OpenAI for AI agents

OpenAI's API gives developers access to language, image, and audio models along with tools for managing files, assistants, and fine-tuning jobs. Product teams build AI features on top of it. Connect it once through Arc0, and your agent, or Claude, ChatGPT and Cursor, can use it through one MCP endpoint, limited to what each user approved.

AI and modelsAPI keyMCP + RESTopenai.com
AUDIT LOG · OPENAIPOLICY: acme-support
09:41:07 · claude · u_8f2read
openai.list_runs
List Runs✓ allowed · 212ms
09:41:08 · claude · u_8f2read
openai.get_eval
Get Eval✓ allowed · 164ms
09:41:09 · claude · u_8f2write
openai.create_run
Create Run✓ approved · approved by user
09:41:12 · claude · u_8f2destructive
openai.delete_eval
Delete evaluation✕ blocked · policy: deny
EVERY OPENAI CALL, ON THE RECORD
01 · USE CASES

What agents do in OpenAI.

01

Generate a chat completion

Send a prompt and conversation history to a model and return a generated response.

02

Transcribe an audio file

Convert a recorded audio file into text using the audio transcription endpoint.

03

Check fine-tuning job status read-only

List fine-tuning jobs and events to monitor progress without starting a new one.

02 · ACTIONS

126 OpenAI actions, graded by risk.

Every OpenAI action is tagged read, write or destructive, so one policy covers the whole app and new actions inherit the right default.

read

57

Look things up. Allowed by default.

  • openai.get_eval
    Get Eval
  • openai.get_video
    Get Video
  • openai.list_runs
    List Runs
  • openai.list_evals
    List Evals
  • openai.list_files
    List files
  • openai.get_message
    Get Message
  • openai.list_models
    List models
  • openai.list_skills
    List Skills
  • openai.list_videos
    List Videos
  • openai.get_eval_run
    Get Evaluation Run
  • openai.get_response
    Get Response
  • openai.get_run_step
    Get Run Step
  • openai.list_batches
    List Batches
  • openai.list_engines
    List engines
  • openai.list_threads
    List ChatKit Threads
  • openai.get_eval_runs
    Get Evaluation Runs
+ 41 MORE

write

48

Create and change things. Allow, or ask the user first.

  • openai.create_run
    Create Run
  • openai.create_eval
    Create Eval
  • openai.update_eval
    Update Eval
  • openai.create_batch
    Create Batch
  • openai.create_image
    Generate Image
  • openai.create_skill
    Create Skill
  • openai.create_video
    Create Video
  • openai.create_speech
    Create Speech (TTS)
  • openai.create_thread
    Create Thread
  • openai.create_upload
    Create Upload
  • openai.create_message
    Create Message
  • openai.add_upload_part
    Add Upload Part
  • openai.create_eval_run
    Create Evaluation Run
  • openai.create_response
    Create Response
  • openai.create_container
    Create Container
  • openai.create_completion
    Create Completion (Legacy)
+ 32 MORE

destructive

21

Delete, cancel or archive. Ask first, or deny outright.

  • openai.cancel_run
    Cancel Run
  • openai.delete_eval
    Delete evaluation
  • openai.delete_file
    Delete file
  • openai.cancel_batch
    Cancel batch
  • openai.delete_skill
    Delete skill
  • openai.delete_video
    Delete video
  • openai.cancel_upload
    Cancel upload
  • openai.delete_thread
    Delete thread
  • openai.delete_message
    Delete message
  • openai.cancel_eval_run
    Cancel evaluation run
  • openai.cancel_response
    Cancel Response
  • openai.delete_eval_run
    Delete evaluation run
  • openai.delete_response
    Delete response
  • openai.delete_assistant
    Delete assistant
  • openai.delete_container
    Delete container
  • openai.delete_conversation
    Delete conversation
+ 5 MORE
03 · HOW IT WORKS

OpenAI in three steps.

  1. 01Your users connect OpenAIThey add their OpenAI api key on Arc0 Connect, under your brand. It goes straight into the vault.
  2. 02You set the rulesReads run, writes like “create Run” can wait for the user, and “delete evaluation” can be denied outright.
  3. 03Any agent can actYour agent calls OpenAI through the Arc0 SDK or MCP, and so can Claude, ChatGPT and Cursor. Every call lands on the audit log.
POLICY.TS
await arc0.policies.set('openai', {
  read: 'allow',
  write: 'ask',        // create_run
  destructive: 'deny',  // delete_eval
})

# Claude Code: the same connection, one URL
$ claude mcp add --transport http arc0 \
    https://mcp.arc0.ai/u/u_8f2
04 · AUTH AND DATA

How OpenAI connects.

Users add their OpenAI api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

The same OpenAI connection serves your agent over MCP and your own backend over REST and the proxy, so a user connects once. How Arc0 handles credentials →

AUTH
API key
CREDENTIALS
Per-tenant encrypted vault
MODEL SEES
Results only, never credentials
AUDIT LOG
Every call, on every plan
05 · WORKS WITH

Use OpenAI from any agent.

Claude
ChatGPT
Cursor
Codex
VS Code
OpenAI Agents SDK
Claude Agent SDK
Vercel AI SDK
Mastra
LangGraph
07 · FAQ

OpenAI and Arc0, answered.

Q01

Can I use OpenAI with Claude, ChatGPT or Cursor?

Yes. Connect OpenAI to Arc0 once, then add your Arc0 MCP URL to Claude, ChatGPT, Cursor, Claude Code or any other remote-MCP client. Each assistant only gets the OpenAI actions you allow.

Q02

How do users connect OpenAI?

Users add their OpenAI api key on Arc0 Connect. It is encrypted in the vault, never shown to the model, and each user can rotate or revoke it at any time.

Q03

Which OpenAI actions can my agent take?

126 in total: 57 read, 48 write and 21 destructive, such as “create Run”. Your policies decide which of them each agent may call.

Q04

Can I stop my agent from deleting things in OpenAI?

Yes. Actions like “delete evaluation” are graded destructive. Set destructive actions to deny, or to ask so the user approves each one, and blocked calls still show up on the audit log.

Q05

Can my own backend call OpenAI too?

Yes. The same OpenAI connection is available over REST and through the Arc0 proxy, so your product and your agent share one connection per user.

Get started

Plug OpenAI into your agent.

Your users connect OpenAI once, under your brand. Your agent gets 126 actions behind your policies, with every call on the record.

Free to build · MCP + REST · Audit log on every plan