Skip to main content

Codex CLI

Changelog

OpenAI's command-line coding assistant

This page shows at most the 120 most recent releases from official sources. It does not claim to be a complete version history.

Latest Version:v0.160.1
Shown Releases:133
Source:GitHub Releases
RSS

Latest Releases (133)

v0.160.1New

0.160.1

October 5, 2026

  • •Preserve SYSTEMROOT, TEMP, and TMP when launching remote stdio MCP servers with explicitly configured remote environment variables, allowing Unix hosts to retain the Windows executor's startup environment.
  • •#51121: Backport Windows remote MCP environment preservation to 0.160.
v0.160.0

0.160.0

October 1, 2026

  • •Browse older tasks in the agent command center with a keyboard-accessible “Show more” action. (#49106)
  • •Select transcript text and paste with middle-click in fullscreen mode on supported local Linux X11 terminals. (#49112)
  • •Start sessions outside a project with workspace defaults when policy permits, and restore saved permissions when resuming. (#49160)
  • •Added opt-in Guardian review capabilities to retrieve earlier user instructions and include context from agent handoffs. (#49036, #49057)
  • •Unsent queued messages now resume after reconnection once uncertain submissions are resolved, avoiding duplicate sends. (#49105)
  • •The terminal UI now preserves server provider, reasoning-summary, and verbosity settings and shows the correct sessions in resume and fork history. (#49144, #49161, #49171)
  • •Fixed Windows sandbox PowerShell fallbacks and long-path permission repairs, and suppressed unwanted console windows from background helpers. (#49019, #49058, #49098, #49164, #49386)
  • •Subagents now retain environments that are still starting and receive their configuration or preparation failure. (#49075)
  • •Prevented SQLite stalls during connection setup and logging, and surfaced initialization errors instead of masking them as timeouts. (#49032, #49102)
  • •Explicit provider model catalogs no longer include unsupported bundled models or reuse stale entries after refresh failures. (#49135)
  • •Clarified how provider credentials use the configured storage backend and how env_key identifies the API-key environment variable. (#49118)
  • •Reduced repeated plugin-loading work by caching parsed manifests and reusing HTTP connections for remote plugin requests. (#49099, #49100)
  • •Added background reclamation of unused log database space to reduce disk usage. (#49069)
v0.159.3

0.159.3

October 1, 2026

  • •Eligible local sessions signed in with ChatGPT can now show optional reminders to complete account security setup. (#49744)
v0.159.2

0.159.2

September 30, 2026

  • •Suppressed console windows flashing on Windows when Codex launches background processes and sandboxed commands. (#49385)
v0.159.1

0.159.1

September 29, 2026

  • •Added GPT-6.1 Sol as the default model in the bundled catalog and Amazon Bedrock Mantle and Runtime catalogs. (#49323, #49342)
v0.159.0

0.159.0

September 29, 2026

  • •Opt-in instant_interrupt lets new input steer Codex during model responses or long-running code-mode calls. (#48135, #48141)
  • •New sessions get a compact welcome screen and consistent headers, with occasional tips during and after turns. (#48513, #48562, #48352)
  • •The warnings viewer dismisses reviewed warnings when closed; press k to keep one for later. (#48205, #48206)
  • •You can scroll the transcript while deciding whether to implement a plan. (#48805)
  • •Native Mermaid rendering supports more flowchart edges, labels, and node groups. (#48814, #48895)
  • •App-server clients can paginate thread history from a specific item. (#48151)
  • •Windows launches avoid stray console windows for MCP servers, code-mode hosts, and piped commands; restrictive launchers can fall back to embedded mode. (#48138, #48238, #48483, #48491)
  • •Copying transcript selections preserves Markdown tables, formatting, and significant whitespace. More terminals now copy automatically on selection. (#48548, #48549, #48469)
  • •Blank sessions retain drafts when switching tasks, and threads can be archived and listed before their first turn. (#48628, #48828, #48199)
  • •Local ChatGPT sign-in opens the browser reliably; onboarding also provides a shortcut to copy the login link. (#48502, #48544)
  • •Approved commands retain explicit filesystem denials, and .aws directories are protected by default under writable roots. (#48155, #48176)
  • •Fixed macOS TLS access in network-enabled sandboxes and remote environments that require proxy access. (#48565, #48198)
  • •Removed automatic follow-up prompt suggestions and the tui.prompt_suggestions setting. (#48621)
  • •Removed the bundled plugin-creator skill. (#48604)
v0.158.0

0.158.0

September 28, 2026

## New Features - Configure copy-on-select and right-click paste in the fullscreen TUI. Copied transcript selections now preserve Markdown formatting. (#47639, #47896, #48118) - Connect to MCP servers that require pre-registered OAuth client secrets, including through codex mcp add --oauth-client-secret. (#47891) - Secure direct exec-server WebSocket connections with bearer tokens, including connections configured through app-server. (#47601, #47648) - Image generation and editing can explicitly request transparent backgrounds, and edits now accept file-backed conversation images. (#47484, #47956) - Terminal input approval is enabled by default for commands running with elevated permissions; runtime-only grants no longer cause unnecessary reviews. (#47799, #48073) ## Bug Fixes - Fixed Windows sandbox failures involving ordinary Windows 10 paths, rejected stored credentials, and large permission policies. (#47672, #47695, #47919) - Fixed Linux sandbox startup with nested writable roots and preserved Git metadata protections across writable roots on Linux and macOS. (#47623, #47974) - macOS patch operations now recognize system path aliases covered by existing permissions, avoiding unnecessary approval prompts. (#47879) - Approval reviews now retry when new user input arrives, so a status question does not automatically abort a pending action. (#47819) - Mermaid flowcharts now render quoted labels and ampersands; unsupported diagrams explain why they fall back to source. (#47572, #47678) - Command completion events now include early output and report process-launch failures to clients. (#47529, #47665) ## Changelog Full Changelog: https://github.com/openai/codex/compare/rust-v0.157.0...rust-v0.158.0 - #47441 Use secondary text styling for the transcript footer shortcut hint @etraut-openai - #47447 Extract WebSocket authentication into codex-websocket-auth @euroelessar - #47458 Parallelize instruction refresh and tool preparation @hlevy-openai - #47484 Add explicit background control to image generation @alicec-oai - #47520 Route session agent operations through AgentControl @jif-oai - #47529 Emit command lifecycle events for unified exec launch failures @steipete-oai - #47536 Route agent lookups and V2 context through AgentControl @jif-oai - #47539 Test interrupted one-shot command launch failure persistence @jif-oai - #47540 Add an option to disable multi-agent v2 direct messaging @jif-oai - #47565 Classify rollout read failures by reason and progress @jif-oai - #47568 Record sandbox backends in command execution analytics @iceweasel-oai - #47571 Wait for idle before injecting remote compaction test history @felixxia-oai - #47572 Explain Mermaid rendering fallbacks in the TUI @etraut-openai - #47582 Retain assistant context for Guardian authorization reviews @felixxia-oai - #47584 Preserve streamed assistant message order in retained context @felixxia-oai - #47585 Preserve delivered assistant messages in Guardian retained context @felixxia-oai - #47589 Keep unfinished link destinations out of rich streaming previews @etraut-openai - #47590 Serialize numeric custom reasoning effort as JSON numbers @dylan-hurd-oai - #47591 Stream daemon executable hashing off the async runtime @etraut-openai - #47596 Refresh realtime context for each model request @reia-oai - #47597 Guard prerelease channel and canary updates against older versions @imac-oai - #47601 Add opt-in WebSocket authentication to exec-server @euroelessar - #47603 Add a reap-only drop policy for child processes @charliemarsh-oai - #47604 Extend child commands with session and descriptor controls @charliemarsh-oai - #47605 Route pipe processes through the shared child launcher @charliemarsh-oai - #47610 Use native POSIX spawning for command hooks @charliemarsh-oai - #47611 Use the shared process launcher for Unix shell snapshots @charliemarsh-oai - #47612 Launch Linux pipe processes through a fresh setup helper @freeqaz-openai - #47613 Expand Linux spawn-helper lifecycle test coverage @charliemarsh-oai - #47617 Route Linux PTY launches through the process setup helper @charliemarsh-oai - #47618 Prefer Shift-arrow hints for queued messages and questions @imac-oai - #47619 Add bounded buffering for global operation metrics @celia-oai - #47620 Add portable project trust lookup APIs @seanh-oai - #47623 Fix read-only metadata mount ordering for nested writable roots @jif-oai - #47624 Recognize user_message tools in Guardian authorization context @ankushg - #47625 Allow history and notes without experimental context capability @pmccrary-oai - #47629 Route V2 child loading through AgentControl @jif-oai - #47630 Bind Guardian reviews to the action's target environment @jif-oai - #47633 Route message board agent resolution through the selected controller @jif-oai - #47635 Overlap startup WebSocket preconnect with tool discovery @bromano-oai - #47638 Classify retryable exec-server preparation errors by type @mtsui-oai - #47639 Add configurable copy-on-select for transcript selections @fcoury-oai - #47641 Honor Retry-After and preserve server retry deadlines @anp-oai - #47642 Add model-specific prefixes to indirect tool descriptions @rhan-oai - #47647 Apply Guardian computer-use review to the Browser connector @johnl-oai - #47648 Support bearer tokens for app-server executor connections @euroelessar - #47649 Add opt-in OTLP logging for final agent responses @xli-oai - #47653 Attach inherited rollout history to diagnostic reports @dkovalenko-oai - #47654 Make Linux descriptor cleanup fork-safe @yuzhu-oai - #47655 Bump the exec-server stable compatibility test to Codex 0.156.1 @imac-oai - #47657 Restrict the default Bedrock GovCloud model catalog @jackz100 - #47662 Expose tool dispatch and timing observations to extensions @euroelessar - #47663 Preserve managed network policy in route-aware transports @jackz100 - #47665 Preserve early unified exec output in completion events @sdcoffey - #47670 Support model-specific descriptions for agent message board tools @eknight-oai - #47672 Fix no-reparse directory opens on Windows 10 @zm-oai - #47673 Clarify registered Windows sandbox setup errors @zm-oai - #47677 Support model catalog overrides for MCP resource tool specs @rhan-oai - #47678 Support quoted labels and ampersands in Mermaid flowcharts @etraut-openai - #47679 Add extension hooks for model requests and response streams @euroelessar - #47680 Add exec-server RPC timing and process startup tracing @anp-oai - #47683 Add executor capability discovery V2 infrastructure @TAFOYA-OAI - #47686 Make thread-owned Guardian context always enabled @felixxia-oai - #47688 Remove legacy Guardian authorization evidence paths @felixxia-oai - #47689 Make Guardian thread context capture unconditional @felixxia-oai - #47690 Remove obsolete Guardian context capture mode branches @felixxia-oai - #47691 Materialize rollout persistence for pending inter-agent messages @dermanyang-oai - #47693 Configure curl retries for DotSlash installation in CI @anp-oai - #47695 Repair rejected Windows sandbox credentials during provisioning @zm-oai - #47696 Avoid the shutdown timeout in the lagged-event test @jgershen-oai - #47698 Allow WebSocket test server shutdown while waiting for requests @jgershen-oai - #47701 Allow idle threads to prewarm and repair WebSocket connections @vkg-oai - #47703 Preserve account network policy for ChatGPT backend requests @jackz100 - #47704 Fix spawn flag typing and isolate project configuration tests @seanh-oai - #47709 Route resume prewarm through the cached WebSocket session @vkg-oai - #47712 Update unified exec output buffers atomically @sdcoffey - #47713 Reduce dependency coupling in shared configuration crates @aibrahim-oai - #47714 Preserve tool result metadata more selectively under size limits @ningyi-oai - #47717 Avoid recursive TUI event dispatch for model picker selections @etraut-openai - #47741 Attribute tool telemetry to the invoking turn's product SKU @rennie-openai - #47742 Honor network policy in history notes and image generation extensions @jackz100 - #47745 Skip startup prewarm preparation when the WebSocket is ready @vkg-oai - #47748 Align Cargo and Bazel Rust debug information defaults @aibrahim-oai - #47751 Reduce generic code duplication in RPC and Markdown rendering @aibrahim-oai - #47755 Centralize typed app-server response decoding @aibrahim-oai - #47757 Refactor tool telemetry product SKU matching to use an allowlist @rennie-openai - #47758 Preserve more tool metadata within outgoing message budgets @ningyi-oai - #47773 Honor catalog schemas for asynchronous user input @rhan-oai - #47797 Support close-on-exec attachments without changing PTY semantics @jif-oai - #47799 Enable terminal input approval by default @jif-oai - #47808 Allow hosts to provide agent controllers through ThreadManager @jif-oai - #47811 Preserve explicit user goal updates in Guardian authorization @felixxia-oai - #47813 Fix sleep interruption test event handling and fixture lifetime @felixxia-oai - #47814 Fix a lost wakeup in the unified exec termination test @felixxia-oai - #47817 Stabilize thread resume and memory dual-write tests @jif-oai - #47819 Retry Guardian reviews when authorization changes @teddywyly-oai - #47820 Add integration coverage for host agent controllers @jif-oai - #47824 Allow four concurrent threads in the multi-agent resume test @felixxia-oai - #47828 Wait for login completion in recommended plugin tests @felixxia-oai - #47830 Bind Guardian async scores to target environment permissions @jif-oai - #47832 Stabilize Rosetta test timing and retry delay telemetry @jif-oai - #47847 Keep the TUI responsive during clipboard copies @fcoury-oai - #47851 Preserve human overrides across repeated heartbeat instructions @felixxia-oai - #47852 Avoid blocking async proxy resolution on the system proxy cache @jif-oai - #47856 Initialize media estimates outside the global cache lock @jif-oai - #47858 Validate loaded plugins outside the cache lock @jif-oai - #47861 Avoid nested read locking when rendering browser sign-in @jif-oai - #47867 Render remote permission paths using executor context @iceweasel-oai - #47870 Add opt-in OTLP logging for Guardian assessments @jif-oai - #47871 Fix PID reservation test race and update guardian heartbeat snapshot @jif-oai - #47873 Measure deferred tool namespace fragments before and after truncation @mzeng-openai - #47879 Fix macOS system-alias matching in patch permission checks @felixxia-oai - #47881 Use Tokio's clock for TUI paste timing @charliemarsh-oai - #47886 Preserve diagnostic logs when SQLite logging fails @dkovalenko-oai - #47887 Warn users when SQLite diagnostic log writes fail @dkovalenko-oai - #47889 Include TUI client logs in diagnostic uploads @etraut-openai - #47891 Support client secrets for pre-registered MCP OAuth clients @willwang-openai - #47894 Clean up temporary Codex homes after TUI tests @fcoury-oai - #47896 Preserve Markdown formatting when copying transcript selections @fcoury-oai - #47898 Preserve local-binding inheritance in environment network policies @seanh-oai - #47899 Add diagnostic reasons to MCP attribution errors @peilin-openai - #47900 Default local threads to paginated history @owenlin0 - #47901 Add bounded credential-storage telemetry helpers @celia-oai - #47902 Avoid repeated table clones during config merging @imac-oai - #47903 Move config key alias normalization ahead of merging @imac-oai - #47904 Support nested canonical paths in config key aliases @imac-oai - #47908 Alias tui.whimsy to tui.effects.starfield @imac-oai - #47912 Fix attestation routing during thread startup @charliemarsh-oai - #47913 Add an opt-in flag to defer mailbox preemption @jif-oai - #47915 Reuse verified V8 checksum manifests from the artifact cache @aibrahim-oai - #47918 Parameterize the turn-start originator header test @aibrahim-oai - #47919 Transport large Windows sandbox launch payloads through the environment @malsamiri-oai - #47920 Allow directory moves under global Seatbelt basename denies @chess-oai - #47922 Allow full-access Windows setup to provision through registered Core @zm-oai - #47924 Make project trust lookup paths explicit and defer root resolution @seanh-oai - #47926 Retry file blob uploads on HTTP 502 and 504 @mtsui-oai - #47927 Use 127.0.0.1 for local login redirects @willwang-openai - #47932 Remove GPT-5.4 from bundled catalogs and preserve migration prompts @andrewgu-oai - #47934 Apply the unchanged-model compaction shortcut to all session sources @hlevy-openai - #47935 Allow cached catalogs to satisfy MCP startup readiness @hlevy-openai - #47936 Make MCP and Code Mode input schema budgets configurable @vivi - #47937 Add direct replies for thread settings updates @sayan-oai - #47939 Separate selected plugin identities from MCP contributions @sayan-oai - #47943 Remove unused Windows world-writable audit code @iceweasel-oai - #47945 Parameterize the thread initialization analytics test by originator @eddie-openai - #47946 Add an in-memory agent message board for ephemeral sessions @jif-oai - #47947 Expand root authorization context to 16 messages @felixxia-oai - #47951 Use prebuilt V8 archives for Bazel on macOS and GNU Linux @aibrahim-oai - #47952 Prune expired in-memory message board registry entries @jif-oai - #47954 Move fullscreen startup tips into the transcript @etraut-openai - #47956 Support file references in image edit requests @kchainani-oai - #47957 Bound tool-call observations to the outgoing Responses message budget @ningyi-oai - #47962 Request transparent huge pages for Cargo and eligible Bazel rustc jobs @aibrahim-oai - #47964 Preserve the client-agent header for Amazon Bedrock Runtime @celia-oai - #47967 Surface Flex capacity failures as a distinct terminal error @sdcoffey - #47968 Handle Btrfs device mismatches when masking daemon sockets @etraut-openai - #47970 Expose current environment selections for a running turn @sayan-oai - #47971 Add Pro Max plan support and update Pro display names @etraut-openai - #47974 Preserve Git directory protections across writable roots @aionescu-oai - #47975 Prevent stale voice answers from reappearing during speech recovery @etraut-openai - #47981 Prepare MCP calls directly from advertised tool identities @hlevy-openai - #47984 Add multi-agent spawn latency and failure metrics @owenlin0 - #47988 Reuse MCP handlers across equivalent bindings @hlevy-openai - #47989 Add startup-only PID namespace inheritance to exec-server @open-matt - #48004 Respect configured authentication in the thread manager sample @celia-oai - #48015 Validate tool suggestion install URLs before showing the app link @aionescu-oai - #48017 Test same-cell permission grants and strict review in code mode @anp-oai - #48035 Remove plugin extension metadata from discovery and summaries @victor-openai - #48060 Deduplicate retained instructions across Guardian reviews @felixxia-oai - #48069 Handle early command yields in the Guardian network approval test @jif-oai - #48072 Skip message-board notification previews when there are no recipients @jif-oai - #48073 Avoid stdin approval for runtime-only permission grants @jif-oai - #48077 Add Serde support to agent message board request types @jif-oai - #48078 Replay exec-server shell snapshots through unnamed files @jif-oai - #48098 Preserve recent authorization context for Guardian reviews @felixxia-oai - #48099 Honor shell environment policy in legacy snapshots @jif-oai - #48100 Add an HTTP client for remote agent message boards @jif-oai - #48101 Show multiline command previews in /ps @etraut-openai - #48109 Deduplicate retained instructions against Guardian transcripts @felixxia-oai - #48110 Deduplicate retained instructions in async Guardian context @felixxia-oai - #48115 Preserve user text parts during local compaction @felixxia-oai - #48116 Allow reasoning shortcuts to reach Max @etraut-openai - #48118 Add configurable right-click paste to the fullscreen TUI @fcoury-oai - #48119 Prevent worker completion races in the guardian authorization test @felixxia-oai - #48121 Keep startup drafts visible during command center session handoff @etraut-openai - #48123 Add early yielding for code-mode observations @pakrym-oai - #48130 Use request notifications in the cloud config loader lifetime test @felixxia-oai - #48132 Allow Left to open the command center from read-only conversations @etraut-openai

v0.157.1

0.157.1

September 26, 2026

  • •Release highlights could not be determined: the supplied PR index is empty, and the GitHub tag comparison returned 404.
v0.157.0

0.157.0

September 25, 2026

  • •Added GPT-6 Sol and Luna, including Amazon Bedrock support and migration prompts for older models. (#47332, #47347)
  • •Enabled fullscreen transcripts by default and added Shift-click to extend text selections. (#47178, #47414)
  • •Enabled automatic background-server startup for eligible interactive sessions, with recovery choices when server settings are incompatible. (#47179, #47318)
  • •Added an f shortcut to fork conversations open in another app, preserving drafts and queued prompts. (#47185)
  • •Made /import available in remote sessions and local background-server sessions. (#47317)
  • •Improved terminal rendering with Unicode bullets, checkboxes, aligned equations, and optimization notation. (#47191, #47322)
  • •Preserved active voice conversations when switching threads. (#47381)
  • •Recovered unsent question answers into the composer when turns end, without disrupting active history searches. (#47422, #47423)
  • •Respected tmux mouse settings and restored native scrollback for Terminal.app over SSH in automatic screen mode. (#47399, #47417)
  • •Fixed configured proxy routing for realtime connections and standalone web search, including search redirects. (#47101, #47142, #47204)
  • •Added retries for transient file-upload failures and increased the upload timeout to five minutes. (#47122, #47393)
  • •Enforced network restrictions across redirects and ongoing HTTP and WebSocket traffic, including cancellation when policy changes revoke access. (#47389, #47407)
v0.156.1

0.156.1

September 23, 2026

  • •Choose GPT-6 Sol or GPT-6 Luna from the model picker. The rate-limit switch prompt now recommends GPT-6 Luna. (#47405)
v0.156.0

0.156.0

September 22, 2026

  • •Choose an optional fullscreen UI with /tui for your next launch, including transcript search, mouse selection, and right-click copying. (#46732, #46734, #46883, #46895)
  • •Voice conversations are enabled by default, with an F8 toggle, a /voice settings picker, and bundled audio runtimes for Linux and Windows. (#44921, #46071, #44622, #44714, #44922)
  • •Explore account usage, token totals, and plugin and skill activity through the /usage analytics dashboard. (#45764, #45769)
  • •Filter tasks by status and create worktree sessions from the agent command center; worktree support is now enabled by default. (#46839, #45276, #44870)
  • •Customize the terminal with six new themes and view supported Mermaid diagrams and display equations directly in responses. (#46504, #46054, #45612)
  • •Update the local background server through /daemon, or bypass it with --no-daemon. (#45854, #46088)
  • •Preserve streamed answers and plans when turns fail, are interrupted, or receive subagent completion events. (#45549, #46867)
  • •Fix clipboard forwarding in tmux and SSH sessions and preserve tab indentation when terminals send pasted text as individual keystrokes. (#45457, #45454)
  • •Restore Plan mode when resuming sessions and preserve thread identity and settings when editing earlier prompts. (#45519, #45845)
  • •Recover login through system proxies and refresh MCP credentials when OAuth discovery returns a 503 error. (#46562, #44636)
  • •Prevent speech from being dropped during playback pauses or bursts of incoming audio. (#46880)
  • •Close sandbox isolation gaps involving inbound Windows connections, privileged Linux/macOS sockets, and writes through read-only macOS file handles. (#44639, #45984, #46500)
  • •Clarify that deprecated friendly and pragmatic personality settings no longer select response styles. (#45809)
  • •Explain how ? matches a single character in network proxy allow and deny patterns. (#46027)
  • •Update bundled TLS dependencies, including OpenSSL 3.6.4 for Linux musl builds. (#45149, #45489)
v0.155.1

0.155.1

September 18, 2026

  • •New local TUI sessions now leave reasoning summaries disabled by default, fixing request rejection by providers that do not support them. Explicit reasoning-summary settings remain respected. (#46467)
v0.155.0

0.155.0

September 18, 2026

  • •Added experimental /voice conversations with live transcripts and microphone controls on supported builds, enabled through /experimental. (#43581, #43651, #44331)
  • •The TUI now shows live reasoning summaries in the status row and completion timestamps after successful turns. (#43558, #43921)
  • •Added task hiding, archiving, and deletion in the agents overview, plus worktree ownership details and confirmed deletion of clean managed worktrees. (#43942, #44424, #44433)
  • •Added Touch ID verification for MCP requests in local TUI sessions on supported Macs. (#43624, #43712, #43715)
  • •Added configurable daemon update schedules and codex app-server daemon update; saved threads and active goals can recover after daemon restarts. (#43542, #43562, #44314)
  • •Amazon Bedrock can now obtain AWS credentials from configured commands, with caching, expiration-based refresh, and authentication recovery. (#44028)
  • •Accepted prompts are now saved even when compaction fails before a turn starts. (#44487)
  • •Fixed missed tmux resizes, transcript viewport restoration, and stale history appearing after switching threads. (#43603, #43889, #43994)
  • •MCP servers now report expired OAuth credentials accurately and provide reconnect guidance when token refresh fails. (#43947, #44359)
  • •Automatic approval reviews now preserve complete actions and authorization evidence more reliably, retry transient failures, and distinguish review failures from unsafe-action findings. (#44482, #44569, #44570)
  • •Switching accounts now invalidates remote-control sessions, cached WebSocket state, and model catalogs belonging to the previous identity. (#43906, #44341, #44489)
  • •Blocked Windows-process escapes from restricted WSL sandboxes and hardened brokered shell snapshots against credential exposure. (#44286, #43909, #44040)
  • •Aligned Python SDK and runtime publishing with stable CLI releases, using matching versions and verifying runtime assets before SDK publication. (#44067)
python-v0.154.0

Python SDK 0.154.0

September 10, 2026

  • •Add max and ultra reasoning-effort values. #39662
  • •Add ExternalMessage to synchronous and asynchronous run() and turn() calls. External content can start a turn or join an active regular turn with tool-level authority; it does not grant user authorization. Consumers receive independent event streams. #44086
  • •Add include_turns on resume/fork, turn_service_tier for one newly started turn, and source metadata. History selection changes the returned response, not model context. Existing defaults are preserved when these options are omitted. #44084
  • •Refresh generated protocol models and notifications, and preserve completion events that arrive before a turn-start response. #44032, #44400
  • •HookMetadata wraps its handler in .root. Replace accesses such as hook.command with hook.root.command, checking hook.root.handler_type before reading handler-specific fields.
  • •Some previously unknown notifications now have typed payloads. Read named fields instead of .params; unknown or invalid payloads still use UnknownNotification.
  • •Manually constructed or late-joining turn handles receive events from their attachment point. Earlier output is not replayed, so collected results can be partial; attaching after completion can raise TransportClosedError. Use thread.read(include_turns=True) for saved history. Handles returned directly by thread.turn(...) retain events from when their request is sent.
v0.154.0

0.154.0

September 10, 2026

  • •GPT-6-Astra is now available in the model picker and Amazon Bedrock catalogs. (#42879, #42619)
  • •Experimental worktree support lets you create isolated checkouts for new or forked sessions using --worktree or /worktree, then browse and resume them. (#42652, #43069, #43120, #43286)
  • •Answer questions inline while Codex continues working, using suggested choices or custom text without losing your main draft. (#42891, #42894, #42897)
  • •Windows sessions can now share a background Codex server, with daemon lifecycle commands and managed updates. (#42405, #42392)
  • •Vim editing gains R replace mode with undo and dot-repeat, plus more reliable Escape handling in legacy terminals. (#42194, #42584)
  • •Copying responses preserves formatting in rich-text apps, and /copy can copy status output or individual session fields. (#42847, #43055)
  • •Existing sessions pick up newly installed plugin tools and refresh skills and hooks after external plugin upgrades or rollbacks. (#42284, #42593, #42990)
  • •MCP connections coordinate OAuth token refreshes and surface login challenges when refresh fails, without automatically replaying rejected tool calls. (#42413, #42552)
  • •Startup avoids running workspace-controlled helpers before trust is established, and the macOS sandbox blocks terminal input injection. (#42324, #42590)
  • •Remote resume and fork operations preserve saved permissions; fresh sessions and forks respect server model defaults unless explicitly overridden. (#43330, #43177, #43355)
  • •Resuming a conversation open in another app now shows a read-only transcript with a retry option while preserving your draft. (#43253)
  • •Automatic approval reviews better preserve authorization context through compaction and reject approvals invalidated by new user instructions or answers. (#42844, #42852, #43442)
  • •Updated the bundled OpenAI Docs skill with GPT-6-Astra migration, compatibility, and prompting guidance. (#42931)
  • •The deprecated codex mcp-server entry point is no longer available. (#42993)
v0.153.4

0.153.4

September 5, 2026

  • •Fixed Astra’s visibility in the bundled model picker and made it the bundled default when no model is explicitly configured. (#42874)
  • •Updated Astra’s guidance to use asynchronous questions only when the tool is available in the session. (#42878)
v0.153.3

0.153.3

September 4, 2026

  • •Added GPT-6-Astra to the Amazon Bedrock model picker for Mantle and Runtime global/US routes. (#42805)
  • •Corrected GPT-6-Astra’s guidance for asynchronous clarification questions to use the supported tool and recognize that it accepts text only. (#42809)
v0.153.2

0.153.2

September 4, 2026

  • •Corrected the GPT-6-Astra Fast tier description to say “2x speed, increased usage” instead of “1.5x.” This changes only the displayed text, not how requests run. (#42632)
v0.153.1

0.153.1

September 3, 2026

  • •Added support for configuring GPT-6-Astra through the API without changing the default model or showing it in the model picker. (#42605)
v0.153.0

0.153.0

September 3, 2026

  • •Vim mode now supports undo with u and redo with Ctrl+R, preserving complete drafts including pasted content and attachments. (#41941, #42140)
  • •The plugin CLI can list, install, and remove plugins from remote marketplaces. (#42150)
  • •Set tui.auto_recap = false to disable automatic recaps while keeping manual /recap available. (#42101)
  • •TUI history shows complete patches, input sent to background terminals, and individual completed commands. (#41893, #42107)
  • •Plus and Team users receive an earlier warning when less than half of their allowance remains in an approximately five-hour usage window. (#42142)
  • •TUI sessions reconnect after an external app-server connection drops, preserving drafts and transcripts while keeping uncertain or queued submissions paused for review. (#41911, #41916, #41918)
  • •Full Access skips Guardian reviews for confirmation-only actions. User approval mode skips background Guardian scoring and prewarming, while sensitive-action checks and requests for user input retain their existing handling. (#42147, #42256)
  • •Guardian review history survives compaction, restarts, and user-created forks while respecting rollback boundaries and isolating subagent history. (#41879, #42065)
  • •Remembered MCP tool approvals are scoped to the selected app account, and relative MCP executable paths start more reliably on macOS. (#42133, #42117)
  • •Rollout compression includes shared histories, codex exec resume handles compressed rollouts when selecting by working directory, and thread forks work with symlinked session roots. (#42039, #42135)
  • •App-server thread metadata includes nullable model and reasoningEffort fields. Structured asynchronous questions are supported through request_user_input_async when enabled by the model catalog. (#42151, #42178)
  • •tui.disable_paste_burst replaces the top-level setting, which remains supported as a fallback. (#41976)
  • •Adds the disabled-by-default features.context_management.experimental_mode configuration. When enabled for eligible ChatGPT Plus, Pro, or Pro Lite sessions using the Codex backend, it activates token-budget context, history notes, and the new_context tool. API-key sessions, custom providers, and temporary structured threads remain excluded. (#42385)
  • •#41870 Use shared transcript collection for Guardian reviews
  • •#41879 Preserve Guardian review evidence across compaction
v0.152.1

0.152.1

September 2, 2026

  • •Guardian approval review now honors Node REPL policies provided through model metadata.
v0.152.0

0.152.0

September 1, 2026

  • •Vim mode supports / and ? searches within drafts, highlighted matches, and repeat navigation with n and N. (#41586)
  • •Rate-limit banners offer actions for checking usage, managing credits, resetting limits, and managing plans. (#41742)
  • •The terminal UI and codex exec show credential-refresh progress, including Amazon Bedrock reauthentication. (#41239)
  • •MCP server names can contain :, @, /, and ., supporting package-style names throughout CLI commands and authentication. (#41700)
  • •Individual MCP tools support an output_token_limit setting, with consistent truncation across session resumes. (#41421)
  • •App-server clients can configure thread/shellCommand timeouts, including deadlines longer than one hour. (#41384)
  • •Vim-enabled composers now start fresh drafts in Insert mode, including after submitting messages or dispatching slash commands. (#41921)
  • •Automatic approval reviews can retain longer messages and a larger conversation transcript. (#41931)
  • •Automatic approval reviews preserve user instructions, answers, and valid authorizations across history compaction. (#41660, #41846, #41852)
  • •Resumed threads restore their saved working directory when none is supplied, and client metadata updates preserve filesystem permissions. (#41567, #41464)
  • •MCP tools remain available through cache refreshes and remote plugin changes; authentication retries use refreshed helper-provided headers. (#41336, #41344, #41396, #41400)
  • •Opening the model picker refreshes available models without losing the highlighted choice. (#41467)
  • •Fixed Windows sandbox execution with Microsoft Store PowerShell, subprocess hangs on terminal queries, and cursor-related display corruption in older JediTerm terminals. (#41227, #41436, #41673)
  • •Cloud task requests reject untrusted backend URLs and disable redirects to protect saved credentials. (#41403)
  • •The planning tool is disabled by default; enable it with tools.update_plan.enabled = true. (#41744)
v0.151.0

0.151.0

August 29, 2026

  • •Added a configurable grace period for discovering tools from optional MCP servers. (#41199)
  • •Extensions can now inspect or replace MCP tool results before they reach the model. (#41202)
  • •Plugin catalogs now combine per-repository configuration and report invalid project marketplaces without hiding valid plugins. (#41208)
  • •Preserved restored permission profiles across TUI turns and prevented /cd from weakening sandbox restrictions. (#41192)
  • •Kept tool availability and reasoning effort correct when switching models or falling back to another model. (#41195, #41206)
  • •Improved remote sandbox enforcement using the executor’s actual home directory, operating system, and path conventions. (#41196, #41204, #41207, #41209)
  • •Preserved structured MCP tool and resource errors in app-server responses. (#41196)
  • •Counted nested subagent token usage toward root goal budgets. (#41183)
  • •Prevented stale Guardian classifications from authorizing actions after permission state changes. (#41196)
  • •Added telemetry for escalated stdin reviews and remote executor MCP discovery. (#41189, #41205)
  • •Stabilized Guardian WebSocket and core fixture tests under slow or highly concurrent CI. (#41191, #41194)
v0.150.1

0.150.1

August 27, 2026

  • •Remote compaction now counts retained images toward its token budget by default, trimming older images as needed. (#41003)
v0.150.0

0.150.0

August 26, 2026

  • •Reference other Codex tasks with @ mentions, and ask agents to read, create, or message tasks from the terminal. (#40308, #40315)
  • •/copy now offers a picker for full responses, individual code blocks, and blockquotes. (#39997)
  • •Unnamed terminal tasks receive descriptive titles automatically, and /rename suggests an editable title based on the conversation. (#40492, #40495)
  • •Markdown links appear as clickable labels in supported terminals, with visible URLs retained elsewhere. (#40471)
  • •Bind shortcuts to cycle permission modes, and use . in Vim mode to repeat your last edit. (#39873, #40521)
  • •New Interrupt hooks can run commands or MCP handlers when an active top-level turn is interrupted. (#40511)
  • •Untrusted projects no longer supply project-level AGENTS.md instructions, and managed deny-read rules remain enforced after permission changes. (#39837, #40004)
  • •Improved credential redaction in app-server diagnostics, including provider, authentication refresh, and attestation fields. (#39993)
  • •Fixed remote MCP bearer-token lookup and required-server startup while preserving compatibility with older executors. (#39926, #39952, #39979)
  • •Fixed elevated Windows sandbox setup and launch aliases under Unicode user paths. (#39971, #40570)
  • •Prevented Unix shutdown hangs caused by detached processes retaining a terminal or full terminal output buffers. (#40460)
  • •Fixed conversation compaction and multi-agent compatibility for Amazon Bedrock models. (#39804, #39825)
v0.149.1

0.149.1

August 24, 2026

## Changelog Full Changelog: https://github.com/openai/codex/compare/rust-v0.149.0...rust-v0.149.1

v0.149.0

0.149.0

August 20, 2026

  • •Added an interactive codex agents dashboard for searching, starting, opening, renaming, and stopping tasks, with configurable shortcuts. (#39094, #39112, #39114, #39142)
  • •Added /cd, /pwd, and /cwd commands for managing the working directory in TUI sessions. (#38894)
  • •Added codex queue for sending messages to existing local or remote sessions. (#39092)
  • •Expanded Vim editing with character replacement and more change motions such as cw, c$, and cc. (#39661)
  • •codex doctor now diagnoses endpoint protection, network/proxy failures, desktop app state, and update connectivity. (#38827, #38918, #39060, #39074)
  • •SDK users can now pass exact CLI config overrides and select max or ultra reasoning effort. (#38817, #39662)
  • •Queued messages now wake idle sessions reliably, resolve duplicate session names more usefully, and preserve pasted or deferred command semantics. (#39034, #39385, #39604)
  • •Resumed and forked threads now restore their active permission profile instead of silently falling back to current defaults. (#39153)
  • •Fixed duplicate sub-agent activity and tightened TUI routing for sub-agent notifications and approvals. (#39049, #39088)
  • •Realtime WebRTC sideband connections now reconnect after unexpected transport loss without dropping pending output. (#39257)
  • •Inline TUI history now remains available in Windows Terminal scrollback. (#39619)
  • •Inactive TUI thread replay buffers are now bounded to prevent excessive retained streamed output. (#39081)
  • •Clarified that external contributions should go through issues and design discussion rather than pull requests. (#39089)
  • •Documented DNS exfiltration risks and trust limitations for secure devcontainers. (#39283)
v0.148.0

0.148.0

August 19, 2026

  • •Export complete TUI conversations to Markdown with /export, either to the clipboard or a new file. (#37358)
  • •Fork sessions with codex exec fork, and archive or restore sessions from the TUI resume picker. (#37367, #37369, #37371)
  • •Draft prompts while the TUI initializes, with resume and fork progress shown during startup. (#38642, #38788)
  • •View estimated thread credits or cost in /status, status lines, and terminal titles for eligible workspaces. (#38281, #38282)
  • •Use Amazon Bedrock Runtime as a built-in provider with AWS profile, region, and GPT-5.6 routing support. (#38470)
  • •Hooks can now run commands asynchronously and invoke MCP tools. (#37533, #38705)
  • •Model switches and settings updates no longer leave stale instructions behind or change an active turn midstream. (#37260, #38785)
  • •Resumed sessions now restore their persisted working directory and approval policy, with more accurate transcript previews. (#37198, #37368, #38605)
  • •Turns reconnect through temporary provider outages, and MCP servers recover after OAuth reauthentication without restarting Codex. (#37337, #37485, #38418)
  • •TUI startup no longer lets buffered terminal input activate prompts accidentally, and onboarding appears when authentication is missing. (#38641, #38643, #38644)
  • •Composer and transcript rendering now handle CRLF pastes, wrapped whitespace, and long URLs correctly. (#37709, #38380, #38704)
  • •Sandbox restrictions now fail closed for denied or unreadable paths across Linux and Windows. (#37875, #38026, #38416, #38660)
  • •The bundled skill-creator guide is more focused, and validation now rejects unfinished TODO placeholders. (#38384)
v0.147.0

0.147.0

August 7, 2026

  • •Install portable Agent Plugins and search across local, personal, workspace, and remote plugin catalogs. (#36544, #36409, #36919, #36796)
  • •Organize conversations into persistent, manually ordered sections and browse long transcripts incrementally. (#35722, #36007, #36380, #36948, #36950)
  • •Enable automatically reviewed approvals with the new --approve-for-me CLI flag. (#36373)
  • •Import Cursor-managed skills and synchronize changes to imported Claude and Cursor conversations without creating duplicates. (#36361, #36356, #35623)
  • •Support the opt-in MCP 2026-07-28 protocol, including paginated discovery, multi-round requests, and non-blocking server startup. (#35724, #35725, #35590, #35742)
  • •Enable cached web search and remote conversation compaction for Amazon Bedrock. (#36938, #36981)
  • •Redact secrets and complete bearer tokens from displayed commands and replayed conversation history. (#36893, #36908)
  • •Prevent lost or stalled terminal input when focus returns, MCP servers initialize, or Ghostty handles keyboard shortcuts. (#35649, #35957, #36834)
  • •Correct rendering and cursor positioning for Japanese characters, emoji, hyperlinks, and text near viewport boundaries. (#35960, #35962, #37166)
  • •Properly interrupt Windows background processes and handle Windows filesystem paths consistently. (#35655, #35851, #37129)
  • •Require explicit trust for unfamiliar local projects and enforce managed authentication restrictions before credentials are used. (#36960, #37132)
  • •Harden plugin isolation and deny network access when policy updates fail. (#37027, #36967, #36037)
  • •Improve the bundled OpenAI documentation skill with targeted official-source lookup and clearer guidance for Codex, model selection, and API workflows. (#36014)
  • •Upgrade the MCP SDK to 3.0.0, Ratatui to 0.30.2, and V8 to 150.4.0. (#36001, #35959, #35831)
  • •Secure macOS release notarization using Azure Key Vault instead of exporting private signing keys. (#37154)
v0.146.1

0.146.1

August 5, 2026

  • •Apply safer automatic-review defaults for cyber-capable models and explain permission changes in the terminal interface. (#37057)
Showing 30 of 133