A custom function in Agents API is a requested operation, not code OpenAI automatically executes. Your handler receives its name and arguments, performs the operation, and returns a result. The managed agent then continues. Attaching a sandbox does not implement that handler.
Where tool execution happens
Remote MCP tools can be called from OpenAI's service. Commands and local MCP tools run in the connected environment.
Custom functions have a callback boundary: you provide a schema; the agent requests a name and arguments; your application executes the operation and submits its result; the harness continues the turn. Attaching an environment does not install a function handler.
Example: an application-owned publish_reply handler can check authority, publish through its client, record the outcome, and return it.