Short answer: Give the logical operation a stable identity and route supported consequential execution through durable state and provider reconciliation instead of treating every tool invocation as a new operation.
The duplicate-tool-call failure
- An OpenAI Agent invokes a consequential tool.
- The external provider performs the action.
- The response is lost or times out.
- The application cannot prove whether the action happened.
- The agent retries the tool.
- A blind retry can duplicate the side effect.
The Once pattern
const operationId = Once.id("refund", orderId);
await once.execute({
operationId,
provider,
action: {
type: "refund",
order_id: orderId
}
});
The same logical refund receives the same operation ID on every retry. A retry is therefore not automatically treated as permission to perform a new external action.
OpenAI Agents example
The Once repository includes a working JavaScript example using the OpenAI Agents SDK function-tool pattern with @once-agent/sdk.
View the Once + OpenAI Agents example on GitHub
Claim boundary: Once does not claim universal exactly-once execution. Safety depends on stable operation identity, durable Once state, the provider integration and sufficiently authoritative provider truth. When the outcome cannot be established safely, Once can preserve uncertainty instead of blindly repeating the action.
Add execution safety to agent writes
npm install @once-agent/sdk