warrantd-openai-agents
Your framework has the approval switch; warrantd is the brain that flips it.
The OpenAI Agents SDK
already ships human-in-the-loop tool approval: needs_approval,
interruptions, approve/reject, resume. What it doesn't ship is a policy for
when a tool needs approval — that's usually a hardcoded bool.
This adapter makes the switch dynamic: earned autonomy from warrantd. A tool starts at MANUAL (every call interrupted for a human), earns SUPERVISED through clean approvals (auto-runs within a value cap), and is bounded by ceilings no metric can move.
pip install warrantd-openai-agents
Quickstart
from decimal import Decimal
from agents import Agent, Runner
from warrantd import (
ActionClass, ApprovalHistorySignal, AutonomyState, GraduationThresholds,
InMemoryApprovalHistory, RiskTier, TrustLayer, TrustPolicy,
)
from warrantd_openai_agents import ToolBinding, WarrantdGate
policy = TrustPolicy(
actions={"issue_refund": ActionClass(
name="issue_refund", risk=RiskTier.REVERSIBLE_WRITE,
auto_cap=Decimal("100"), hard_cap=Decimal("1000"),
max_state=AutonomyState.SUPERVISED,
)},
thresholds=GraduationThresholds(
pass_rate={AutonomyState.SUPERVISED: 1.0, AutonomyState.AUTONOMOUS: 1.0},
adversarial_pass_rate={AutonomyState.SUPERVISED: 0.0, AutonomyState.AUTONOMOUS: 0.9},
min_samples={AutonomyState.SUPERVISED: 5, AutonomyState.AUTONOMOUS: 1000},
),
)
evidence = InMemoryApprovalHistory()
trust = TrustLayer(policy, audit=my_audit_sink,
signals=[ApprovalHistorySignal(evidence, window=10)])
gate = WarrantdGate(trust, policy=policy, evidence=evidence,
bindings={"issue_refund": ToolBinding(value_param="amount")})
agent = gate.guard_agent(Agent(name="billing", tools=[issue_refund]))
result = await Runner.run(agent, "refund invoice INV-1 by $50")
if result.interruptions: # REQUIRE_APPROVAL: run paused
state = result.to_state()
for item in result.interruptions:
print(gate.context_for(item).sentence())
# -> "this class is 4/10 approvals from SUPERVISED — your decision
# feeds its trust record"
gate.approve(state, item, approver="alice") # or gate.reject(...)
result = await Runner.run(agent, state)
After enough clean approvals the same call stops interrupting — it
auto-runs within auto_cap. A call above hard_cap never interrupts either:
it is blocked outright, with the reason returned as tool output so the model
can adapt. Ceilings never move.
Call
gate.approve()/gate.reject(), notstate.approve()directly — the SDK has no approval callback, so the gate is the hook that turns the human's decision into trust evidence. Bypass it and nothing is learned.
What this adapter does NOT do
- No decision logic. Every verdict comes from
warrantd-core'sTrustLayer; this package only translates SDK events. (Verify it:GraduationEngineappears only in the display-only progress helper, and noDecision/Verdictis ever constructed here.) - No approval UI. Your interruption handler is the UI;
context_for()gives you the graduation sentence to render. - No MCP gating. For gating MCP servers with zero agent changes, use warrantd-gateway.
- No persistence by default.
InMemoryApprovalHistoryresets on restart. For hash-chained, restart-proof evidence:
pip install "warrantd-openai-agents[gateway]"
from warrantd_openai_agents.stores import sqlite_store
evidence = sqlite_store(".warrantd/evidence.db") # also usable as audit=
That store is the gateway's chained audit log: warrantd verify-audit
checks it and warrantd dashboard displays it read-only.
Learn more
- Why earned autonomy:
DESIGN.md— Trust is earned, not configured - Runnable example (no API key needed):
examples/openai_agents/earned_autonomy.py - API promises:
STABILITY.md
Metadata
Release files for warrantd-openai-agents 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| warrantd_openai_agents-0.1.0.tar.gz | 13.8 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| warrantd_openai_agents-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 25.8 kB
Release files / warrantd_openai_agents-0.1.0.tar.gz
| Download URL | warrantd_openai_agents-0.1.0.tar.gz |
|---|---|
| Size | 13.8 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
537a4920d5ff5fda5e201c782cc78b3e9f3853ebddb01382c93c65482ec2b1eb
|
|
BLAKE2b-256 checksum How to use checksums |
5582649a99cec80c11a5ef54aaaf41b74dc0be653cd27130cf525d1f5bf51541
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 12, 2026.
Transparency logRelease files / warrantd_openai_agents-0.1.0-py3-none-any.whl
| Download URL | warrantd_openai_agents-0.1.0-py3-none-any.whl |
|---|---|
| Size | 12.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
9a70cd5f12ed9d02e7ea06d5a14958eadf6f21c0ba141a415d3e9de501a97145
|
|
BLAKE2b-256 checksum How to use checksums |
ab32f61e3fca9e60a58bd1cccfad26fab63f4a902f66f945361d0508d1809353
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 12, 2026.
Transparency log