Skip to main content
Glama

Generate an image with Codex

codex_generate_image
Destructive

Generate an image from a text prompt and save it to a specified output path using your Codex session, without needing an API key.

Instructions

Generate an image using the image_gen tool built into Codex, and save it to output_path. No API key is needed: it runs through your Codex session. Returns the path of the file written, not the image bytes.

Input Schema

TableJSON Schema
NameRequiredDescriptionDefault
cwdNoWorking directory for the run. Must sit inside the server allowlist. Defaults to the first allowed root.
sizeNoRequested size as WIDTHxHEIGHT, e.g. "1024x1024", "1536x1024", "3840x2160".
modelNoModel slug, e.g. "gpt-5.5". Defaults to the Codex configuration.
styleNoStyle or medium, e.g. "flat minimal vector", "studio product photography".
configNoRaw Codex config overrides as key=value, TOML-parsed, e.g. 'model_reasoning_effort="high"'.
enableNoCodex feature flags to enable for this run.
imagesNoImage files to attach to the prompt. Each must be inside the allowlist.
presetNoNamed preset configured on this server instance. It supplies the subject, style, constraints and reference art, so the prompt only has to say what differs. The tool description lists the presets this instance knows; omit it on an instance that has none.
promptYesWhat the image should show. Plain language; the server wraps it in the spec Codex expects. With a preset, describe only the variation — the preset already carries the subject.
disableNoCodex feature flags to disable for this run.
sandboxNoSandbox for commands Codex runs. "read-only" forbids writes, "workspace-write" (default) allows writes inside the workspace, "danger-full-access" removes all limits and is refused unless the server was started with CODEX_MCP_ALLOW_DANGEROUS=1.
use_caseNoTaxonomy slug steering the style. One of: product-mockup, ui-mockup, logo-brand, illustration-story, infographic-diagram, photorealistic-natural, stylized-concept, ads-marketing.
worktreeNoRun in a fresh managed git worktree instead of the working directory.
ephemeralNoDo not persist the session to disk. It cannot be resumed afterwards.
constraintsNoThings the image must avoid or preserve, e.g. "no text, no watermark".
output_pathYesWhere to write the image, e.g. "assets/hero.png". Must sit inside the server allowlist.
transparentNoAsk for a genuinely transparent background and preserve the alpha channel.
output_schemaNoPath to a JSON Schema file constraining the shape of the agent final response.
timeout_secondsNoHow long to wait inline before handing back a job_id and continuing in the background. 0 means return immediately. Defaults to the server setting (120s).
reference_imagesNoReference images for style or composition. Each must be inside the allowlist.
skip_git_repo_checkNoAllow running outside a git repository.
dangerously_bypass_approvals_and_sandboxNoRemove every approval and sandbox check. Refused unless CODEX_MCP_ALLOW_DANGEROUS=1.

Schema Changelog

Changes observed during successful MCP inspections.

  1. Changed6 schema fields changedv0.0.7
    • addedInput schema / properties / preset
      Added value: +{
      +  "description": "Named preset configured on this server instance. It supplies the subject, style, constraints and reference art, so the prompt only has to say what differs. The tool description lists the presets this instance knows; omit it on an instance that has none.",
      +  "type": "string"
      +}
    • changedInput schema / properties / prompt / description
      Previous value: -"What the image should show. Plain language; the server wraps it in the spec Codex expects."New value: +"What the image should show. Plain language; the server wraps it in the spec Codex expects. With a preset, describe only the variation — the preset already carries the subject."
    • changedInput schema / properties / size / description
      Previous value: -"Requested size, e.g. \"1024x1024\", \"1536x1024\", \"3840x2160\"."New value: +"Requested size as WIDTHxHEIGHT, e.g. \"1024x1024\", \"1536x1024\", \"3840x2160\"."
    • addedInput schema / properties / size / pattern
      Added value: +"^\\d{2,5}x\\d{2,5}$"
    • changedInput schema / properties / use_case / description
      Previous value: -"Taxonomy slug steering the style: product-mockup, ui-mockup, logo-brand, illustration-story, infographic-diagram, photorealistic-natural, stylized-concept, ads-marketing."New value: +"Taxonomy slug steering the style. One of: product-mockup, ui-mockup, logo-brand, illustration-story, infographic-diagram, photorealistic-natural, stylized-concept, ads-marketing."
    • addedInput schema / properties / use_case / enum
      Added value: +[
      +  "product-mockup",
      +  "ui-mockup",
      +  "logo-brand",
      +  "illustration-story",
      +  "infographic-diagram",
      +  "photorealistic-natural",
      +  "stylized-concept",
      +  "ads-marketing"
      +]
  2. First observedv0.0.4

TDQS

A4/5.0
Behavior4/5

Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?

Annotations already carry readOnlyHint=false and destructiveHint=true, so the write/destructive profile is covered. The description adds genuine value beyond annotations by disclosing the return format (path, not image bytes) and the no-API-key requirement. No contradiction with annotations — the file-writing behavior aligns with the non-read-only hint.

Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.

Conciseness5/5

Is the description appropriately sized, front-loaded, and free of redundancy?

Three sentences with zero waste. The core action and output path are front-loaded, followed by the auth note and return-format clarification. Every sentence earns its place.

Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.

Completeness4/5

Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?

For a complex 22-parameter tool with no output schema, the description clarifies the return value and the execution mechanism, which is essential. The rich per-parameter schema descriptions cover the remaining configuration surface. Slightly more safety/limitation context would help given the destructive annotation, but the description is largely adequate.

Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.

Parameters3/5

Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?

Schema coverage is 100%, so all 22 parameters are documented in the input schema, setting the baseline at 3. The description adds marginal semantic value by tying output_path to the save behavior and clarifying the return, but it does not elaborate on individual parameters beyond what the schema already provides.

Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.

Purpose5/5

Does the description clearly state what the tool does and how it differs from similar tools?

States a specific verb ('Generate an image'), a concrete resource, and the output behavior (saves to output_path). It also clarifies the mechanism (Codex's built-in image_gen) and the return type (path, not bytes), making it clearly distinct from siblings like codex_exec, codex_apply, and the job/session tools.

Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.

Usage Guidelines3/5

Does the description explain when to use this tool, when not to, or what alternatives exist?

The description gives useful context about how the tool runs (through the Codex session, no API key needed), but offers no explicit when-to-use vs. alternatives guidance and no exclusions. The purpose is self-evident relative to siblings, but the description relies on inference rather than stating usage boundaries.

Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.