Codex

Advanced usage

AGENTS.md, profiles, MCP, non-interactive tasks, approvals and practical workflows.

Effective Codex work combines suitable permissions, project context, profiles, MCP and non-interactive execution. See Commands for a quick reference.

#AGENTS.md project instructions

Place AGENTS.md at the project root to explain conventions, similarly to Claude Code's CLAUDE.md.

AGENTS.md
# Project conventions

Stack: Python + FastAPI
Package manager: uv, not pip

## Commands
- Start: uv run uvicorn app:main
- Test: uv run pytest

## Style
- Include type annotations.
- Run pytest after changes.

Instructions are layered: user preferences in ~/.codex/AGENTS.md, shared repository rules at the root and more specific rules in subdirectories. Use /init to generate a starting draft.

#Advanced config.toml settings

Common settings, with the full setup in Configuration:

SettingPurpose
modelDefault model, as enabled in your provider's catalog
model_reasoning_effortA supported effort such as low / medium / high
approval_policyon-request / never
sandbox_moderead-only / workspace-write / danger-full-access
web_searchSearch mode; live selects current web access where supported

Override a setting for one run with -c key=value, for example codex -c model_reasoning_effort=high.

#Switch settings with profiles

Store scenario-specific settings in a profile and select it with --profile:

~/.codex/fast.config.toml
# Profile files use top-level keys.
model = "gpt-6-sol"
model_reasoning_effort = "high"
approval_policy = "on-request"
sandbox_mode = "workspace-write"
codex --profile fast "Add tests for this module"

Old [profiles.fast] examples should be migrated to the separate file. Retired approval values such as on-failure/untrusted should not be copied into new configuration.

#Connect tools with MCP

MCP connects external tools and data such as browsers, databases and internal APIs. Define the server in config.toml:

~/.codex/config.toml
[mcp_servers.my-tool]
command = "npx"
args = ["-y", "@scope/my-mcp-server"]
# env = { API_KEY = "..." }

Use /mcp to inspect connectivity and available tools.

MCP servers receive the access you give them. Connect trusted sources and scope their permissions.

#Non-interactive scripts and CI

codex exec completes a task without entering the interactive TUI:

# One task
codex exec "Fix lint failures and run the relevant tests"

# Explain a staged diff
git diff --staged | codex exec "Summarize these changes as a commit message"

Use explicit, limited permissions for unattended work, such as read-only or a specific writable workspace.

#Approvals and sandbox

Codex combines approval policy with the sandbox boundary:

Conservative starting pointUse on-request with a suitable sandbox for unfamiliar projects.
Focused local implementationUse workspace-write and scoped approvals for changes within the project.
Unrestricted executionBypass flags are for controlled, isolated, recoverable environments only.

--full-auto is deprecated. New scripts should use explicit --sandbox workspace-write --ask-for-approval on-request. -a and -s override approval and sandbox settings; -C sets the working directory.

Do not use unrestricted execution in unfamiliar repositories, production directories or secret-bearing folders. See Security.

#Common workflow

1

Understand first

Ask Codex to explain the project's structure and entry points, then verify its understanding.

2

Define the goal and plan

Plan complex changes before implementation. Correct the direction here; use /model for supported reasoning adjustments when needed.

3

Implement and check

After agreeing on scope, implement the change and run relevant tests/builds.

4

Review the diff

Inspect changes with /diff. Keep work under version control so unwanted changes can be reverted selectively.

#Continue reading

Support

Need help?

For setup, billing, or model issues, email us. Check the status page for uptime.

WeChat / QQ support is available at the bottom right.