# Code interpreter (`type: "code_interpreter"`) **Status:** DOCUMENTED · LIVE_VERIFIED (2026-09-18, `gpt-5.4-nano`, auto container; container retrieved/listed/deleted through `/v1/containers`) **Sources:** https://developers.openai.com/api/docs/guides/tools-code-interpreter · https://developers.openai.com/api/reference/resources/containers · https://developers.openai.com/api/docs/pricing#built-in-tools · openapi-master.yaml `CodeInterpreterTool`, `AutoCodeInterpreterToolParam`, `ContainerMemoryLimit`, `ContainerNetworkPolicy*`, `CodeInterpreterToolCall`, `CodeInterpreterOutputLogs|Image` **Last verified:** 2026-09-18 ## Parameters | Parameter | Type / enum | Req. | Notes | |---|---|---|---| | `type` | `code_interpreter` | yes | model knows it as the "python tool" | | `container` | string container id **or** object | yes | explicit mode: create via `POST /v1/containers` and pass `cntr_…` | | `container.type` | `auto` | yes (object form) | auto container, `name: "auto"`, expires 20 min after `last_active_at` | | `container.file_ids` | string[] ≤ 50 | no | files copied into `/mnt/data`; input files of the request are auto-uploaded | | `container.memory_limit` | `1g` (default) \| `4g` \| `16g` \| `64g` | no | billed per tier | | `container.network_policy` | `{type:"disabled"}` \| `{type:"allowlist", allowed_domains[] (≥1), domain_secrets[] {domain, name, value}}` | no | default: no outbound network; org allow-list governs | | `allowed_callers` | `["direct"\|"programmatic"]` | no | programmatic tool calling | `include: ["code_interpreter_call.outputs"]` returns `outputs`. ## Output `code_interpreter_call` `{id:"ci_…", type, status: in_progress|interpreting|completed|incomplete|failed, container_id, code, outputs: [{type:"logs", logs} | {type:"image", url}] | null}`. Files the model creates are cited as `container_file_citation {container_id, file_id, filename, start_index, end_index}` annotations and downloadable via `GET /v1/containers/{id}/files/{file_id}/content`. ## Streaming (spec; not streamed live to save cost) `response.code_interpreter_call.in_progress` → `response.code_interpreter_call_code.delta` (`delta`) → `response.code_interpreter_call_code.done` (`code`) → `response.code_interpreter_call.interpreting` → `response.code_interpreter_call.completed`. ## Billing (cited) Per container **session** (20 minutes): 1 GB $0.03 · 4 GB $0.12 · 16 GB $0.48 · 64 GB $1.92, shared with hosted shell; tokens at model rates. ## Live evidence | Probe | Status | Result | |---|---|---| | auto container, `include outputs`, `max_output_tokens 64` | 200 | `code: "print(2+2)"`, `outputs: [{type:"logs", logs:"4\n"}]`, `container_id: cntr_…`, answer `4` | | same without `tool_choice`, `max_output_tokens 128` (py example, first run) | 200 | model answered `4` **without** calling the tool → examples now force `tool_choice: {"type":"code_interpreter"}` | | `GET /v1/containers/{id}` | 200 | `status: "running"`, `memory_limit: "1g"`, `expires_after: {anchor: last_active_at, minutes: 20}`, `name: "auto"` | | `GET …/files` | 200 | empty list (no files produced) | | `DELETE /v1/containers/{id}` | 200 | `{object: "container.deleted", deleted: true}` | Security (docs): network-enabled containers = exfiltration/prompt-injection risk; allowlist only trusted domains; inject credentials with `domain_secrets` (model sees placeholders). See [containers](../../openai/containers.md) for the full API. Examples: `examples/openai/tools/code-interpreter/`. Test (expensive): `test_code_interpreter_auto_container`.