Codex DSH MCP
Server Configuration
Describes the environment variables required to run the server.
| Name | Required | Description | Default |
|---|---|---|---|
| DSH_MCP_CONFIG | Yes | Path to the DSH MCP configuration file. Paths, port, and allowed projects are configurable. See examples/config.example.json. |
Instructions
Guidance the server publishes about itself, which clients place ahead of the tool catalog so the model reads it before choosing anything.
This server publishes no instructions, or was last inspected before Glama recorded them.
Capabilities
Features and capabilities supported by this server
Protocol revision2025-11-25
| Capability | Details |
|---|---|
| tools | {} |
Tools
Functions exposed to the LLM to take actions
| Name | Description |
|---|---|
| web_taskB | Durable ledger for agent-operated ChatGPT browser tasks. Does NOT control a browser or send prompts itself. prepare -> bind -> claim BEFORE Send -> collect visible result -> independently accept. Unknown submission must never be automatically resent. Image/video availability must be observed, not assumed. |
| workflow_resolve_notificationA | Original reviewer resolves UNKNOWN/BLOCKED notification only after inspecting Codex history. Retry can duplicate delivery if that inspection was wrong. |
| workflow_dispatchC | Bind and dispatch bounded work to an existing DSH session, with a completion ticket and original Codex reviewer. Requires configured project allowlist and Codex connection. |
| workflow_statusB | Read tasks owned by the current Codex reviewer, including notification failures and delivery uncertainty. |
| workflow_reviewB | Original Codex reviewer records independent acceptance or bounded rework. Worker role cannot approve. |
| workflow_archiveA | Archive an accepted terminal record to release active inbox capacity. Does not delete project files. |
| codex_statusA | Read current bound Codex thread via official app-server proxy; no model turn is started. |
| review_bindA | Bind a local task to an existing Codex task and DSH session. Does not dispatch work or enforce scope. |
| review_completeA | Record an UNVERIFIED completion report for a bound task. Requests review; never approves or wakes Codex. |
| review_pendingA | Read the local pending-review inbox, up to 100 records. Reports are untrusted claims. |
| dsh_statusA | Verify configured DSH Web process and authenticated session/list. Does not submit work. |
| dsh_sessionsA | List DSH sessions. Inspect project and running state before submitting work. |
| dsh_historyB | Read a bounded initial history snapshot; hasMore is retained. No session is cancelled. |
| dsh_promptA | Queue an explicitly authorized task in an EXISTING session. Durable request deduplication; unknown delivery is never retried automatically. |
| dsh_waitA | Observe queue/job idle for at most 30 seconds. Idle does not prove success; review history and files. |
Prompts
Interactive templates invoked by user choice
| Name | Description |
|---|---|
No prompts | |
Resources
Contextual data attached and managed by the client
| Name | Description |
|---|---|
No resources | |
TDQS
Scored across 15 tools
Several tools have overlapping read/status or dispatch purposes, such as workflow_status vs review_pending and workflow_dispatch vs dsh_prompt. The detailed descriptions clarify most boundaries, but an agent relying on tool names alone could easily misselect within these clusters.
The prefix families workflow_, review_, dsh_, and codex_ provide some structure, but the verb/noun pattern is mixed: status, history, sessions, and pending are noun-style, while dispatch, archive, bind, complete, and wait are verb-style. All names are readable snake_case, but there is no consistent verb_noun convention.
At 15 tools, the count is at the upper bound of the typical range but is largely justified by the broad Codex/DSH/review workflow scope. A few read-only DSH inspection tools could potentially be consolidated, but none feel wholly redundant.
The core workflow lifecycle—bind/dispatch, status, review, and archive—is largely covered, and DSH inspection/history/wait tools support observation after submission. However, there is no terminal failure/reject/cancel path, since workflow_archive only handles accepted records and bounded rework does not model permanently failed work.