📍 Independent. Unsponsored. Reliable.

OpenAI Agents API With Computer Use: What You Can Build

The OpenAI Agents API with computer use lets you build agents that operate software the way a person does: they look at a screen, click, type and move between apps until a task is done. …

Cursor clicking through a browser dashboard with a gear and chip, illustrating the OpenAI Agents API with computer use

The OpenAI Agents API with computer use lets you build agents that operate software the way a person does: they look at a screen, click, type and move between apps until a task is done. OpenAI announced the update at DevDay on September 29, 2026, and OpenAI runs the underlying infrastructure, so you do not host the agent runtime yourself.

You can reach it through the API, and through Codex and ChatGPT Work on Pro 500 and Enterprise plans. ChatGPT Plus and free users do not get it. This guide covers what it does, who can use it, what it costs, where it is risky, and what a training team could realistically build with it.

It is one launch among more than 20 on the day. For the full list, read our OpenAI DevDay 2026 announcements guide and the OpenAI DevDay 2026 recap.

What is the OpenAI Agents API with computer use?

The Agents API is OpenAI’s managed way to run agents: OpenAI operates a Codex-style harness that handles long tasks while you send it work. The September 29 update adds computer use, meaning an agent can click, type and navigate software. It also carries Codex’s multi-agent tools, tool search, tool calling and context compaction.

The Agents API has been in public beta since September 11, according to The Decoder’s DevDay coverage. Computer use itself is not new to OpenAI: it reached Codex and ChatGPT on macOS in April and on Windows 11 in May. What changed is that developers can now build on it directly.

OpenAI’s own summary in its DevDay 2026 recap is short: “The Agents API now supports computer use so developers can build agents that interact with software to complete tasks.”

What can the Agents API do now that it has computer use?

The Agents API now combines six things: computer use, multi-agent tools, tool search, tool calling, context compaction and OpenAI-hosted infrastructure. Together they let an agent work through a long, multi-step job across several applications, without you writing the loop that keeps it on track. The table shows what each piece is for.

Capability What it does Why it matters for real work
Computer use Clicks, types and navigates software from screenshots Reaches tools that have no API or a limited one
Multi-agent tools Lets one agent hand parts of a job to others (carried over from Codex) Splits large jobs, but more agents means more compute purchased
Tool search Helps the agent find the tool it needs Keeps large tool sets manageable
Tool calling Calls functions, MCP servers and hosted tools Lets the agent use an API when one exists, instead of clicking
Context compaction Shrinks a long task history so the model “doesn’t lose the plot” Makes long tasks feasible
OpenAI-hosted infrastructure OpenAI runs the harness and its state No agent servers for you to maintain

The quoted phrase on compaction comes from Decrypt’s DevDay report. Reliability is improving but not solved. In figures noted in Simon Willison’s DevDay live blog, success on 8 to 16 hour tasks with zero human interventions rose from 10% in January 2026 to 35% in July 2026. Read that the other way and most such tasks still needed a person.

Who can access the OpenAI Agents API with computer use?

Developers with API access can use it directly. Inside ChatGPT, the agent features arrive through Codex and ChatGPT Work on Pro 500 ($500 a month) and Enterprise plans. Plus and free users are excluded. As of September 30, 2026, that is the extent of what OpenAI has published, so check your own account before you plan around it.

Route Who gets it Notes
OpenAI API Developers with API access You build the app around the Agents API
Codex and ChatGPT Work Pro 500 and Enterprise Pro 200 is not named in the sources we found, so confirm
Bedrock Managed Agents Eligible enterprise AWS customers Limited preview, terms unpublished
ChatGPT Plus and free Not included Use Dots or plain chat instead, where available

Plan allowances and prices move quickly. Our ChatGPT pricing guide tracks the current tiers, and the Pro 200 cut announced at DevDay is a good example of why you should recheck before committing.

What are Bedrock Managed Agents, and are they right for AWS shops?

Bedrock Managed Agents is an OpenAI and Amazon collaboration, built on the Agents API, that runs OpenAI agents entirely inside AWS. According to The Next Web, customer data never leaves AWS. It is a limited preview, so treat it as something to apply for, not to plan a rollout on.

The reported design keeps all inference on Amazon Bedrock, uses AgentCore as the default compute environment and gives each agent its own identity with complete action logging for audit. Planned additions include authorization policies, agent discovery, observability and evaluation tools. Salesforce is named as an early customer.

For an AWS-first company, the appeal is procurement and data location: one cloud, one set of controls. The unknowns are large. Sources differ on timing (The Decoder says the limited preview was first announced in April, The Next Web reports a September 29 launch), and we found no published pricing or plan restrictions. Ask your AWS account team before you commit.

How is the Agents API different from building your own agent loop?

With the Agents API, OpenAI runs the harness: it manages the loop, context compaction, multi-agent orchestration and tool calling, and keeps state across a long task. With the Agents SDK or your own code, you run the loop and control approvals and storage. Managed saves engineering time. Building keeps control.

That split comes from OpenAI’s Agents developer guide, which says to choose a runtime “based on where you want orchestration to run and who should manage the state between tasks.” Both routes sit on top of the Responses API and support guardrails, tracing and handoffs between agents.

A managed harness does not remove your obligations. One independent review of the managed Agents API points out that moving to it does not automatically migrate your permissions, acceptance tests or data duties. The same review could not verify retention or residency claims, and advises keeping your own business records rather than relying on a provider session ID.

How safe is OpenAI computer use, and what are the risks?

Computer use can affect real accounts and data, and OpenAI’s own guide says so. The main risks are agents acting beyond their brief, hostile instructions hidden in web pages, and irreversible mistakes. Treat every screen as untrusted, run agents in a sandbox, and require human approval before anything that spends money, sends data or cannot be undone.

The OpenAI computer use guide tells developers to “apply these controls in your application and execution environment as well as in the model’s instructions.” It also treats typing sensitive information into a form as a data transmission that needs explicit authorization.

Scope is a live concern at OpenAI itself. On September 28, the company said it would not release GPT-6.1 Astra. Safety head Saachi Jain said the model “didn’t quite meet the bar in terms of staying within scope and authorization,” per CBS News. Our OpenAI Astra computer use risk analysis covers what that means for teams giving agents real access.

Outside attackers are active too. Palo Alto Networks’ Unit 42 research on indirect prompt injection documented real-world web pages that hide instructions for AI agents, including attempts to trigger payments and destroy data. OpenAI says its models are “much less likely to make a mistake while navigating the desktop and the browser.” That is a vendor claim, not an independent test.

A sensible minimum control set:

  • Run the agent in an isolated browser or virtual machine with a domain allowlist.
  • Give it a dedicated account with the least permissions the task needs.
  • Require human approval for purchases, deletions, outbound data and permission changes.
  • Set step, time and cost limits, with a way to cancel a run.
  • Keep screenshots and action logs so someone can review what happened.

Rehearse With Read-Only Access

Run the first two weeks against a staging copy using a read-only role, and have a person compare the agent’s action log with what they would have done. Only grant write access once it has repeated clean runs.

What can you build with OpenAI computer use agents?

The best fits are repetitive, screen-based jobs where no API exists or the API is incomplete: testing web apps, moving data between older systems, and routine admin in tools like an LMS. These are possibilities, not proven deployments. We found no published case studies for the new API yet, so pilot small and measure.

Can OpenAI computer use run QA on a web application?

Yes, in principle. An agent can register an account, complete a checkout or step through a course player, and capture a screenshot where something breaks. That suits exploratory testing and quick regression passes on interfaces that change often, though it is unproven at scale.

It does not replace scripted tests. A Playwright suite is cheaper, faster and repeatable, and OpenAI’s guide even lets the model write Playwright code. Use the agent to find problems a script would never look for, then turn what it finds into scripts.

Can it enter data into a legacy system?

It can try. Older HR, finance or student-record systems often lack an API, so people re-key data between screens. An agent that reads a spreadsheet and fills the forms is a natural candidate, with a human approving each batch before it is saved.

The catch is accuracy. A misread field is a silent error, so build in a verification step: have the agent screenshot the saved record and compare it with the source. Reserve unattended runs for low-risk records.

Can it handle LMS admin chores like bulk enrolment or report exports?

Possibly. Enrolling a cohort, reassigning overdue compliance courses, or exporting completion reports from an LMS that lacks a clean API are all click-heavy tasks. Where your LMS supports CSV import, SCORM or xAPI reporting, or an API, use those first. An agent is the fallback for the gaps.

Add a compliance and permissions caution. Learner records hold personal data, and a wrong completion record can become an audit problem. Use a dedicated service account with only the roles needed, log every action, and keep a person in the loop for anything touching compliance training status. If you are choosing a platform, our list of the top AI-powered LMS platforms is a starting point if you are weighing platforms with AI features built in. For more on training uses of the model family, see GPT-6 Astra for learning and development.

Not every job needs a full agent. The new OpenAI Decisions API can sort requests into a fixed set of answers before an agent acts, and OpenAI Dots give individuals an always-on agent with its own cloud computer and browser, with no code. If the job is software rather than clicking, Codex cloud is the closer tool.

How much does the OpenAI Agents API with computer use cost?

Most of the cost is model tokens, and computer use adds up because each step sends a fresh screenshot back to the model. As of September 30, 2026, GPT-6.1 Sol lists at $2 input and $10 output per million tokens, against $10 and $50 for GPT-6 Astra. Ultrafast raises rates up to six times.

Model or tier Input per 1M tokens Output per 1M tokens Notes
GPT-6.1 Sol $2 ($0.10 cached) $10 One-fifth of Astra’s standard price
GPT-6 Astra $10 ($1 cached) $50 OpenAI’s top model
GPT-6 Astra Ultrafast $60 $300 Up to 6x faster in the API
GPT-6.1 Sol Ultrafast Not announced Not announced “Coming soon”

The Sol case rests on OpenAI-reported results relayed by Unite.AI: on the OSWorld 2.0 computer-use benchmark, Sol scores within 2.1 points of Astra at one-seventh the cost. Artificial Analysis puts cost per task at $0.72 for Sol against $3.26 for Astra. Our GPT-6 Sol vs Luna vs Astra comparison explains where each model fits.

Token rates are not your total bill. The independent Wavect review reports no additional Agents API platform fee, but notes that real cost includes tools, compute, retries, human review and operations. It also warns that parallel subagents cut latency while increasing the compute you buy. Measure cost per accepted task, not cost per run.

Cap the Loop Before Scaling

Set a hard step and dollar limit per task from day one. Start on Sol, log which step types fail, and move only those steps to Astra rather than upgrading the whole workflow.

Should you build your own agent or use the managed Agents API?

Use the managed Agents API when you want to ship quickly, lack platform engineers and can accept OpenAI-hosted infrastructure. Build your own loop when you need custom approvals, strict data location or several model providers. AWS-first regulated companies should watch Bedrock Managed Agents. Most training teams should start with a small managed pilot.

Your situation Better fit Why
Small team, no platform engineers Managed Agents API OpenAI runs the harness and state
Custom approval steps or your own storage Agents SDK or own loop You control the loop, approvals and records
Data must stay inside AWS Bedrock Managed Agents Reported to keep customer data in AWS; limited preview
Need to switch model vendors later Own loop Avoids tying business records to one provider
One person automating their own tasks Dots, no code No development needed, where available
Task has a stable API Plain API integration Cheaper and more reliable than clicking

For training operations, the honest default is a scoped pilot rather than a platform decision. Pick one task, define what “correct” looks like, and only then decide how much of the stack to own.

Conclusion

Your next step is a two-week pilot on one low-risk, repetitive task, such as exporting a weekly LMS completion report or running a smoke test on your course player. Use a dedicated account, a sandbox or staging copy, read-only access first, and a written definition of a correct result.

Track three numbers: how often a person had to step in, cost per accepted task, and how long review took. If the agent cannot beat your current process on those, you have your answer cheaply. Before you go live, confirm data retention, residency and plan access with OpenAI or your AWS account team.

Then read the wider picture in our DevDay 2026 announcements guide to see how the Agents API fits with Dots, Codex and the new plans.

FAQ

Q1. What is the OpenAI Agents API?

The Agents API is OpenAI’s managed service for running agents. OpenAI operates a Codex-style harness that handles long tasks, including multi-agent tools, tool search, tool calling and context compaction, so developers do not host the runtime themselves. It has been in public beta since September 11, 2026, and gained computer use at DevDay on September 29.

Q2. Does the OpenAI Agents API support computer use?

Yes. Since DevDay on September 29, 2026, the Agents API supports computer use, meaning agents can click, type and navigate software to complete tasks. It is available through the API, and through Codex and ChatGPT Work on Pro 500 and Enterprise plans. Plus and free ChatGPT users do not get it.

Q3. Is the OpenAI Agents API available on ChatGPT Plus?

No. OpenAI says the computer use features in ChatGPT Work and Codex are for Pro 500 and Enterprise plans, and Plus and free users are excluded. Developers can still call the Agents API directly with an API account. Plan details change often, so confirm what your own account includes before you build around it.

Q4. What are Bedrock Managed Agents?

Bedrock Managed Agents is an OpenAI and Amazon collaboration, built on the Agents API, that runs OpenAI agents entirely inside AWS. Reporting says customer data never leaves AWS and inference runs on Amazon Bedrock. It is a limited preview, and we found no published pricing or plan restrictions, so ask your AWS account team.

Q5. Is OpenAI computer use safe for business systems?

It can affect real accounts and data, so safety depends on your controls. OpenAI’s guidance is to use sandboxed browsers or virtual machines, treat screen content as untrusted, require human approval for purchases, data transmission and irreversible changes, and set step, time and cost limits. Start with read-only access on a staging copy.

Q6. How much does the OpenAI Agents API cost?

Most cost is model tokens. As of September 30, 2026, GPT-6.1 Sol lists at $2 input and $10 output per million tokens, and GPT-6 Astra at $10 and $50. Ultrafast costs up to six times more. An independent review reports no extra platform fee, but retries, review and infrastructure still add cost.

Q7. What is the difference between the Agents API and the Agents SDK?

With the Agents API, OpenAI runs the harness and manages state across long tasks. With the Agents SDK, you run the agent loop inside your own application and control approvals and storage. The API saves engineering effort, while the SDK gives more control over workflow, data location and records.

Rohan Mehta

Written by Rohan Mehta

Rohan ran operations for a mid-size commercial training company before turning to writing full-time, so his advice on scheduling, instructor logistics, and revenue-per-course tends to come from having actually lived the spreadsheet chaos he now writes about avoiding. He covers the business side of training delivery, the parts that don’t show up in a course catalog but determine whether a training company is profitable. He’s opinionated about TMS platforms and will tell you exactly why.

Table of contents