codex-app-server-mcp
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| CODEX_MODEL | No | Model ID to use. If unset, Codex default is used. Can be overridden per call via the model parameter. | |
| CODEX_EXECUTABLE | No | Path to the Codex executable. If not set, the server searches for 'codex' in PATH (also .exe, .cmd, .bat on Windows). | |
| CODEX_STATE_PATH | No | Path to a local JSON file used as an atomic state index for task metadata (excluding prompts, replies, credentials). | |
| CODEX_SANDBOX_MODE | No | Sandbox mode for Codex. Defaults to 'read-only'. Set to 'workspace-write' to allow modifications within the workspace. Other values cause startup failure. | |
| CODEX_ALLOWED_ROOTS | No | Semicolon-separated list of directories or a JSON array string. Required when CODEX_SANDBOX_MODE is 'workspace-write'. Task cwd must be within this whitelist. | |
| CODEX_APP_SERVER_URL | No | WebSocket URL of an existing Codex app-server. If set, remote mode is used; otherwise local mode spawns a child process. wss:// required for remote hosts; ws:// only allowed for localhost, 127.0.0.1, or ::1. | |
| CODEX_REMOTE_TOKEN_FILE | No | Path to a file containing the bearer token for remote WebSocket authentication. Mutually exclusive with CODEX_REMOTE_BEARER_TOKEN. | |
| CODEX_REMOTE_BEARER_TOKEN | No | Bearer token for remote WebSocket authentication. Mutually exclusive with CODEX_REMOTE_TOKEN_FILE. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {
"listChanged": true
} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| codex_startA | 在新的或已有 Codex thread 中启动任务,立即返回 jobId。可用 model 参数指定本次任务模型。配置模型:Codex 默认配置 / 已有会话模型。当前沙箱:read-only;只读,禁止修改文件。权限由用户启动配置决定,工具参数不能更改。 |
| codex_statusA | 查询 Codex 任务状态和已经收到的助手答复。传入 cursor 时只返回新增输出;waitMs 可长轮询最多 30 秒。 |
| codex_cancelA | 请求中断正在运行的 Codex 任务;终态以后才确认取消。 |
| codex_modelsB | 从当前 Codex app-server 实时读取可用模型列表。可使用 nextCursor 继续读取下一页。 |
| codex_steerA | 向当前运行中的普通 Codex turn 补充指令;不会改变沙箱或审批策略。 |
| codex_reviewC | 对已有 Codex thread 启动原生代码审查。仅接受明确的审查目标。 |
| codex_compactA | 压缩已有 Codex thread 的上下文,适用于长会话;作为一个异步任务返回 jobId。 |
| codex_pending_inputB | 列出某个任务正在等待回答的 Codex 问题。 |
| codex_answer_inputA | 提交 codex_pending_input 返回的问题答案,并恢复任务;不能用于批准命令或文件变更。 |
| codex_doctorB | 检查桥接模式、Codex 可执行文件、初始化状态、沙箱、目录白名单和任务索引配置。 |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 10 tools
Each tool maps to a distinct Codex operation: start, status, cancel, steer, review, compact, pending input, answer input, model listing, and diagnostics. Even similar actions like codex_steer and codex_answer_input are cleanly separated by their stated purpose.
The codex_ prefix and snake_case style are consistent throughout, making the family easy to recognize. Minor deviations exist: codex_models and codex_status are noun-like rather than verb_noun, while most others follow an action-oriented pattern.
Ten tools is a well-scoped set for managing Codex tasks and app-server operations. Each tool covers a meaningful lifecycle or capability without unnecessary redundancy.
The surface covers the main task lifecycle: start, monitor, cancel, steer, answer pending input, compact context, and review. Minor gaps exist around broader thread history or explicit thread deletion, but these are not essential for the core workflow.