openai_mcp_dispatch
Executes MCP tool calls against upstream MCP servers within the Responses API agentic loop.
On this page
Executes MCP tool calls against upstream MCP servers within the Responses API agentic loop.
Configuration
| Field | Type | Required | Description |
|---|---|---|---|
user_credential | string | no | Optional per-user bearer slot from callout_credentials. Must match the corresponding openai_mcp_tool_resolve setting. |
authorization_assertion | string | no | Optional opaque assertion slot from callout_credentials.assertions. Must match the corresponding openai_mcp_tool_resolve setting. |
outbound_chain | string | object | no | Inline outbound filter chain the MCP tools/call callout runs through. openai_mcp_dispatch runs inside an iterative_request_router step. praxis core builds each IRR step with a live chain-binding context, so an inline chain ({ name, filters }) is bound at step-build time. A named reference is rejected: IRR supplies each step an empty top-level named-chain map, so a Named reference can never resolve inside a step (see [require_inline_outbound_chain]). The chain carries only operator-configured cross-cutting filters — the SSRF-validated dial target is staged by the transport, so no upstream-selecting filter is prepended. When omitted, the callout runs through an empty chain and dials the staged target directly. Whether loopback/private MCP destinations are permitted is governed by the operator’s global insecure posture, not a per-filter flag. |
forward_headers | string[] | no | Trusted request headers forwarded to connector-backed MCP tools/call requests. No request headers are forwarded by default. Credential headers such as authorization are rejected because MCP destinations are client-selected; use the MCP tool entry’s dedicated authorization field instead. Direct, client-selected server_url targets never receive ambient request headers. |
timeout_ms | integer | no | Per-call timeout in milliseconds for tools/call calls. Inside an iterative request router, every MCP exchange is capped by the router’s remaining deadline. |
max_calls_per_round | integer | no | Hard cap on MCP calls processed from one model response, and the maximum number of mcp_approval_response items accepted from a single resume request — a resume batch cannot exceed what one round could have emitted (1..=1024; default: 32). |
max_parallel_calls | integer | no | Maximum concurrent MCP calls when parallel_tool_calls is enabled (1..=64; default: 8). |
max_result_bytes | integer | no | Maximum retained bytes for one MCP result (minimum: 1 KiB; default: 1 MiB). |
max_total_result_bytes | integer | no | Maximum retained bytes across one MCP result batch (default: 8 MiB). |
Examples
Example 1
filter: openai_mcp_dispatch
Example 2
filter: openai_mcp_dispatch
forward_headers:
- x-tenant-id
- x-user-id
timeout_ms: 30000
max_calls_per_round: 32
max_parallel_calls: 8
max_result_bytes: 1048576
max_total_result_bytes: 8388608