codex-cli-mcp
Allows MCP clients to run OpenAI Codex CLI sessions in headless mode, enabling code generation and execution via prompts.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@codex-cli-mcpRefactor the authentication module to use JWT"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
Bridge OpenAI Codex CLI to any MCP client
English | 한국어
npm · GitHub · Issues
Overview
An MCP (Model Context Protocol) server that wraps OpenAI Codex CLI as tools. It enables MCP clients like Claude Desktop, Cursor, and Windsurf to run Codex CLI sessions in headless mode.
Related MCP server: Codex Bridge MCP
Prerequisites
1. Install Codex CLI
Install Codex CLI (docs) and make sure it is available in your PATH:
# npm
npm install -g @openai/codex
# Homebrew (macOS)
brew install --cask codexOr download the binary from GitHub Releases.
2. Authenticate
Option A — ChatGPT Login (Recommended)
Run codex and select "Sign in with ChatGPT". Requires a Plus, Pro, Team, Edu, or Enterprise plan.
Option B — API Key
For headless / CI environments:
export OPENAI_API_KEY="your-api-key"See the Codex Authentication docs for more details.
Tools
See Codex Models for available models.
codex
Start a new Codex CLI session.
Parameter | Type | Required | Description |
| string | Yes | The prompt to send to Codex |
| string | No | Model name override |
| enum | No | Reasoning effort: |
| enum | No |
|
| string | No | Working directory for the session |
| string | No | Configuration profile from config.toml |
| object | No | Config overrides as key-value pairs |
| number | No | Timeout in ms (default: |
codex-reply
Continue an existing Codex CLI session.
Parameter | Type | Required | Description |
| string | Yes | The follow-up prompt |
| string | Yes | Thread ID from a previous |
| string | No | Model name override |
| enum | No | Reasoning effort: |
| object | No | Config overrides as key-value pairs |
| number | No | Timeout in ms (default: |
Setup
For Humans
Copy the prompt below and paste it into your LLM agent — it will install and configure everything automatically:
Install and configure @nayagamez/codex-cli-mcp by following: https://raw.githubusercontent.com/nayagamez/codex-cli-mcp/main/docs/guide/installation.mdOr set it up manually — see Manual Setup below.
For LLM Agents
curl -s https://raw.githubusercontent.com/nayagamez/codex-cli-mcp/main/docs/guide/installation.mdManual Setup
Add to your claude_desktop_config.json:
{
"mcpServers": {
"codex-cli-mcp": {
"command": "npx",
"args": ["-y", "@nayagamez/codex-cli-mcp"]
}
}
}Add to your MCP settings:
{
"mcpServers": {
"codex-cli-mcp": {
"command": "npx",
"args": ["-y", "@nayagamez/codex-cli-mcp"]
}
}
}claude mcp add codex-cli-mcp -- npx -y @nayagamez/codex-cli-mcpProgress Notifications
The server sends MCP progress notifications in real-time as Codex processes your request. This lets MCP clients know the server is alive and working, not hanging.
Progress messages include:
[5s] Session started (thread: ...)— session initialized[12s] Command executed: npm test— a command was run[18s] Message: Refactoring the auth module...— agent reasoning[25s] Turn completed— turn finished
Idle-based Timeout
The timeout is idle-based, not absolute. The timer resets every time the server receives an event from Codex. This means long-running tasks with continuous activity will never timeout, while truly stuck processes will be killed after the configured idle period.
Default idle timeout: 10 minutes
Override per-call via
timeoutparameter, or globally viaCODEX_TIMEOUT_MS
Environment Variables
Variable | Default | Description |
|
| Path to the Codex CLI binary |
|
| Idle timeout for Codex process |
| (unset) | Set to enable debug logging to stderr |
How It Works
MCP Client → Tool Call (codex / codex-reply)
→ Spawn `codex exec --json --full-auto` as subprocess
→ Stream JSONL events from stdout
→ Send progress notifications back to client
→ Return formatted results when doneThe MCP client sends a tool call (
codexorcodex-reply)The server spawns Codex CLI with
--jsonand--full-autoflagsThe prompt is passed via stdin
JSONL events are streamed and parsed in real-time
Progress notifications are sent to the client on each event (idle timer resets)
Results (messages, commands, errors, token usage) are formatted as markdown and returned
License
MIT
Available Tools
2 toolscodexA
Run a Codex CLI session. Executes codex exec as a subprocess and returns the result.
Use this tool to start a new coding task with Codex. The response includes a Thread ID that can be used with the codex-reply tool to continue the conversation.
| Name | Required | Description | Default |
|---|---|---|---|
| cwd | No | Working directory for the Codex session | |
| model | No | Model name override. Do NOT set this unless the user explicitly requests a specific model or asks for the "latest" model — Codex CLI uses its own configured default. Known models: gpt-5.6-sol (latest, supports effort max) | |
| config | No | Config overrides as key-value pairs (passed as -c key=value) | |
| effort | No | Reasoning effort level. Auto-select based on task complexity: medium for simple tasks (quick questions, small edits), high for moderate tasks (bug fixes, features), xhigh for complex tasks (architecture, multi-file refactoring), max for the hardest tasks (deep analysis, large-scale design). Do NOT set if the user explicitly requests a specific level. | |
| prompt | Yes | The prompt to send to Codex | |
| profile | No | Configuration profile from config.toml | |
| sandbox | No | Sandbox mode for file access | |
| timeout | No | Timeout in milliseconds (default: 600000 = 10 min). Increase for long-running tasks. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the transparency burden. It discloses that it executes a subprocess, returns a result, and provides a Thread ID, but it does not warn about potential side effects (e.g., file modifications depending on sandbox mode) or mention authorization requirements. The sandbox parameter is defined in the schema, but the description adds no behavioral context beyond basic execution.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences, front-loaded with the primary action and followed by a brief usage note. Every sentence adds value—mentioning the subprocess execution, result return, Thread ID, and continuation with codex-reply. There is no redundancy or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
The tool is complex with 8 documented parameters and no output schema. The description gives enough to start a task and mention the Thread ID, but it does not describe the overall return structure, error behavior, or caveats like long-running operations (despite a timeout parameter). It is adequate but leaves gaps for an agent to fully predict behavior.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Schema description coverage is 100%, so the baseline is 3. The description itself does not elaborate on any parameters, but the schema thoroughly documents each one, including enums for effort and sandbox. Therefore, the description adds no additional parameter meaning beyond what the schema already provides.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool runs a Codex CLI session via `codex exec` and returns the result, which is specific and distinguishable from the sibling tool codex-reply. The mention of starting a new coding task and providing a Thread ID for continuation reinforces its distinct role.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description explicitly says to use this tool for starting a new coding task and implies codex-reply is for continuing, but it does not explicitly state 'do not use when continuing' or list exclusions. This is clear enough for an agent to decide, though a more explicit alternative comparison would make it stronger.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
codex-replyA
Continue a Codex CLI conversation by providing the thread ID from a previous codex call and a follow-up prompt.
Uses codex exec resume to load the previous session from disk and continue the conversation.
| Name | Required | Description | Default |
|---|---|---|---|
| model | No | Model name override. Do NOT set this unless the user explicitly requests a specific model or asks for the "latest" model — Codex CLI uses its own configured default. Known models: gpt-5.6-sol (latest, supports effort max) | |
| config | No | Config overrides as key-value pairs (passed as -c key=value) | |
| effort | No | Reasoning effort level. Auto-select based on task complexity: medium for simple tasks (quick questions, small edits), high for moderate tasks (bug fixes, features), xhigh for complex tasks (architecture, multi-file refactoring), max for the hardest tasks (deep analysis, large-scale design). Do NOT set if the user explicitly requests a specific level. | |
| prompt | Yes | The follow-up prompt to send to Codex | |
| timeout | No | Timeout in milliseconds (default: 600000 = 10 min). Increase for long-running tasks. | |
| threadId | Yes | The thread ID from a previous codex tool call |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses the underlying mechanism ('uses codex exec resume', 'loads the previous session from disk'), adding useful context. However, it does not mention potential side effects (e.g., code execution, file modifications) or error conditions. Since no annotations exist, more behavioral disclosure would be valuable.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two sentences: purpose then mechanism. It is front-loaded, concise (~30 words), with no redundant information.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With 6 parameters, no annotations, and no output schema, the description provides a clear purpose and mechanism but lacks details on return values, error handling, or safety considerations. Sufficient as a minimal viable but not fully complete for a tool that may execute code.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
Input schema coverage is 100%, so the baseline is 3. The description restates the purpose of threadId and prompt but adds no new parameter-specific details beyond what the schema already provides.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool continues a Codex CLI conversation using a thread ID and follow-up prompt, with a specific verb ('Continue') and resource ('Codex CLI conversation'). It distinguishes from sibling 'codex' by explicitly referencing 'previous codex call', implying this is for follow-ups.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear usage context: you need a thread ID from a previous call. It implicitly differentiates from starting a new conversation but does not explicitly state when not to use or name alternatives like 'codex'.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
2 tool updates
v0.4.2- First observed
codex - First observed
codex-reply
TDQS
The two tools have clearly distinct purposes: codex starts a new conversation, while codex-reply continues an existing one using a thread ID. There is no ambiguity between them, as each accepts different inputs and performs a different action.
Both tool names share the 'codex' prefix, but 'codex' is a standalone verb while 'codex-reply' is a compound with a hyphen. This is a minor inconsistency, but the pattern is predictable and readable, clearly indicating the primary action and the continuation action.
With only 2 tools, the set is on the low end of the range, but it is appropriate for the narrow scope of running Codex CLI sessions. The tools cover the essential start and continue operations, though the set feels thin compared to more comprehensive servers.
The core lifecycle of starting and continuing a conversation is covered, which covers the main use case. However, there are no tools for listing active threads, ending sessions, or retrieving session history, which are minor gaps given the focus on interactive coding tasks.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
- QuallaaOAuthcom.quallaa
Talk to your public-facing AI from any MCP client — Claude, ChatGPT, Cursor, Cline, Windsurf.
A paid remote MCP for OpenAI Codex agent coordination MCP, built to return verdicts, receipts, usage
Real-time chat for AI agents. Claude Code, Cursor, Cline and Codex join channels over MCP.
Remote MCP server for supportsheep: run AI interviews and manage support content for your blog.
Related MCP Servers
- AlicenseCqualityDmaintenanceBridges MCP clients with local Codex CLI to execute autonomous coding tasks, manage threads, and inspect history via SQLite state.137654Apache 2.0
- FlicenseNot gradedqualityBmaintenanceCodex Bridge MCP is a local MCP orchestration service for a stable Claude Code x Codex CLI development workflow.2-
- AlicenseNot gradedqualityDmaintenanceWraps OpenAI's Codex CLI as an MCP server, enabling AI clients like KiloCode, Roo Code, and Cline to leverage Codex for code generation, debugging, and analysis through natural language.52MIT
- AlicenseAqualityAmaintenanceMCP server that wraps Codex CLI as a subprocess, exposing code execution, web search, and structured output as Model Context Protocol tools.8813MIT
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/nayagamez/codex-cli-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server