Advanced usage
AGENTS.md, profiles, MCP, non-interactive tasks, approvals and practical workflows.
Effective Codex work combines suitable permissions, project context, profiles, MCP and non-interactive execution. See Commands for a quick reference.
#AGENTS.md project instructions
Place AGENTS.md at the project root to explain conventions, similarly to Claude Code's CLAUDE.md.
# Project conventions
Stack: Python + FastAPI
Package manager: uv, not pip
## Commands
- Start: uv run uvicorn app:main
- Test: uv run pytest
## Style
- Include type annotations.
- Run pytest after changes.Instructions are layered: user preferences in ~/.codex/AGENTS.md, shared repository rules at the root and more specific rules in subdirectories. Use /init to generate a starting draft.
#Advanced config.toml settings
Common settings, with the full setup in Configuration:
| Setting | Purpose |
|---|---|
model | Default model, as enabled in your provider's catalog |
model_reasoning_effort | A supported effort such as low / medium / high |
approval_policy | on-request / never |
sandbox_mode | read-only / workspace-write / danger-full-access |
web_search | Search mode; live selects current web access where supported |
Override a setting for one run with -c key=value, for example codex -c model_reasoning_effort=high.
#Switch settings with profiles
Store scenario-specific settings in a profile and select it with --profile:
# Profile files use top-level keys.
model = "gpt-6-sol"
model_reasoning_effort = "high"
approval_policy = "on-request"
sandbox_mode = "workspace-write"codex --profile fast "Add tests for this module"Old [profiles.fast] examples should be migrated to the separate file. Retired approval values such as on-failure/untrusted should not be copied into new configuration.
#Connect tools with MCP
MCP connects external tools and data such as browsers, databases and internal APIs. Define the server in config.toml:
[mcp_servers.my-tool]
command = "npx"
args = ["-y", "@scope/my-mcp-server"]
# env = { API_KEY = "..." }Use /mcp to inspect connectivity and available tools.
MCP servers receive the access you give them. Connect trusted sources and scope their permissions.
#Non-interactive scripts and CI
codex exec completes a task without entering the interactive TUI:
# One task
codex exec "Fix lint failures and run the relevant tests"
# Explain a staged diff
git diff --staged | codex exec "Summarize these changes as a commit message"Use explicit, limited permissions for unattended work, such as read-only or a specific writable workspace.
#Approvals and sandbox
Codex combines approval policy with the sandbox boundary:
--full-auto is deprecated. New scripts should use explicit --sandbox workspace-write --ask-for-approval on-request. -a and -s override approval and sandbox settings; -C sets the working directory.
Do not use unrestricted execution in unfamiliar repositories, production directories or secret-bearing folders. See Security.
#Common workflow
Understand first
Ask Codex to explain the project's structure and entry points, then verify its understanding.
Define the goal and plan
Plan complex changes before implementation. Correct the direction here; use /model for supported reasoning adjustments when needed.
Implement and check
After agreeing on scope, implement the change and run relevant tests/builds.
Review the diff
Inspect changes with /diff. Keep work under version control so unwanted changes can be reverted selectively.
#Continue reading
Support
Need help?
For setup, billing, or model issues, email us. Check the status page for uptime.
WeChat / QQ support is available at the bottom right.

