Codex MCP checks: configured, exposed, and callable
A retained Codex CLI tool-call trace separates MCP configuration from a usable tool, including an approval failure and a successful read-only search.
Last updated: 2026-10-03
By Stometa · Verification sources and dates are cited in the article.
On October 3, 2026, Codex CLI 0.157.0 listed the tavily MCP server as enabled. A read-only codex exec --json run then failed at the approval boundary; a second run with the authorized bypass flag completed one tavily_search call and returned three URLs. The server inventory alone did not predict either outcome. Save the tool-call event before changing MCP configuration.
The cost is one bounded tool call and a private JSONL trace that can contain queries and results. Our trace stays outside this repository; the reduced table below contains its relevant fields. This test used the existing server, not a fresh installation.
What did the two runs actually show?
Both runs used the same search input: Codex MCP startup_timeout_sec tool_timeout_sec, include_domains: ["developers.openai.com"], and max_results: 3. Both used codex exec --json --ephemeral with model gpt-6-sol. The first used a read-only sandbox with approval policy never; the second used --dangerously-bypass-approvals-and-sandbox under this run's authorization. The official CLI reference, checked October 3, says this flag removes approvals and sandboxing and restricts its use to an externally hardened environment. Our tool-call trace does not establish that host boundary. Do not copy the bypass flag as a troubleshooting fix.
| October 3 run | Retained mcp_tool_call event | Result | What it proves |
|---|---|---|---|
Read-only sandbox, approval never | tavily / tavily_search, status: failed | MCP tool call requires approval, but approval policy is never | The configured server was exposed, but this call was denied by the active approval policy. |
| Authorized bypass | tavily / tavily_search, status: completed | Three official-documentation URLs returned | This one read operation worked under that run's authority; it says nothing about other tools or future calls. |
The successful result URLs were the MCP guide, configuration reference, and configuration sample. We checked the MCP guide itself on October 3 rather than treating search snippets as documentation evidence. A different approval setup might allow the same safe read without a bypass; this pair does not establish the minimum permission needed.
Which check answers which question?
The official MCP guide, checked October 3, documents codex mcp list for configured servers and /mcp in the TUI for active servers. We did not capture a /mcp screen in this test. The JSONL event adds execution evidence that neither inventory provides.
| Check | Keep as evidence | Established here | Still unknown |
|---|---|---|---|
codex mcp list | Server name, status and transport, with secrets redacted | tavily was listed as enabled by CLI 0.157.0 | What another host or session loaded |
/mcp in the target TUI | Active server and tool names | Not captured | Whether that TUI exposes the same tools |
| One bounded call | Input, event status, error or returned URLs | One denial and one completed search in codex exec | Other permissions, tools and later calls |
If a call fails, preserve its named layer. An approval error is different from a startup timeout, and a completed call does not validate every server setting. The official guide lists startup_timeout_sec (default 10 seconds), tool_timeout_sec (default 60 seconds), and mcp_optional_startup_grace_ms (default 1000 milliseconds). Optional servers missing from the initial catalog may involve the grace setting; a tool execution timeout involves a later stage. Neither timeout was measured in our two runs.
For configuration precedence, see the config.toml guide. For a separate scripted-run trace, see codex exec diagnostics. For the broader question of a quality drop, keep tool failures separate from the quality checklist.
Last verified October 3, 2026: the official MCP guide and the retained CLI event were checked. Open loop: reproduce setup on a clean host, capture the target TUI's /mcp inventory, and test whether a narrower approval policy permits the same read.