Plugins

Open WebUI Now Lets Your Local AI Ask Before It Acts

Open WebUI logo on a soft pastel background representing new tool permissions and approval features.
Open WebUI now gives users more control over how local AI models use tools.

Open WebUI released two updates close together this summer that changed how tools and plugins work in practice. Version 0.11.0 arrived on July 27, 2026, followed by v0.11.1 on August 25. While 0.11.0 also brought noticeable interface changes, this article focuses on the tool and plugin features introduced across both releases.

What Changed With Tools

If you have used tools in Open WebUI before, you probably know where things start to feel risky. Giving a model access to a tool that reads a file is one thing. Letting it send a message, delete something, or make an API request is a much bigger step. Before this update, the main choice was simply whether the tool was attached to the conversation or not.

Version 0.11.1 adds a new Tool Permissions setting directly to the chat input. An administrator first needs to enable the feature from the Interface section in Admin Settings. Once enabled, each conversation can use either Full access, which works like the old system, or Ask for approval.

With approval enabled, tool calls do not run immediately. Instead, Open WebUI shows a card in the chat with the tool name and the exact arguments the model wants to use. You can then approve or deny the request. If you deny it, that rejection is sent back to the model as the tool result, and the conversation continues without the requested data.

Your permission choice stays active for the rest of that conversation and also becomes the default for future chats. Automations, channel replies, and temporary chats do not use this permission system.

The Model Can Now Ask You a Question Mid-Response

A new built-in tool called ask_user allows the model to stop partway through a response and ask you a structured question directly in the chat. Once you choose an option, the model can use that input to continue and finish its answer.

The card gives you two or three labeled choices, with one marked as the recommended option. If none of them fit, there is also a field where you can type your own answer. Unanswered cards remain in the conversation too, so they will still be there if you leave the chat and return later.

The main benefit is that the model no longer has to guess when it is missing important information. If it needs to know something like your backup schedule, it can ask directly instead of making an assumption that you have to correct in the next message. For tasks that involve an actual choice, that can remove an entire extra back-and-forth.

Sub-Agents Arrived in 0.11.0, but They Are Disabled by Default

Version 0.11.0 added sub-agents, which let a model hand parts of a larger task to separate helper agents. Each helper runs its own conversation, can use tools, and then sends its results back to the main chat.

Before enabling the feature, it is worth checking the settings carefully. Open WebUI makes it clear that every sub-agent is effectively its own chat with full tool access, which also means more LLM calls. Administrators can control how many sub-agents run at the same time, whether they continue working while the main chat moves on, how many tool loops they are allowed, how much output they can return, and which system prompt they share.

Sub-agents are disabled by default and need to be turned on by an administrator.

What Else Changed Across These Two Releases

The slash menu now includes /model, which opens the model selector straight from the keyboard, so you can switch models in the middle of a chat without touching the mouse. /temporary starts a new conversation in temporary mode before the first message is sent, while /settings opens the settings panel without taking you out of the chat.

The Tools and Skills sections inside the Integrations menu also gained search boxes. That makes larger lists much easier to manage since you can search by name instead of scrolling through everything.

Streaming responses were improved too. Previously, Open WebUI kept sending the full generated response again with every update, which caused the amount of transferred data to grow heavily during long outputs. In v0.11.1, it only sends the newly generated part each time. According to Open WebUI, a 250,000-character response dropped from around 1.5GB of streaming traffic to less than 2MB.

The Model Behind These Features Matters

Sub-agents and tool approvals depend heavily on the model using them. A model that knows when to call a tool, when to ask for more information, and how to follow approval rules will behave very differently from one that makes up tool calls or handles them poorly.

Local models have gotten much better at tool calling, but support still varies a lot between models. If you plan to use sub-agents or approval mode, it is worth testing the exact model you want to run instead of assuming it will handle these features properly.

Sources

Open WebUI v0.11.0 release notes

Open WebUI v0.11.1 release notes

Published Oct 5, 2026