codexpulse.
Back to home

Codex MCP checks: configured, exposed, and callable

A retained Codex CLI tool-call trace separates MCP configuration from a usable tool, including an approval failure and a successful read-only search.

Last updated: 2026-10-03

By Stometa · Verification sources and dates are cited in the article.

On October 3, 2026, Codex CLI 0.157.0 listed the tavily MCP server as enabled. A read-only codex exec --json run then failed at the approval boundary; a second run with the authorized bypass flag completed one tavily_search call and returned three URLs. The server inventory alone did not predict either outcome. Save the tool-call event before changing MCP configuration.

The cost is one bounded tool call and a private JSONL trace that can contain queries and results. Our trace stays outside this repository; the reduced table below contains its relevant fields. This test used the existing server, not a fresh installation.

What did the two runs actually show?

Both runs used the same search input: Codex MCP startup_timeout_sec tool_timeout_sec, include_domains: ["developers.openai.com"], and max_results: 3. Both used codex exec --json --ephemeral with model gpt-6-sol. The first used a read-only sandbox with approval policy never; the second used --dangerously-bypass-approvals-and-sandbox under this run's authorization. The official CLI reference, checked October 3, says this flag removes approvals and sandboxing and restricts its use to an externally hardened environment. Our tool-call trace does not establish that host boundary. Do not copy the bypass flag as a troubleshooting fix.

October 3 runRetained mcp_tool_call eventResultWhat it proves
Read-only sandbox, approval nevertavily / tavily_search, status: failedMCP tool call requires approval, but approval policy is neverThe configured server was exposed, but this call was denied by the active approval policy.
Authorized bypasstavily / tavily_search, status: completedThree official-documentation URLs returnedThis one read operation worked under that run's authority; it says nothing about other tools or future calls.

The successful result URLs were the MCP guide, configuration reference, and configuration sample. We checked the MCP guide itself on October 3 rather than treating search snippets as documentation evidence. A different approval setup might allow the same safe read without a bypass; this pair does not establish the minimum permission needed.

Which check answers which question?

The official MCP guide, checked October 3, documents codex mcp list for configured servers and /mcp in the TUI for active servers. We did not capture a /mcp screen in this test. The JSONL event adds execution evidence that neither inventory provides.

CheckKeep as evidenceEstablished hereStill unknown
codex mcp listServer name, status and transport, with secrets redactedtavily was listed as enabled by CLI 0.157.0What another host or session loaded
/mcp in the target TUIActive server and tool namesNot capturedWhether that TUI exposes the same tools
One bounded callInput, event status, error or returned URLsOne denial and one completed search in codex execOther permissions, tools and later calls

If a call fails, preserve its named layer. An approval error is different from a startup timeout, and a completed call does not validate every server setting. The official guide lists startup_timeout_sec (default 10 seconds), tool_timeout_sec (default 60 seconds), and mcp_optional_startup_grace_ms (default 1000 milliseconds). Optional servers missing from the initial catalog may involve the grace setting; a tool execution timeout involves a later stage. Neither timeout was measured in our two runs.

For configuration precedence, see the config.toml guide. For a separate scripted-run trace, see codex exec diagnostics. For the broader question of a quality drop, keep tool failures separate from the quality checklist.

Last verified October 3, 2026: the official MCP guide and the retained CLI event were checked. Open loop: reproduce setup on a clean host, capture the target TUI's /mcp inventory, and test whether a narrower approval policy permits the same read.