Codex

Connect Codex to scoped tools through ExecWarden MCP.

Use Codex CLI as the agent loop while ExecWarden provides the governed capabilities. The tested path today runs through ExecWarden MCP.

Authorized client

Keep OAuth transport access visible and separately revocable.

Codex CLI authorized to use ExecWarden through a revocable OAuth transport
The product distinguishes MCP OAuth authorization from the tool grants attached to its Agent identity.

Integration shape

The setup, credentials, governed actions, and evidence should be obvious.

Compatibility

Tested MCP registration and bearer-authenticated connectivity for Codex CLI.

Agent loop

Codex runs the reasoning loop locally, remotely, or in the execution environment the team chooses.

Credentials

Provider credentials stay behind ExecWarden when the capability is supplied by ExecWarden.

Governed actions

GitHub, package-backed tools, imported MCP tools, and approval-gated writes can be governed when called through ExecWarden.

Not implied

This is MCP connectivity and governed tool access, not a native hosted Codex session inside ExecWarden.

Start

Create or choose an Agent identity, grant a GitHub boundary or tool capability, then connect Codex through MCP.

How it works today

ExecWarden MCP keeps Codex in its own loop and governed tools behind ExecWarden.

Codex stays in its own local or remote reasoning loop. ExecWarden governs the external tools Codex reaches through MCP.

Compatibility

Tested with Codex CLI over MCP.

The grounded path today is the ExecWarden MCP setup path for Codex CLI, not a native hosted Codex session in ExecWarden.

Agent loop

Codex owns the reasoning loop.

Codex can run locally or in another execution environment while using ExecWarden for mediated capabilities.

Evidence

Governed calls appear in ExecWarden.

Tool calls through ExecWarden can produce activity records, approval records, and provider results for review.

Where teams start

Codex tasks that fit the governed-tool boundary.

1Codex reads a granted repo through ExecWarden MCP.
2Codex asks before a PR or external write where policy requires it.
3The team revokes the Agent identity when the task ends.

Connect Codex

Connect Codex through ExecWarden MCP and grant one bounded tool set.

Keep Codex in its own reasoning loop and let ExecWarden govern the external tools it can reach.

Connect an MCP clientRead MCP quickstart