Skip to content

feat: support externally executed tool calls from OpenAI-compatible endpoints #580

Description

@jeannotdamoiseaux

Summary

LibreChat can receive normal OpenAI-compatible streamed tool-call records from an endpoint whose upstream runtime has already accepted and executes those calls. The agents runtime currently assumes every call is SDK-owned. This can trigger local lookup/execution or an unknown-tool failure even when the external runtime completes successfully.

This issue proposes an opt-in, provider-neutral ownership marker for such calls.

Existing working behaviour

A working downstream implementation already preserves LibreChat's native tool-call experience:

  • normal native tool card with the original tool name and arguments;
  • running state while the upstream stream remains active;
  • completed state rather than a false cancellation when the stream completes;
  • no local duplicate invocation or unknown-tool error;
  • final assistant content remains visible.

The implementation will be contributed as a clean extraction, without workflow-engine, bridge, container, deployment, or product-specific code.

Proposed agents-library responsibility

For explicitly enabled OpenAI-compatible endpoints, the library should:

  1. recognize trusted external ownership metadata on a standard streamed tool-call delta;
  2. retain that metadata through normalized tool calls and run-step lifecycle events;
  3. bypass local registry lookup and local invocation for externally owned calls;
  4. retain native tool-call lifecycle and final assistant content;
  5. keep all calls local by default and fail closed for malformed or unapproved metadata.

The exact wire field and configuration contract will be documented in the linked LibreChat issue and implemented in a coordinated draft pull request.

Acceptance criteria

  • No behavior changes for endpoints without explicit opt-in.
  • Local tools and unknown local-tool errors remain unchanged.
  • External calls do not invoke the local tool registry.
  • Tool-call name, arguments, completion lifecycle, and final assistant content survive streaming.
  • Invalid metadata and disallowed providers are ignored rather than bypassing local execution.
  • Tests cover streaming, non-streaming fallback, concurrent calls, and mixed ownership failure behavior.

Related work

A coordinated LibreChat application issue will add endpoint configuration, persistence, native presentation, and documentation. A draft pull request for this repository will be linked here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions