Codex CLI
See the generated compatibility matrix for capability details and version-scoped evidence.
codex-cli lets ctrlyoke drive Codex-based workflows from the same schema used by the other CLI harnesses.
Good fit
- Teams already using Codex in local or CI workflows
- Workflows that benefit from Codex-specific sandbox and approval controls
Notes
- Install the Codex CLI (
npm install -g @openai/codex) and sign in before selecting this harness. - Codex uses sandbox and approval modes rather than individual tool patterns, so
allowedTools/deniedToolsare not enforced on this harness. The permissionmodemaps to Codex flags:dangerouslyAllowAll→--dangerously-bypass-approvals-and-sandboxallowAll→--sandbox workspace-write --ask-for-approval on-requestcustom→-s <permissions.codexSandboxMode> -a <permissions.codexApprovalPolicy>none→ no permission flags (Codex's own defaults)
permissions.codexSandboxMode(read-only,workspace-write,danger-full-access; defaultworkspace-write) andpermissions.codexApprovalPolicy(untrusted,on-request,never; defaulton-request) are only read incustommode.- Headless runs use
codex exec, which does not accept an approval flag, so only the sandbox flag is passed there. - Directories in
permissions.trustedExternalRootsare passed to Codex as--add-dir.
Example
yaml
harness: codex-cli
model: gpt-5.5
steps:
- prompt: Review @src/cli.ts and simplify the option parsing where practical.