codex-buddy-for-claude
Provides code review, deep thinking, and security audit capabilities using OpenAI models via API or ChatGPT subscription.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@codex-buddy-for-claudeReview main.py for security issues"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
codex-buddy-for-claude
MCP server that gives Claude Code access to OpenAI models for:
Code Review (
codex_review) — expert code review with severity ratings and actionable fixesDeep Thinking (
codex_thinkdeep) — architecture decisions, trade-off analysis, debugging hypothesesSecurity Audit (
codex_secaudit) — OWASP-aligned security audit with threat-level-aware analysis
Reports are automatically saved as markdown files to <project>/codex-reports/.
Requirements
Python 3.10+
Either an OpenAI API key (pay-per-token) or a ChatGPT Plus/Pro subscription (flat monthly fee)
Related MCP server: Claude Code Starter Kit MCP
Install
# Clone the repo
git clone https://github.com/leo919cc/codex-buddy-for-claude.git
cd codex-buddy-for-claude
# Create venv and install dependencies
python3 -m venv .venv
source .venv/bin/activate
pip install -r requirements.txtAdd to Claude Code
Add the server to your Claude Code MCP config (~/.claude.json):
{
"mcpServers": {
"codexreview": {
"command": "/absolute/path/to/codex-buddy-for-claude/.venv/bin/python",
"args": ["/absolute/path/to/codex-buddy-for-claude/server.py"]
}
}
}Replace /absolute/path/to/ with the actual path where you cloned the repo.
Then restart Claude Code. You should see the three tools available:
mcp__codexreview__codex_reviewmcp__codexreview__codex_thinkdeepmcp__codexreview__codex_secaudit
Authentication
The server supports two auth methods. It prefers OAuth (free with subscription) and falls back to API key (pay-per-token).
Option A: ChatGPT subscription (recommended)
Use your ChatGPT Plus ($20/mo) or Pro ($200/mo) subscription — no per-token API costs.
# Install Codex CLI and login (one-time)
npm install -g @openai/codex
codex loginThis saves OAuth tokens to ~/.codex/auth.json. The MCP server auto-detects them on startup. The report footer will show (subscription) to confirm.
Option B: API key (pay-per-token)
Create a .env file in the repo directory:
echo "OPENAI_API_KEY=sk-your-key-here" > .envOr export it in your shell:
export OPENAI_API_KEY=sk-your-key-hereThe report footer will show (API) when using this method.
Both configured?
If both OAuth and API key are available, OAuth is used by default (free). The API key serves as fallback if OAuth tokens expire or fail.
Configuration
Env Variable | Default | Description |
| (optional if using OAuth) | Your OpenAI API key |
|
| Default model for all tools |
You can also override the model per-call by passing the model parameter to any tool.
Supported models
Any OpenAI model works. High-reasoning models (codex/5.x series) automatically use the Responses API:
gpt-5.4(default) — high reasoninggpt-5.4-pro— xhigh reasoning (premium pricing)gpt-5.3-codex,gpt-5.2-codex,gpt-5.1-codex, etc.gpt-4o,gpt-4-turbo, etc. — use standard chat completions API
Usage
Once configured, Claude Code will automatically have access to the tools. You can ask Claude to:
"Review this file" → triggers
codex_review"Think deeply about whether we should use X or Y" → triggers
codex_thinkdeep"Run a security audit on this file" → triggers
codex_secaudit
Parameters
All tools accept:
model— override the default modelproject_dir— where to save reports (auto-detected from file paths if not set)
codex_review
files(required) — list of absolute file pathscontext— what the code does, focus areas
codex_thinkdeep
problem(required) — the question or decision to analyzecontext— constraints, what you've consideredfiles— relevant code files for grounding
codex_secaudit
files(required) — list of absolute file pathscontext— deployment context, threat modelthreat_level—low|medium|high|critical
License
MIT
Related MCP Connectors
No-data MCP handoff for local Claude Code to Codex harness moves. $49 lifetime.
Use AI models for chat, image, and video generation from Claude Code and other MCP hosts.
AI code review for GitHub PRs with an MCP autofix loop for Claude Code and Cursor
Paid remote MCP for Claude Code skill update gate MCP, structured receipts, audit logs, and reviewer
Related MCP Servers
- -licenseNot gradedqualityNot gradedmaintenanceGives Claude access to multiple AI models (Gemini, OpenAI, OpenRouter, Ollama) for enhanced development capabilities including extended reasoning, collaborative development, code review, and advanced debugging.-
- AlicenseCqualityCmaintenanceEnables AI-powered automated testing, security scanning, code review, and maintenance tasks directly within Claude Code or desktop.124MIT
- FlicenseBqualityDmaintenanceBrings OpenAI's GPT-5 capabilities to Claude Code with advanced reasoning, cost management, conversation handling, and automatic GPT-4 fallback.81-
- AlicenseAqualityDmaintenanceEnables Claude Code to delegate tasks to OpenAI's Codex CLI (GPT-5.4) with structured execution traces, parallel execution, session persistence, and adversarial code review.15MIT