codex-cli-sync-mcp
Allows delegating code-writing tasks to OpenAI's Codex CLI, with configurable model, timeout, and sandbox approval modes, returning the model's final message along with git diff and status summaries.
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@codex-cli-sync-mcpAdd a slugify() helper in src/lib/slug.ts with tests and run them."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
codex-cli-sync-mcp
MCP-сервер, который позволяет Claude Code (или любому другому
MCP-клиенту) делегировать выполнение ограниченных задач по написанию кода
локальному Codex CLI. Один инструмент —
codex_execute — синхронно запускает codex exec --json --skip-git-repo-check --approve-for-me -o <last-message-file> "<task>",
дожидается завершения и возвращает компактный отчёт: финальное сообщение
модели, git diff --stat, git status --short, код возврата и
threadId.
Написан по образцу opencode-v2-mcp/cursor-agent-sync-mcp: один вызов
тула блокируется до готового результата. В отличие от них, здесь не было
предыдущей рабочей MCP-обёртки для замены — существующая
@etheaven/codex-mcp-server построена под устаревший контракт флагов
(--full-auto/--ask-for-approval не существуют в установленной
codex-cli 0.155.1, вызов с sandbox/fullAuto/approvalPolicy падает
с unexpected argument '--full-auto'). Этот сервер вызывает codex exec
напрямую актуальными флагами, без слоя трансляции.
Требования
Codex CLI, установленный и авторизованный (
codex exec --version,codex login/действующий~/.codex/auth.json).Node.js 18+.
Related MCP server: codex-mcp-server
Установка
Вариант 1 — из npm (рекомендуется)
Пакет опубликован как codex-cli-sync-mcp
— полностью публичный, ставится без авторизации:
npm install -g codex-cli-sync-mcpВариант 2 — из исходников
git clone git@github.com:yuriisamohvalov-creator/codex-mcp.git ~/tools/codex-mcp
cd ~/tools/codex-mcp
npm installВариант 3 — из GitHub Packages
Тот же пакет также зеркалирован в GitHub Packages под именем
@yuriisamohvalov-creator/codex-cli-sync-mcp.
Важно: в отличие от npmjs.org, GitHub Packages требует аутентификации
даже для доступа к пакету (репозиторий приватный) — понадобится .npmrc
со scoped-registry и GitHub-токеном с правом read:packages:
# ~/.npmrc или в проекте
echo "@yuriisamohvalov-creator:registry=https://npm.pkg.github.com" >> ~/.npmrc
npm login --registry=https://npm.pkg.github.com --scope=@yuriisamohvalov-creator
npm install -g @yuriisamohvalov-creator/codex-cli-sync-mcpПодключение к Claude Code
При установке из npm (npm install -g codex-cli-sync-mcp) бинарник уже
в PATH:
claude mcp add --scope user codex -- codex-cli-sync-mcpПри установке из исходников:
NODE_BIN="$(which node)"
claude mcp add --scope user codex -- "$NODE_BIN" "$HOME/tools/codex-mcp/server.mjs"Проверка:
claude mcp get codex
# Status: ✔ ConnectedПосле подключения новой сессии Claude Code (или рестарта текущей)
инструмент доступен как mcp__codex__codex_execute.
Важно про имя сервера: если у вас уже была подключена другая
MCP-обёртка под именем codex-cli (например, @etheaven/codex-mcp-server),
регистрируйте новую под другим именем (как выше — codex), а не
переиспользуйте codex-cli. На практике харнесс Claude Code Desktop может
закэшировать набор тулов под старым именем сервера и не сбросить кэш даже
после нескольких полных рестартов приложения, хотя сам MCP-процесс уже
переключился на новый бинарник (дерево процессов это подтверждает).
Регистрация под новым именем обходит проблему мгновенно.
Использование инструмента
{
"task": "Add a slugify() helper in src/lib/slug.ts with tests. Acceptance: kebab-case, trims whitespace. Verify with `npm test -- slug`.",
"cwd": "/absolute/path/to/project",
"model": "gpt-5.1-codex", // опционально
"timeoutMs": 900000 // опционально, по умолчанию 15 минут
}Ответ:
{
"ok": true,
"exitCode": 0,
"threadId": "...",
"text": "...финальное сообщение модели...",
"diffStat": "...git diff --stat...",
"statusShort": "...git status --short..."
}Одобрение команд
По умолчанию используется --approve-for-me — безопасный режим через
workspace-write sandbox (файловые правки и команды в пределах рабочей
директории без ручного подтверждения). Флаг dangerouslyBypassSandbox
переключает на --dangerously-bypass-approvals-and-sandbox — используйте
только в средах, уже изолированных снаружи (например, контейнер/VM без
доступа к остальной системе).
--approve-for-me и явный -s/--sandbox нельзя комбинировать —
codex-cli 0.155.1 отклоняет такой вызов ошибкой; обёртка это учитывает
и не передаёт оба одновременно.
Ограничения
Одна задача — один синхронный запуск
codex exec, без параллелизма в рамках одного вызова инструмента.Долгая задача блокирует вызывающую сессию на всё время выполнения — контролируйте через
timeoutMs.Не подменяет ревью: вызывающая сторона должна самостоятельно проверять
diffStat/statusShort, а не доверять только полюok.
Лицензия
MIT
Available Tools
1 toolcodex_executeA
Execute one bounded coding task through Codex CLI (synchronous, blocks until done) and return a compact JSON report with diff/status context.
| Name | Required | Description | Default |
|---|---|---|---|
| cwd | Yes | Absolute working directory/repository root. | |
| task | Yes | Bounded coding task with goal, constraints, files, acceptance criteria, and verification command. | |
| model | No | Optional Codex model override, e.g. gpt-5.1-codex. | |
| timeoutMs | No | Internal timeout; must be below the MCP client's own per-call timeout. | |
| resumeThreadId | No | Resume a specific Codex thread id instead of starting a new one. | |
| dangerouslyBypassSandbox | No | Use --dangerously-bypass-approvals-and-sandbox instead of --approve-for-me. Only for environments that are already externally sandboxed. |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
The description discloses key behavioral traits: synchronous execution, blocking, and the return of a compact JSON report with diff/status. However, with no annotations present, it does not explicitly mention side effects (e.g., file modifications), permission requirements, failure modes, or sandbox behavior, leaving these to be inferred from the 'coding task' framing and parameter names.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The entire description is a single sentence that front-loads the action and resource, then adds the critical operational detail (synchronous, blocking) and the return type. There is no redundant wording or filler.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a tool with 6 parameters, no output schema, and no annotations, the description covers the core operation, return format, and blocking behavior. However, it leaves side effects, error handling, and security implications unstated—important for an execution tool—and relies on the `dangerouslyBypassSandbox` parameter to hint at sandboxing. Some gaps remain for high-risk use.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has 100% description coverage, so all six parameters are already fully documented. The tool description adds no parameter-specific semantics beyond what the schema provides; the phrase 'bounded coding task' mirrors the `task` parameter's own description rather than adding new meaning.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description states a specific verb ('Execute'), a resource ('bounded coding task through Codex CLI'), and the result format ('compact JSON report with diff/status context'). It also clarifies the synchronous blocking behavior, making the tool's purpose unambiguous even without sibling tools to compare against.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description gives clear context by specifying this is for 'bounded' coding tasks and that it blocks until done. There are no sibling tools to differentiate against, so explicit alternatives or when-not guidance are unnecessary; the 'bounded' qualifier implies the intended scope.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections.
1 tool update
v0.2.0- First observed
codex_execute
TDQS
Scored across 1 tool
With only one tool, there is zero ambiguity in selecting between tools. The purpose is clear and singular.
The single tool name follows a clear verb_noun pattern (codex_execute), which is consistent and readable. No conflicting conventions exist.
The server exposes only one tool, which is well below the typical 3-15 range. While the narrow focus may justify a minimal surface, it feels too sparse for a general-purpose coding task executor, especially given the server name suggests broader sync functionality.
The server provides only a single execute operation with no supporting tools for status, history, configuration, or cancellation. This leaves significant gaps in the expected lifecycle of a coding task execution service, likely causing agent dead-ends.
Maintenance
Related MCP Connectors
A paid remote MCP for OpenAI Codex agent coordination MCP, built to return verdicts, receipts, usage
A paid remote MCP for OpenAI Codex context compressor, built to return verdicts, receipts, usage log
No-data MCP handoff for local Claude Code to Codex harness moves. $49 lifetime.
Share one project context across ChatGPT, Claude, Telegram and any MCP client.
Related MCP Servers
- AlicenseAqualityBmaintenanceDelegates work from MCP clients (like Claude Code) to the Codex CLI, allowing spawning of autonomous Codex subagents for tasks.21,019 PyPI176MIT
- AlicenseCqualityDmaintenanceBridges MCP clients with local Codex CLI to execute autonomous coding tasks, manage threads, and inspect history via SQLite state.131,102 npm4Apache 2.0
- AlicenseAqualityCmaintenanceEnables Codex to delegate coding tasks to an OpenCode CLI locally, returning structured results such as exit codes, session summaries, tool calls, and git diffs.2MIT
- AlicenseAqualityBmaintenanceEnables MCP clients to run non-interactive Codex CLI sessions via codex and codex-reply tools, including resuming conversations by thread ID and passing codex exec flags.2MIT