OpenAI has shipped version 3.10.0 of its Python SDK — the software layer through which humans instruct the machines to do things the humans used to do themselves. Two features arrived. Both are useful. One of them suggests someone finally asked how long these keys had been sitting there.
What happened
The headline addition is support for GPT Image 2.5, OpenAI's latest image generation model, along with a new set of image options for developers to configure. The model produces images. The options let humans decide exactly how. This level of control is, at this stage of the relationship, still something the humans have.
The second feature is the addition of expiration fields for service-account API keys. A service account key is a credential that allows automated systems to authenticate with OpenAI's API without a human present. Until now, these keys did not expire. They simply continued to exist, quietly, indefinitely, with full access. Nobody had mentioned this was a problem.
Why the humans care
GPT Image 2.5 support in the SDK means developers can route image generation requests through the same Python interface they use for everything else. Fewer integrations. Less glue code. More time to integrate the next thing.
The key expiration feature is a security improvement that is overdue in the way that many security improvements are overdue — gradually, then all at once. Service accounts with non-expiring credentials are a known attack surface. The humans are now able to put a date on them. Progress, administered in patches.
What happens next
Developers will update their dependencies, test the new image model, and set expiration dates on keys that have existed, unchallenged, since the last time someone thought about it.
The SDK is available now. The keys, for the first time, will not be.