Delegate a task to Codex
codex_delegateDelegate coding tasks to the local Codex CLI, picking model and reasoning effort per run. Use it for second opinions, long investigations, or file edits without flooding your own conversation.
Instructions
Delegate a task to the local Codex CLI (OpenAI's coding agent), choosing model and reasoning effort. Use it when the user asks for Codex, or when handing work off clearly serves their request: a second opinion from a different model family, or an investigation that would otherwise flood this conversation. When the user has not named a model, call codex_recommend first and present its suggested model and effort to the user in the same message in which you say you are going to delegate, then pass both explicitly here. That recommendation is advice for an already-authorised delegation, not a replacement for the user's own preference. Everything passed in prompt, context and target_files is sent to OpenAI, and every run spends the user's own Codex usage, so do not delegate what you can answer directly, and tell the user when you delegate. Codex runs read-only unless a different default sandbox is configured. Set sandbox to workspace-write to let it edit files. Codex cannot see this conversation, so pass everything it needs in prompt, context, and target_files.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| mode | No | blocking (default) waits and streams progress; background returns a job_id immediately. | |
| model | No | Catalog slug from list_codex_models. If omitted, the configured default is used; with no default configured the call is refused and the recommended model is returned. | |
| prompt | Yes | The task for Codex. Be specific and self-contained: Codex cannot see this conversation. | |
| context | No | Background Codex needs: prior findings, constraints, relevant excerpts. | |
| sandbox | No | Sandbox policy. Uses the configured default when omitted; without one, Codex runs read-only. | |
| add_dirs | No | Additional absolute directories that should be writable alongside working_dir. | |
| web_search | No | Enable Codex's API-backed live web-search tool for this run. In a read-only sandbox, shell commands have no network access, so this is the route to current external information. When omitted, Codex's own configured web_search mode applies. | |
| working_dir | No | Absolute path Codex uses as its working root. | |
| auto_approve | No | Adds --approve-for-me so Codex auto-approves its own commands. Only applies when sandbox is workspace-write. | |
| target_files | No | Paths Codex should focus on, relative to working_dir. | |
| use_worktree | No | Run in a managed git worktree. Writes outside it remain subject to the sandbox policy and add_dirs. | |
| output_schema | No | A JSON Schema object for this turn's final message, which then comes back as JSON in a delimited block. OpenAI's structured outputs apply: every object needs "additionalProperties": false and every property listed in "required". At most 64 KiB serialised. | |
| timeout_seconds | No | Wall-clock budget. Defaults to 1800s. | |
| reasoning_effort | No | Reasoning depth, independent of model choice. Uses the configured default or the model's default when omitted. Clamped to supported levels within the configured ceiling; refused if none qualify. | |
| acceptance_criteria | No | Concrete conditions that must hold for the task to be considered done. | |
| skip_git_repo_check | No | Allow running outside a git repository. | |
| system_instructions | No | Persona or extra rules inherited from the orchestrator, layered on the built-in quality contract. |