openai_web_search

Web search filter for model-driven web_search_call dispatch.
On this page

Web search filter for model-driven web_search_call dispatch.

Configuration Notes

Detects pending web search calls in the response phase and executes them on re-entry via the iterative_request_router agentic loop.

Each provider request is executed through the shared filtered-subrequest executor, which enforces destination authority, DNS/SSRF, TLS/SNI, and Host centrally. An optional outbound_chain runs operator-managed cross-cutting filters (headers, credentials, logging) on the callout; when omitted it defaults to an empty inline chain (pure passthrough), so the central protections still apply.

Configuration

FieldTypeRequiredDescription
providerbrave | tavily | youyesSearch backend provider.
user_credentialstringnoOptional callout-credential slot id (see [WebSearchFilterConfig::user_credential]).
api_keystring (secret)yesAPI key for the search provider (supports ${ENV_VAR}). Wrapped in [SecretString] to prevent accidental logging.
default_context_sizestringnoDefault search context size when the client omits it.
timeout_msintegernoCallout timeout in milliseconds. Inside an iterative request router, the effective timeout is capped by the router’s remaining deadline.
max_calls_per_roundintegernoHard cap on web-search calls processed from one model response (1..=1024; default: 32).
base_urlstringnoOverride the provider’s default API base URL.
outbound_chainstring | objectnoOutbound filter chain the provider callout executes through. See [WebSearchFilterConfig::outbound_chain]; the two configs stay in sync. Optional — when omitted it defaults to an empty inline passthrough chain via [default_outbound_chain].

Examples

Example 1

filter: openai_web_search
provider: brave
api_key: ${WEB_SEARCH_API_KEY}

Example 2

filter: openai_web_search
provider: brave
api_key: ${WEB_SEARCH_API_KEY}
outbound_chain: web_search_outbound
default_context_size: medium
timeout_ms: 10000
max_calls_per_round: 32