core-agent-ide/codex-rs
Gabriel Peal 1d17ca1fa3
[MCP] Add support for MCP Oauth credentials (#4517)
This PR adds oauth login support to streamable http servers when
`experimental_use_rmcp_client` is enabled.

This PR is large but represents the minimal amount of work required for
this to work. To keep this PR smaller, login can only be done with
`codex mcp login` and `codex mcp logout` but it doesn't appear in `/mcp`
or `codex mcp list` yet. Fingers crossed that this is the last large MCP
PR and that subsequent PRs can be smaller.

Under the hood, credentials are stored using platform credential
managers using the [keyring crate](https://crates.io/crates/keyring).
When the keyring isn't available, it falls back to storing credentials
in `CODEX_HOME/.credentials.json` which is consistent with how other
coding agents handle authentication.

I tested this on macOS, Windows, WSL (ubuntu), and Linux. I wasn't able
to test the dbus store on linux but did verify that the fallback works.

One quirk is that if you have credentials, during development, every
build will have its own ad-hoc binary so the keyring won't recognize the
reader as being the same as the write so it may ask for the user's
password. I may add an override to disable this or allow
users/enterprises to opt-out of the keyring storage if it causes issues.

<img width="5064" height="686" alt="CleanShot 2025-09-30 at 19 31 40"
src="https://github.com/user-attachments/assets/9573f9b4-07f1-4160-83b8-2920db287e2d"
/>
<img width="745" height="486" alt="image"
src="https://github.com/user-attachments/assets/9562649b-ea5f-4f22-ace2-d0cb438b143e"
/>
2025-10-03 13:43:12 -04:00
..
ansi-escape chore: unify cargo versions (#4044) 2025-09-22 16:47:01 +00:00
app-server docs: add barebones README for codex-app-server crate (#4671) 2025-10-03 09:26:44 -07:00
app-server-protocol feat: add file name to fuzzy search response (#4619) 2025-10-02 18:19:13 -07:00
apply-patch chore: remove once_cell dependency from multiple crates (#4154) 2025-09-24 09:15:57 -07:00
arg0 chore: clippy on redundant closure (#4058) 2025-09-22 19:30:16 +00:00
backend-client Add cloud tasks (#3197) 2025-09-30 10:10:33 +00:00
chatgpt Add cloud tasks (#3197) 2025-09-30 10:10:33 +00:00
cli [MCP] Add support for MCP Oauth credentials (#4517) 2025-10-03 13:43:12 -04:00
cloud-tasks Support CODEX_API_KEY for codex exec (#4615) 2025-10-02 09:59:45 -07:00
cloud-tasks-client Add cloud tasks (#3197) 2025-09-30 10:10:33 +00:00
codex-backend-openapi-models Add cloud tasks (#3197) 2025-09-30 10:10:33 +00:00
common Make model switcher two-stage (#4178) 2025-10-02 19:38:24 +00:00
core [MCP] Add support for MCP Oauth credentials (#4517) 2025-10-03 13:43:12 -04:00
docs fix: separate codex mcp into codex mcp-server and codex app-server (#4471) 2025-09-30 07:06:18 +00:00
exec feat: codex exec writes only the final message to stdout (#4644) 2025-10-03 16:22:12 +00:00
execpolicy Use anyhow::Result in tests for error propagation (#4105) 2025-09-23 13:31:36 -07:00
file-search [mcp-server] Expose fuzzy file search in MCP (#2677) 2025-09-29 12:19:09 -07:00
git-apply Add cloud tasks (#3197) 2025-09-30 10:10:33 +00:00
git-tooling feat: git tooling for undo (#3914) 2025-09-23 16:59:52 +01:00
linux-sandbox chore: clippy on redundant closure (#4058) 2025-09-22 19:30:16 +00:00
login Support CODEX_API_KEY for codex exec (#4615) 2025-10-02 09:59:45 -07:00
mcp-client Add cloud tasks (#3197) 2025-09-30 10:10:33 +00:00
mcp-server Separate interactive and non-interactive sessions (#4612) 2025-10-02 13:06:21 -07:00
mcp-types chore: unify cargo versions (#4044) 2025-09-22 16:47:01 +00:00
ollama chore: clippy on redundant closure (#4058) 2025-09-22 19:30:16 +00:00
otel chore: refactor tool handling (#4510) 2025-10-03 13:21:06 +01:00
process-hardening feat: introduce npm module for codex-responses-api-proxy (#4417) 2025-09-28 19:34:06 -07:00
protocol [MCP] Add support for MCP Oauth credentials (#4517) 2025-10-03 13:43:12 -04:00
protocol-ts fix: remove mcp-types from app server protocol (#4537) 2025-10-01 02:16:26 +00:00
responses-api-proxy feat: write pid in addition to port to server info (#4571) 2025-10-02 17:15:09 -07:00
rmcp-client [MCP] Add support for MCP Oauth credentials (#4517) 2025-10-03 13:43:12 -04:00
scripts feat: add --emergency-version-override option to create_github_release script (#4556) 2025-10-01 11:40:04 -07:00
tui chore: refactor tool handling (#4510) 2025-10-03 13:21:06 +01:00
utils chore: refactor tool handling (#4510) 2025-10-03 13:21:06 +01:00
.gitignore fix: support arm64 build for Linux (#1225) 2025-06-05 20:29:46 -07:00
Cargo.lock [MCP] Add support for MCP Oauth credentials (#4517) 2025-10-03 13:43:12 -04:00
Cargo.toml [MCP] Add support for MCP Oauth credentials (#4517) 2025-10-03 13:43:12 -04:00
clippy.toml fix: clean up styles & colors and define in styles.md (#2401) 2025-08-18 08:26:29 -07:00
code Send text parameter for non-gpt-5 models (#4195) 2025-09-24 22:00:06 +00:00
config.md Added back codex-rs/config.md to link to new location (#2778) 2025-08-27 18:37:41 +00:00
default.nix restructure flake for codex-rs (#888) 2025-05-13 13:08:42 -07:00
justfile [MCP] Add experimental support for streamable HTTP MCP servers (#4317) 2025-09-26 21:24:01 -04:00
README.md fix: separate codex mcp into codex mcp-server and codex app-server (#4471) 2025-09-30 07:06:18 +00:00
rust-toolchain.toml chore: upgrade to Rust 1.90 (#4124) 2025-09-24 08:32:00 -07:00
rustfmt.toml Update cargo to 2024 edition (#842) 2025-05-07 08:37:48 -07:00

Codex CLI (Rust Implementation)

We provide Codex CLI as a standalone, native executable to ensure a zero-dependency install.

Installing Codex

Today, the easiest way to install Codex is via npm:

npm i -g @openai/codex
codex

You can also install via Homebrew (brew install codex) or download a platform-specific release directly from our GitHub Releases.

What's new in the Rust CLI

The Rust implementation is now the maintained Codex CLI and serves as the default experience. It includes a number of features that the legacy TypeScript CLI never supported.

Config

Codex supports a rich set of configuration options. Note that the Rust CLI uses config.toml instead of config.json. See docs/config.md for details.

Model Context Protocol Support

Codex CLI functions as an MCP client that can connect to MCP servers on startup. See the mcp_servers section in the configuration documentation for details.

It is still experimental, but you can also launch Codex as an MCP server by running codex mcp-server. Use the @modelcontextprotocol/inspector to try it out:

npx @modelcontextprotocol/inspector codex mcp-server

Use codex mcp to add/list/get/remove MCP server launchers defined in config.toml, and codex mcp-server to run the MCP server directly.

Notifications

You can enable notifications by configuring a script that is run whenever the agent finishes a turn. The notify documentation includes a detailed example that explains how to get desktop notifications via terminal-notifier on macOS.

codex exec to run Codex programmatically/non-interactively

To run Codex non-interactively, run codex exec PROMPT (you can also pass the prompt via stdin) and Codex will work on your task until it decides that it is done and exits. Output is printed to the terminal directly. You can set the RUST_LOG environment variable to see more about what's going on.

Typing @ triggers a fuzzy-filename search over the workspace root. Use up/down to select among the results and Tab or Enter to replace the @ with the selected path. You can use Esc to cancel the search.

EscEsc to edit a previous message

When the chat composer is empty, press Esc to prime “backtrack” mode. Press Esc again to open a transcript preview highlighting the last user message; press Esc repeatedly to step to older user messages. Press Enter to confirm and Codex will fork the conversation from that point, trim the visible transcript accordingly, and prefill the composer with the selected user message so you can edit and resubmit it.

In the transcript preview, the footer shows an Esc edit prev hint while editing is active.

--cd/-C flag

Sometimes it is not convenient to cd to the directory you want Codex to use as the "working root" before running Codex. Fortunately, codex supports a --cd option so you can specify whatever folder you want. You can confirm that Codex is honoring --cd by double-checking the workdir it reports in the TUI at the start of a new session.

Shell completions

Generate shell completion scripts via:

codex completion bash
codex completion zsh
codex completion fish

Experimenting with the Codex Sandbox

To test to see what happens when a command is run under the sandbox provided by Codex, we provide the following subcommands in Codex CLI:

# macOS
codex debug seatbelt [--full-auto] [COMMAND]...

# Linux
codex debug landlock [--full-auto] [COMMAND]...

Selecting a sandbox policy via --sandbox

The Rust CLI exposes a dedicated --sandbox (-s) flag that lets you pick the sandbox policy without having to reach for the generic -c/--config option:

# Run Codex with the default, read-only sandbox
codex --sandbox read-only

# Allow the agent to write within the current workspace while still blocking network access
codex --sandbox workspace-write

# Danger! Disable sandboxing entirely (only do this if you are already running in a container or other isolated env)
codex --sandbox danger-full-access

The same setting can be persisted in ~/.codex/config.toml via the top-level sandbox_mode = "MODE" key, e.g. sandbox_mode = "workspace-write".

Code Organization

This folder is the root of a Cargo workspace. It contains quite a bit of experimental code, but here are the key crates:

  • core/ contains the business logic for Codex. Ultimately, we hope this to be a library crate that is generally useful for building other Rust/native applications that use Codex.
  • exec/ "headless" CLI for use in automation.
  • tui/ CLI that launches a fullscreen TUI built with Ratatui.
  • cli/ CLI multitool that provides the aforementioned CLIs via subcommands.