才能调用它们。
  • program 项目及其由程序拥有的子调用会显示为 ToolCallItem 条目。对应的 program_output 会显示为 ToolCallOutputItem。有关检查详情,请参阅结果流式传输
  • 有关完整的并发库存规划代码示例,请参阅 examples/tools/programmatic_tool_calling.py
  • 官方平台指南:编程式工具调用

托管容器 shell 与技能

ShellTool 还支持在OpenAI托管的容器中执行。当你希望模型在托管容器中运行 shell 命令,而不是在本地运行时中运行时,请使用此模式。

from agents import Agent, Runner, ShellTool, ShellToolSkillReference

csv_skill: ShellToolSkillReference = {
    "type": "skill_reference",
    "skill_id": "skill_698bbe879adc81918725cbc69dcae7960bc5613dadaed377",
    "version": "1",
}

agent = Agent(
    name="Container shell agent",
    model="gpt-5.6-sol",
    instructions="Use the mounted skill when helpful.",
    tools=[
        ShellTool(
            environment={
                "type": "container_auto",
                "network_policy": {"type": "disabled"},
                "skills": [csv_skill],
            }
        )
    ],
)

result = await Runner.run(
    agent,
    "Use the configured skill to analyze CSV files in /mnt/data and summarize totals by region.",
)
print(result.final_output)

若要在后续运行中复用现有容器,请设置 environment={"type": "container_reference", "container_id": "cntr_..."}

注意事项:

  • 托管 shell 可通过 Responses API 的 shell 工具使用。
  • container_auto 为请求预配容器;container_reference 复用现有容器。
  • container_auto 还可以包含 file_idsmemory_limit
  • environment.skills 接受技能引用和内联技能包。
  • 使用托管环境时,请勿在 ShellTool 上设置 executorneeds_approvalon_approval
  • network_policy 支持 disabledallowlist 模式。
  • 在允许列表模式下,network_policy.domain_secrets 可以按名称注入限定于域的密钥。
  • 有关完整代码示例,请参阅 examples/tools/container_shell_skill_reference.pyexamples/tools/container_shell_inline_skill.py
  • OpenAI 平台指南:Shell技能

本地运行时工具

本地运行时工具在模型响应本身之外执行。模型仍然决定何时调用它们,但实际工作由你的应用或配置的执行环境完成。

ComputerToolApplyPatchTool 始终需要由你提供本地实现。ShellTool 横跨两种模式:如果需要托管执行,请使用上述托管容器配置;如果希望命令在你自己的进程中运行,请使用下述本地运行时配置。

本地运行时工具要求你提供实现:

ComputerTool 与 Responses 计算机工具

ComputerTool 仍然是一个本地执行框架:你需要提供 ComputerAsyncComputer 实现,SDK 会将该执行框架映射到 OpenAI Responses API 的计算机操作界面。

对于明确的 gpt-5.5 请求,SDK 会发送正式发布版内置工具载荷 {"type": "computer"}。较旧的 computer-use-preview 模型则继续使用预览版载荷 {"type": "computer_use_preview", "environment": ..., "display_width": ..., "display_height": ...}。这与 OpenAI 的计算机操作指南中所述的平台迁移一致:

  • 模型:computer-use-preview -> gpt-5.5
  • 工具选择器:computer_use_preview -> computer
  • 计算机调用结构:每个 computer_call 包含一个 action -> computer_call 上批量的 actions[]
  • 截断:预览版路径要求使用 ModelSettings(truncation="auto") -> 正式发布版路径不要求

SDK 会根据实际 Responses 请求中的有效模型选择相应的传输结构。如果你使用提示词模板,并且由于模型由提示词指定而使请求省略 model,SDK 会继续使用兼容预览版的计算机载荷;除非你明确保留 model="gpt-5.5",或通过 ModelSettings(tool_choice="computer")ModelSettings(tool_choice="computer_use") 强制使用正式发布版选择器。

存在 ComputerTool 时,tool_choice="computer""computer_use""computer_use_preview" 均会被接受,并规范化为与有效请求模型匹配的内置选择器。不存在 ComputerTool 时,这些字符串仍然会像普通函数名称一样处理。

ComputerToolComputerProvider 工厂支持时,这一区别很重要。正式发布版 computer 载荷在序列化时不需要 environment 或尺寸,因此工厂尚未解析也没有问题。兼容预览版的序列化仍然需要已解析的 ComputerAsyncComputer 实例,以便 SDK 可以发送 environmentdisplay_widthdisplay_height

在运行时,两条路径仍然使用同一个本地执行框架。预览版响应会发出包含单个 actioncomputer_call 项目;gpt-5.5 可以发出批量的 actions[],SDK 会按顺序执行这些操作,然后生成一个 computer_call_output 截图项目。有关基于 Playwright 的可运行执行框架,请参阅 examples/tools/computer_use.py

from agents import Agent, ApplyPatchTool, ShellTool
from agents.computer import AsyncComputer
from agents.editor import ApplyPatchResult, ApplyPatchOperation, ApplyPatchEditor


class NoopComputer(AsyncComputer):
    environment = "browser"
    dimensions = (1024, 768)
    async def screenshot(self): return ""
    async def click(self, x, y, button): ...
    async def double_click(self, x, y): ...
    async def scroll(self, x, y, scroll_x, scroll_y): ...
    async def type(self, text): ...
    async def wait(self): ...
    async def move(self, x, y): ...
    async def keypress(self, keys): ...
    async def drag(self, path): ...


class NoopEditor(ApplyPatchEditor):
    async def create_file(self, op: ApplyPatchOperation): return ApplyPatchResult(status="completed")
    async def update_file(self, op: ApplyPatchOperation): return ApplyPatchResult(status="completed")
    async def delete_file(self, op: ApplyPatchOperation): return ApplyPatchResult(status="completed")


async def run_shell(request):
    return "shell output"


agent = Agent(
    name="Local tools agent",
    tools=[
        ShellTool(executor=run_shell),
        ApplyPatchTool(editor=NoopEditor()),
        # ComputerTool expects a Computer/AsyncComputer implementation; omitted here for brevity.
    ],
)

工具调用

你可以将任意 Python 函数用作工具。Agents SDK 会自动设置该工具:

  • 工具名称将是 Python 函数的名称(也可以自行提供名称)
  • 工具描述将取自函数的文档字符串(也可以自行提供描述)
  • 函数输入的架构会根据函数参数自动创建
  • 除非禁用,否则每个输入的描述都取自函数的文档字符串

我们使用 Python 的 inspect 模块提取函数签名,使用 griffe 解析文档字符串,并使用 pydantic 创建架构。

使用 OpenAI Responses 模型时,@function_tool(defer_loading=True) 会隐藏工具调用,直到 ToolSearchTool() 将其加载。你还可以使用 tool_namespace() 对相关工具调用进行分组。有关完整设置和限制,请参阅托管工具搜索

import json

from typing_extensions import TypedDict, Any

from agents import Agent, FunctionTool, RunContextWrapper
from agents.decorators import tool


class Location(TypedDict):
    lat: float
    long: float

@tool  # (1)!
async def fetch_weather(location: Location) -> str:
    # (2)!
    """Fetch the weather for a given location.

    Args:
        location: The location to fetch the weather for.
    """
    # In real life, we'd fetch the weather from a weather API
    return "sunny"


@tool(name_override="fetch_data")  # (3)!
def read_file(ctx: RunContextWrapper[Any], path: str, directory: str | None = None) -> str:
    """Read the contents of a file.

    Args:
        path: The path to the file to read.
        directory: The directory to read the file from.
    """
    # In real life, we'd read the file from the file system
    return "<file contents>"


agent = Agent(
    name="Assistant",
    tools=[fetch_weather, read_file],  # (4)!
)

for tool in agent.tools:
    if isinstance(tool, FunctionTool):
        print(tool.name)
        print(tool.description)
        print(json.dumps(tool.params_json_schema, indent=2))
        print()
  1. 你可以使用任意 Python 类型作为函数参数,并且函数可以是同步或异步的。
  2. 如果存在文档字符串,则会使用它来获取描述和参数描述
  3. 函数可以选择接收 context(必须是第一个参数)。你还可以设置覆盖项,例如工具名称、描述、要使用的文档字符串样式等。
  4. 你可以将经过装饰的函数传递给工具列表。
展开以查看输出
fetch_weather
Fetch the weather for a given location.
{
"$defs": {
  "Location": {
    "properties": {
      "lat": {
        "title": "Lat",
        "type": "number"
      },
      "long": {
        "title": "Long",
        "type": "number"
      }
    },
    "required": [
      "lat",
      "long"
    ],
    "title": "Location",
    "type": "object"
  }
},
"properties": {
  "location": {
    "$ref": "#/$defs/Location",
    "description": "The location to fetch the weather for."
  }
},
"required": [
  "location"
],
"title": "fetch_weather_args",
"type": "object"
}

fetch_data
Read the contents of a file.
{
"properties": {
  "path": {
    "description": "The path to the file to read.",
    "title": "Path",
    "type": "string"
  },
  "directory": {
    "anyOf": [
      {
        "type": "string"
      },
      {
        "type": "null"
      }
    ],
    "default": null,
    "description": "The directory to read the file from.",
    "title": "Directory"
  }
},
"required": [
  "path"
],
"title": "fetch_data_args",
"type": "object"
}

从工具调用返回图像或文件

除了返回文本输出之外,你还可以返回一个或多个图像或文件作为工具调用的输出。为此,可以返回以下任意内容:

自定义工具调用

有时,你可能不想将 Python 函数用作工具。如果愿意,可以直接创建 FunctionTool。你需要提供:

  • name
  • description
  • params_json_schema,即参数的 JSON 架构
  • on_invoke_tool,它是一个异步函数,接收 ToolContext 和 JSON 字符串形式的参数,并返回工具输出(例如文本、结构化工具输出对象或输出列表)。
from typing import Any

from pydantic import BaseModel

from agents import RunContextWrapper, FunctionTool



def do_some_work(data: str) -> str:
    return "done"


class FunctionArgs(BaseModel):
    username: str
    age: int


async def run_function(ctx: RunContextWrapper[Any], args: str) -> str:
    parsed = FunctionArgs.model_validate_json(args)
    return do_some_work(data=f"{parsed.username} is {parsed.age} years old")


tool = FunctionTool(
    name="process_user",
    description="Processes extracted user data",
    params_json_schema=FunctionArgs.model_json_schema(),
    on_invoke_tool=run_function,
)

参数与文档字符串的自动解析

如前所述,我们会自动解析函数签名以提取工具架构,并解析文档字符串以提取工具和各个参数的描述。相关注意事项如下:

  1. 签名解析通过 inspect 模块完成。我们使用类型注解了解参数类型,并动态构建 Pydantic 模型来表示整体架构。它支持大多数类型,包括 Python 基本类型、Pydantic 模型、TypedDict 等。
  2. 我们使用 griffe 解析文档字符串。支持的文档字符串格式包括 googlesphinxnumpy。我们会尝试自动检测文档字符串格式,但这只是尽力而为;你可以在调用 function_tool 时明确设置格式。也可以将 use_docstring_info 设置为 False 来禁用文档字符串解析。对于 Google 风格的文档字符串,解析器还接受紧跟在摘要文本之后且中间没有空行的 Args:Arguments:Params:Parameters: 章节。

架构提取代码位于 agents.function_schema

使用 Pydantic Field 约束和描述参数

你可以使用 Pydantic 的 Field 为工具参数添加约束(例如数字的最小值/最大值、字符串的长度或模式)和描述。与 Pydantic 相同,两种形式都受支持:基于默认值的形式(arg: int = Field(..., ge=1))和 Annotated 形式(arg: Annotated[int, Field(..., ge=1)])。生成的 JSON 架构和验证均包含这些约束。

from typing import Annotated
from pydantic import Field
from agents.decorators import tool

# Default-based form
@tool
def score_a(score: int = Field(..., ge=0, le=100, description="Score from 0 to 100")) -> str:
    return f"Score recorded: {score}"

# Annotated form
@tool
def score_b(score: Annotated[int, Field(..., ge=0, le=100, description="Score from 0 to 100")]) -> str:
    return f"Score recorded: {score}"

工具调用超时

你可以使用 @function_tool(timeout=...) 为异步工具调用设置单次调用超时。

import asyncio
from agents import Agent
from agents.decorators import tool


@tool(timeout=2.0)
async def slow_lookup(query: str) -> str:
    await asyncio.sleep(10)
    return f"Result for {query}"


agent = Agent(
    name="Timeout demo",
    instructions="Use tools when helpful.",
    tools=[slow_lookup],
)

达到超时时间时,默认行为是 timeout_behavior="error_as_result",它会发送模型可见的超时消息(例如 Tool 'slow_lookup' timed out after 2 seconds.)。

你可以控制超时处理方式:

  • timeout_behavior="error_as_result"(默认):向模型返回超时消息,使其能够恢复。
  • timeout_behavior="raise_exception":引发 ToolTimeoutError 并使运行失败。
  • timeout_error_function=...:使用 error_as_result 时自定义超时消息。
import asyncio
from agents import Agent, Runner, ToolTimeoutError
from agents.decorators import tool


@tool(timeout=1.5, timeout_behavior="raise_exception")
async def slow_tool() -> str:
    await asyncio.sleep(5)
    return "done"


agent = Agent(name="Timeout hard-fail", tools=[slow_tool])

try:
    await Runner.run(agent, "Run the tool")
except ToolTimeoutError as e:
    print(f"{e.tool_name} timed out in {e.timeout_seconds} seconds")

Note

仅异步 @function_tool 处理程序支持超时配置。

工具调用中的错误处理

通过 @function_tool 创建工具调用时,可以传入 failure_error_function。当工具调用崩溃时,此函数会向 LLM 提供错误响应。

  • 默认情况下(即未传入任何内容时),它会运行 default_tool_error_function,告知 LLM 发生了错误。
  • 如果传入自己的错误函数,则会改为运行该函数,并将响应发送给 LLM。
  • 如果明确传入 None,则任何工具调用错误都会重新引发,由你处理。如果模型生成了无效 JSON,这可能是 ModelBehaviorError;如果你的代码崩溃,则可能是 UserError,等等。
from agents import RunContextWrapper
from agents.decorators import tool
from typing import Any

def my_custom_error_function(context: RunContextWrapper[Any], error: Exception) -> str:
    """A custom function to provide a user-friendly error message."""
    print(f"A tool call failed with the following error: {error}")
    return "An internal server error occurred. Please try again later."

@tool(failure_error_function=my_custom_error_function)
def get_user_profile(user_id: str) -> str:
    """Fetches a user profile from a mock API.
     This function demonstrates a 'flaky' or failing API call.
    """
    if user_id == "user_123":
        return "User profile for user_123 successfully retrieved."
    else:
        raise ValueError(f"Could not retrieve profile for user_id: {user_id}. API returned an error.")

如果手动创建 FunctionTool 对象,则必须在 on_invoke_tool 函数内部处理错误。

Agents as tools

在某些工作流中,你可能希望由一个中心智能体编排专用智能体网络,而不是转移控制权。你可以通过将智能体建模为工具来实现这一点。

import asyncio

from agents import Agent, Runner

spanish_agent = Agent(
    name="Spanish agent",
    instructions="You translate the user's message to Spanish",
)

french_agent = Agent(
    name="French agent",
    instructions="You translate the user's message to French",
)

orchestrator_agent = Agent(
    name="orchestrator_agent",
    instructions=(
        "You are a translation agent. You use the tools given to you to translate. "
        "If asked for multiple translations, you call the relevant tools."
    ),
    tools=[
        spanish_agent.as_tool(
            tool_name="translate_to_spanish",
            tool_description="Translate the user's message to Spanish",
        ),
        french_agent.as_tool(
            tool_name="translate_to_french",
            tool_description="Translate the user's message to French",
        ),
    ],
)

async def main():
    result = await Runner.run(orchestrator_agent, input="Say 'Hello, how are you?' in Spanish.")
    print(result.final_output)


if __name__ == "__main__":
    asyncio.run(main())

工具智能体自定义

agent.as_tool 函数是一种便捷方法,可以轻松地将智能体转换为工具。它支持 max_turnsrun_confighooksprevious_response_idconversation_idsessionneeds_approval 等常见运行时选项。它还通过 parametersinput_builderinclude_input_schema 支持结构化输入。

状态选项用于配置由工具调用启动的嵌套智能体运行;父运行的对话状态不会自动继承。若要在父运行和嵌套运行之间共享由客户端管理的历史记录,请明确向两者传入相同的 session。与 Runner.run 一样,应为嵌套运行选择一种状态策略:使用由客户端管理的 session,或通过 previous_response_idconversation_id 在服务端管理延续状态。

from agents.decorators import tool


@tool
async def run_my_agent() -> str:
    """A tool that runs the agent with custom configs"""

    agent = Agent(name="My agent", instructions="...")

    result = await Runner.run(
        agent,
        input="...",
        max_turns=5,
        run_config=...
    )

    return str(result.final_output)

工具智能体的结构化输入

默认情况下,Agent.as_tool() 需要单个字符串输入({"input": "..."}),但你可以通过传入 parameters(Pydantic 模型或 dataclass 类型)公开结构化架构。

其他选项:

  • include_input_schema=True 会在生成的嵌套输入中包含完整的 JSON Schema。
  • input_builder=... 让你可以完全自定义如何将结构化工具参数转换为嵌套智能体输入。
  • RunContextWrapper.tool_input 包含嵌套运行上下文中已解析的结构化载荷。
from pydantic import BaseModel, Field


class TranslationInput(BaseModel):
    text: str = Field(description="Text to translate.")
    source: str = Field(description="Source language.")
    target: str = Field(description="Target language.")


translator_tool = translator_agent.as_tool(
    tool_name="translate_text",
    tool_description="Translate text between languages.",
    parameters=TranslationInput,
    include_input_schema=True,
)

有关完整的可运行代码示例,请参阅 examples/agent_patterns/agents_as_tools_structured.py

工具智能体的审批门控

Agent.as_tool(..., needs_approval=...) 使用与 function_tool 相同的审批流程。如果需要审批,运行会暂停,待处理项目将显示在 result.interruptions 中;然后使用 result.to_state(),并在调用 state.approve(...)state.reject(...) 后恢复运行。有关完整的暂停/恢复模式,请参阅人工介入指南

自定义输出提取

在某些情况下,你可能希望先修改工具智能体的输出,再将其返回给中心智能体。以下情况可能会需要这样做:

  • 从子智能体的聊天历史中提取特定信息(例如 JSON 载荷)。
  • 转换或重新格式化智能体的最终答案(例如将 Markdown 转换为纯文本或 CSV)。
  • 验证输出,或在智能体响应缺失或格式错误时提供回退值。

你可以通过向 as_tool 方法提供 custom_output_extractor 参数来实现:

async def extract_json_payload(run_result: RunResult) -> str:
    # Scan the agent’s outputs in reverse order until we find a JSON-like message from a tool call.
    for item in reversed(run_result.new_items):
        if isinstance(item, ToolCallOutputItem) and item.output.strip().startswith("{"):
            return item.output.strip()
    # Fallback to an empty JSON object if nothing was found
    return "{}"


json_tool = data_agent.as_tool(
    tool_name="get_data_json",
    tool_description="Run the data agent and return only its JSON payload",
    custom_output_extractor=extract_json_payload,
)

在自定义提取器内部,嵌套的 RunResult 还会公开 agent_tool_invocation。当你需要在对嵌套结果进行后处理时获取外层工具名称、调用 ID 或原始参数,这会很有用。请参阅结果指南

嵌套智能体运行的流式传输

as_tool 传入 on_stream 回调,以侦听嵌套智能体发出的流式传输事件,同时仍在流完成后返回其最终输出。

from agents import AgentToolStreamEvent


async def handle_stream(event: AgentToolStreamEvent) -> None:
    # Inspect the underlying StreamEvent along with agent metadata.
    print(f"[stream] {event['agent'].name} :: {event['event'].type}")


billing_agent_tool = billing_agent.as_tool(
    tool_name="billing_helper",
    tool_description="Answer billing questions.",
    on_stream=handle_stream,  # Can be sync or async.
)

预期行为:

  • 事件类型与 StreamEvent["type"] 一致:raw_response_eventrun_item_stream_eventagent_updated_stream_event
  • 提供 on_stream 会自动以流式传输模式运行嵌套智能体,并在返回最终输出前耗尽该流。
  • 处理程序可以是同步或异步的;每个事件都会按到达顺序传递。
  • 通过模型工具调用来调用工具时,会提供 tool_call;直接调用时,其值可能为 None
  • 有关完整的可运行示例,请参阅 examples/agent_patterns/agents_as_tools_streaming.py

条件式工具启用

你可以使用 is_enabled 参数,在运行时有条件地启用或禁用智能体工具。这样便可根据上下文、用户偏好或运行时条件,动态筛选可供 LLM 使用的工具。

import asyncio
from agents import Agent, AgentBase, Runner, RunContextWrapper
from pydantic import BaseModel

class LanguageContext(BaseModel):
    language_preference: str = "french_spanish"

def french_enabled(ctx: RunContextWrapper[LanguageContext], agent: AgentBase) -> bool:
    """Enable French for French+Spanish preference."""
    return ctx.context.language_preference == "french_spanish"

# Create specialized agents
spanish_agent = Agent(
    name="spanish_agent",
    instructions="You respond in Spanish. Always reply to the user's question in Spanish.",
)

french_agent = Agent(
    name="french_agent",
    instructions="You respond in French. Always reply to the user's question in French.",
)

# Create orchestrator with conditional tools
orchestrator = Agent(
    name="orchestrator",
    instructions=(
        "You are a multilingual assistant. You use the tools given to you to respond to users. "
        "You must call ALL available tools to provide responses in different languages. "
        "You never respond in languages yourself, you always use the provided tools."
    ),
    tools=[
        spanish_agent.as_tool(
            tool_name="respond_spanish",
            tool_description="Respond to the user's question in Spanish",
            is_enabled=True,  # Always enabled
        ),
        french_agent.as_tool(
            tool_name="respond_french",
            tool_description="Respond to the user's question in French",
            is_enabled=french_enabled,
        ),
    ],
)

async def main():
    context = LanguageContext(language_preference="french_spanish")
    result = await Runner.run(orchestrator, "How are you?", context=context)
    print(result.final_output)

asyncio.run(main())

is_enabled 参数接受:

  • 布尔值True(始终启用)或 False(始终禁用)
  • 可调用函数:接收 (context, agent) 并返回布尔值的函数
  • 异步函数:用于复杂条件逻辑的异步函数

禁用的工具在运行时对 LLM 完全隐藏,因此适用于:

  • 根据用户权限进行功能门控
  • 特定环境下的工具可用性(开发环境与生产环境)
  • 对不同工具配置进行 A/B 测试
  • 根据运行时状态动态筛选工具

实验性 Codex 工具

codex_tool 封装 Codex CLI,使智能体能够在工具调用期间运行限定于工作区的任务(shell、文件编辑、MCP工具)。此功能为实验性功能,可能会发生变化。

当你希望主智能体在不离开当前运行的情况下,将范围明确的工作区任务委托给 Codex 时,请使用它。默认情况下,工具名称为 codex。如果设置自定义名称,该名称必须是 codex 或以 codex_ 开头。当智能体包含多个 Codex 工具时,每个工具必须使用唯一名称。

from agents import Agent
from agents.extensions.experimental.codex import ThreadOptions, TurnOptions, codex_tool

agent = Agent(
    name="Codex Agent",
    instructions="Use the codex tool to inspect the workspace and answer the question.",
    tools=[
        codex_tool(
            sandbox_mode="workspace-write",
            working_directory="/path/to/repo",
            default_thread_options=ThreadOptions(
                model="gpt-5.5",
                model_reasoning_effort="low",
                network_access_enabled=True,
                web_search_mode="disabled",
                approval_policy="never",
            ),
            default_turn_options=TurnOptions(
                idle_timeout_seconds=60,
            ),
            persist_session=True,
        )
    ],
)

可从以下选项组开始:

  • 执行范围:sandbox_modeworking_directory 定义 Codex 可以在何处操作。请配合设置这两个选项;当工作目录不在 Git 仓库内时,请设置 skip_git_repo_check=True
  • 线程默认值:default_thread_options=ThreadOptions(...) 配置模型、推理强度、审批策略、其他目录、网络访问和网络检索模式。请优先使用 web_search_mode,而不是旧版的 web_search_enabled
  • 轮次默认值:default_turn_options=TurnOptions(...) 配置每轮行为,例如 idle_timeout_seconds 和可选的取消 signal
  • 工具输入/输出:工具调用必须至少包含一个 inputs 项目,其格式为 { "type": "text", "text": ... }{ "type": "local_image", "path": ... }output_schema 让你可以要求 Codex 返回结构化响应。

线程复用和持久化是独立的控制项:

  • persist_session=True 会让对同一工具实例的重复调用复用一个 Codex 线程。
  • use_run_context_thread_id=True 会在运行上下文中存储并复用线程 ID,适用于共享同一可变上下文对象的多个运行。
  • 线程 ID 的优先级依次为:每次调用的 thread_id、运行上下文线程 ID(如果已启用),然后是已配置的 thread_id 选项。
  • 对于 name="codex",默认运行上下文键为 codex_thread_id;对于 name="codex_<suffix>",则为 codex_thread_id_<suffix>。可使用 run_context_thread_id_key 覆盖该键。

运行时配置:

  • 身份验证:设置 CODEX_API_KEY(首选)或 OPENAI_API_KEY,或者传入 codex_options={"api_key": "..."}
  • 运行时:codex_options.base_url 会覆盖 CLI 基础 URL。
  • 二进制文件解析:设置 codex_options.codex_path_override(或 CODEX_PATH)以固定 CLI 路径。否则,SDK 会先从 PATH 中解析 codex,然后回退到捆绑的供应商二进制文件。
  • 环境:codex_options.env 完全控制子进程环境。提供该选项时,子进程不会继承 os.environ
  • 流限制:codex_options.codex_subprocess_stream_limit_bytes(或 OPENAI_AGENTS_CODEX_SUBPROCESS_STREAM_LIMIT_BYTES)控制 stdout/stderr 读取器限制。有效范围为 6553667108864;默认值为 8388608
  • 流式传输:on_stream 接收线程/轮次生命周期事件和项目事件(reasoningcommand_executionmcp_tool_callfile_changeweb_searchtodo_listerror 项目更新)。
  • 输出:结果包括 responseusagethread_id;用量会添加到 RunContextWrapper.usage

参考: