Codex CLI
Changelog
OpenAI's command-line coding assistant
This page shows at most the 120 most recent releases from official sources. It does not claim to be a complete version history.
Latest Releases (133)
0.160.1
October 5, 2026
- •Preserve
SYSTEMROOT,TEMP, andTMPwhen launching remote stdio MCP servers with explicitly configured remote environment variables, allowing Unix hosts to retain the Windows executor's startup environment. - •#51121: Backport Windows remote MCP environment preservation to 0.160.
0.160.0
October 1, 2026
- •Browse older tasks in the agent command center with a keyboard-accessible “Show more” action. (#49106)
- •Select transcript text and paste with middle-click in fullscreen mode on supported local Linux X11 terminals. (#49112)
- •Start sessions outside a project with workspace defaults when policy permits, and restore saved permissions when resuming. (#49160)
- •Added opt-in Guardian review capabilities to retrieve earlier user instructions and include context from agent handoffs. (#49036, #49057)
- •Unsent queued messages now resume after reconnection once uncertain submissions are resolved, avoiding duplicate sends. (#49105)
- •The terminal UI now preserves server provider, reasoning-summary, and verbosity settings and shows the correct sessions in resume and fork history. (#49144, #49161, #49171)
- •Fixed Windows sandbox PowerShell fallbacks and long-path permission repairs, and suppressed unwanted console windows from background helpers. (#49019, #49058, #49098, #49164, #49386)
- •Subagents now retain environments that are still starting and receive their configuration or preparation failure. (#49075)
- •Prevented SQLite stalls during connection setup and logging, and surfaced initialization errors instead of masking them as timeouts. (#49032, #49102)
- •Explicit provider model catalogs no longer include unsupported bundled models or reuse stale entries after refresh failures. (#49135)
- •Clarified how provider credentials use the configured storage backend and how
env_keyidentifies the API-key environment variable. (#49118) - •Reduced repeated plugin-loading work by caching parsed manifests and reusing HTTP connections for remote plugin requests. (#49099, #49100)
- •Added background reclamation of unused log database space to reduce disk usage. (#49069)
0.159.1
September 29, 2026
- •Added GPT-6.1 Sol as the default model in the bundled catalog and Amazon Bedrock Mantle and Runtime catalogs. (#49323, #49342)
0.159.0
September 29, 2026
- •Opt-in
instant_interruptlets new input steer Codex during model responses or long-running code-mode calls. (#48135, #48141) - •New sessions get a compact welcome screen and consistent headers, with occasional tips during and after turns. (#48513, #48562, #48352)
- •The warnings viewer dismisses reviewed warnings when closed; press
kto keep one for later. (#48205, #48206) - •You can scroll the transcript while deciding whether to implement a plan. (#48805)
- •Native Mermaid rendering supports more flowchart edges, labels, and node groups. (#48814, #48895)
- •App-server clients can paginate thread history from a specific item. (#48151)
- •Windows launches avoid stray console windows for MCP servers, code-mode hosts, and piped commands; restrictive launchers can fall back to embedded mode. (#48138, #48238, #48483, #48491)
- •Copying transcript selections preserves Markdown tables, formatting, and significant whitespace. More terminals now copy automatically on selection. (#48548, #48549, #48469)
- •Blank sessions retain drafts when switching tasks, and threads can be archived and listed before their first turn. (#48628, #48828, #48199)
- •Local ChatGPT sign-in opens the browser reliably; onboarding also provides a shortcut to copy the login link. (#48502, #48544)
- •Approved commands retain explicit filesystem denials, and
.awsdirectories are protected by default under writable roots. (#48155, #48176) - •Fixed macOS TLS access in network-enabled sandboxes and remote environments that require proxy access. (#48565, #48198)
- •Removed automatic follow-up prompt suggestions and the
tui.prompt_suggestionssetting. (#48621) - •Removed the bundled
plugin-creatorskill. (#48604)
0.158.0
September 28, 2026
## New Features
- Configure copy-on-select and right-click paste in the fullscreen TUI. Copied transcript selections now preserve Markdown formatting. (#47639, #47896, #48118)
- Connect to MCP servers that require pre-registered OAuth client secrets, including through codex mcp add --oauth-client-secret. (#47891)
- Secure direct exec-server WebSocket connections with bearer tokens, including connections configured through app-server. (#47601, #47648)
- Image generation and editing can explicitly request transparent backgrounds, and edits now accept file-backed conversation images. (#47484, #47956)
- Terminal input approval is enabled by default for commands running with elevated permissions; runtime-only grants no longer cause unnecessary reviews. (#47799, #48073)
## Bug Fixes
- Fixed Windows sandbox failures involving ordinary Windows 10 paths, rejected stored credentials, and large permission policies. (#47672, #47695, #47919)
- Fixed Linux sandbox startup with nested writable roots and preserved Git metadata protections across writable roots on Linux and macOS. (#47623, #47974)
- macOS patch operations now recognize system path aliases covered by existing permissions, avoiding unnecessary approval prompts. (#47879)
- Approval reviews now retry when new user input arrives, so a status question does not automatically abort a pending action. (#47819)
- Mermaid flowcharts now render quoted labels and ampersands; unsupported diagrams explain why they fall back to source. (#47572, #47678)
- Command completion events now include early output and report process-launch failures to clients. (#47529, #47665)
## Changelog
Full Changelog: https://github.com/openai/codex/compare/rust-v0.157.0...rust-v0.158.0
- #47441 Use secondary text styling for the transcript footer shortcut hint @etraut-openai
- #47447 Extract WebSocket authentication into codex-websocket-auth @euroelessar
- #47458 Parallelize instruction refresh and tool preparation @hlevy-openai
- #47484 Add explicit background control to image generation @alicec-oai
- #47520 Route session agent operations through AgentControl @jif-oai
- #47529 Emit command lifecycle events for unified exec launch failures @steipete-oai
- #47536 Route agent lookups and V2 context through AgentControl @jif-oai
- #47539 Test interrupted one-shot command launch failure persistence @jif-oai
- #47540 Add an option to disable multi-agent v2 direct messaging @jif-oai
- #47565 Classify rollout read failures by reason and progress @jif-oai
- #47568 Record sandbox backends in command execution analytics @iceweasel-oai
- #47571 Wait for idle before injecting remote compaction test history @felixxia-oai
- #47572 Explain Mermaid rendering fallbacks in the TUI @etraut-openai
- #47582 Retain assistant context for Guardian authorization reviews @felixxia-oai
- #47584 Preserve streamed assistant message order in retained context @felixxia-oai
- #47585 Preserve delivered assistant messages in Guardian retained context @felixxia-oai
- #47589 Keep unfinished link destinations out of rich streaming previews @etraut-openai
- #47590 Serialize numeric custom reasoning effort as JSON numbers @dylan-hurd-oai
- #47591 Stream daemon executable hashing off the async runtime @etraut-openai
- #47596 Refresh realtime context for each model request @reia-oai
- #47597 Guard prerelease channel and canary updates against older versions @imac-oai
- #47601 Add opt-in WebSocket authentication to exec-server @euroelessar
- #47603 Add a reap-only drop policy for child processes @charliemarsh-oai
- #47604 Extend child commands with session and descriptor controls @charliemarsh-oai
- #47605 Route pipe processes through the shared child launcher @charliemarsh-oai
- #47610 Use native POSIX spawning for command hooks @charliemarsh-oai
- #47611 Use the shared process launcher for Unix shell snapshots @charliemarsh-oai
- #47612 Launch Linux pipe processes through a fresh setup helper @freeqaz-openai
- #47613 Expand Linux spawn-helper lifecycle test coverage @charliemarsh-oai
- #47617 Route Linux PTY launches through the process setup helper @charliemarsh-oai
- #47618 Prefer Shift-arrow hints for queued messages and questions @imac-oai
- #47619 Add bounded buffering for global operation metrics @celia-oai
- #47620 Add portable project trust lookup APIs @seanh-oai
- #47623 Fix read-only metadata mount ordering for nested writable roots @jif-oai
- #47624 Recognize user_message tools in Guardian authorization context @ankushg
- #47625 Allow history and notes without experimental context capability @pmccrary-oai
- #47629 Route V2 child loading through AgentControl @jif-oai
- #47630 Bind Guardian reviews to the action's target environment @jif-oai
- #47633 Route message board agent resolution through the selected controller @jif-oai
- #47635 Overlap startup WebSocket preconnect with tool discovery @bromano-oai
- #47638 Classify retryable exec-server preparation errors by type @mtsui-oai
- #47639 Add configurable copy-on-select for transcript selections @fcoury-oai
- #47641 Honor Retry-After and preserve server retry deadlines @anp-oai
- #47642 Add model-specific prefixes to indirect tool descriptions @rhan-oai
- #47647 Apply Guardian computer-use review to the Browser connector @johnl-oai
- #47648 Support bearer tokens for app-server executor connections @euroelessar
- #47649 Add opt-in OTLP logging for final agent responses @xli-oai
- #47653 Attach inherited rollout history to diagnostic reports @dkovalenko-oai
- #47654 Make Linux descriptor cleanup fork-safe @yuzhu-oai
- #47655 Bump the exec-server stable compatibility test to Codex 0.156.1 @imac-oai
- #47657 Restrict the default Bedrock GovCloud model catalog @jackz100
- #47662 Expose tool dispatch and timing observations to extensions @euroelessar
- #47663 Preserve managed network policy in route-aware transports @jackz100
- #47665 Preserve early unified exec output in completion events @sdcoffey
- #47670 Support model-specific descriptions for agent message board tools @eknight-oai
- #47672 Fix no-reparse directory opens on Windows 10 @zm-oai
- #47673 Clarify registered Windows sandbox setup errors @zm-oai
- #47677 Support model catalog overrides for MCP resource tool specs @rhan-oai
- #47678 Support quoted labels and ampersands in Mermaid flowcharts @etraut-openai
- #47679 Add extension hooks for model requests and response streams @euroelessar
- #47680 Add exec-server RPC timing and process startup tracing @anp-oai
- #47683 Add executor capability discovery V2 infrastructure @TAFOYA-OAI
- #47686 Make thread-owned Guardian context always enabled @felixxia-oai
- #47688 Remove legacy Guardian authorization evidence paths @felixxia-oai
- #47689 Make Guardian thread context capture unconditional @felixxia-oai
- #47690 Remove obsolete Guardian context capture mode branches @felixxia-oai
- #47691 Materialize rollout persistence for pending inter-agent messages @dermanyang-oai
- #47693 Configure curl retries for DotSlash installation in CI @anp-oai
- #47695 Repair rejected Windows sandbox credentials during provisioning @zm-oai
- #47696 Avoid the shutdown timeout in the lagged-event test @jgershen-oai
- #47698 Allow WebSocket test server shutdown while waiting for requests @jgershen-oai
- #47701 Allow idle threads to prewarm and repair WebSocket connections @vkg-oai
- #47703 Preserve account network policy for ChatGPT backend requests @jackz100
- #47704 Fix spawn flag typing and isolate project configuration tests @seanh-oai
- #47709 Route resume prewarm through the cached WebSocket session @vkg-oai
- #47712 Update unified exec output buffers atomically @sdcoffey
- #47713 Reduce dependency coupling in shared configuration crates @aibrahim-oai
- #47714 Preserve tool result metadata more selectively under size limits @ningyi-oai
- #47717 Avoid recursive TUI event dispatch for model picker selections @etraut-openai
- #47741 Attribute tool telemetry to the invoking turn's product SKU @rennie-openai
- #47742 Honor network policy in history notes and image generation extensions @jackz100
- #47745 Skip startup prewarm preparation when the WebSocket is ready @vkg-oai
- #47748 Align Cargo and Bazel Rust debug information defaults @aibrahim-oai
- #47751 Reduce generic code duplication in RPC and Markdown rendering @aibrahim-oai
- #47755 Centralize typed app-server response decoding @aibrahim-oai
- #47757 Refactor tool telemetry product SKU matching to use an allowlist @rennie-openai
- #47758 Preserve more tool metadata within outgoing message budgets @ningyi-oai
- #47773 Honor catalog schemas for asynchronous user input @rhan-oai
- #47797 Support close-on-exec attachments without changing PTY semantics @jif-oai
- #47799 Enable terminal input approval by default @jif-oai
- #47808 Allow hosts to provide agent controllers through ThreadManager @jif-oai
- #47811 Preserve explicit user goal updates in Guardian authorization @felixxia-oai
- #47813 Fix sleep interruption test event handling and fixture lifetime @felixxia-oai
- #47814 Fix a lost wakeup in the unified exec termination test @felixxia-oai
- #47817 Stabilize thread resume and memory dual-write tests @jif-oai
- #47819 Retry Guardian reviews when authorization changes @teddywyly-oai
- #47820 Add integration coverage for host agent controllers @jif-oai
- #47824 Allow four concurrent threads in the multi-agent resume test @felixxia-oai
- #47828 Wait for login completion in recommended plugin tests @felixxia-oai
- #47830 Bind Guardian async scores to target environment permissions @jif-oai
- #47832 Stabilize Rosetta test timing and retry delay telemetry @jif-oai
- #47847 Keep the TUI responsive during clipboard copies @fcoury-oai
- #47851 Preserve human overrides across repeated heartbeat instructions @felixxia-oai
- #47852 Avoid blocking async proxy resolution on the system proxy cache @jif-oai
- #47856 Initialize media estimates outside the global cache lock @jif-oai
- #47858 Validate loaded plugins outside the cache lock @jif-oai
- #47861 Avoid nested read locking when rendering browser sign-in @jif-oai
- #47867 Render remote permission paths using executor context @iceweasel-oai
- #47870 Add opt-in OTLP logging for Guardian assessments @jif-oai
- #47871 Fix PID reservation test race and update guardian heartbeat snapshot @jif-oai
- #47873 Measure deferred tool namespace fragments before and after truncation @mzeng-openai
- #47879 Fix macOS system-alias matching in patch permission checks @felixxia-oai
- #47881 Use Tokio's clock for TUI paste timing @charliemarsh-oai
- #47886 Preserve diagnostic logs when SQLite logging fails @dkovalenko-oai
- #47887 Warn users when SQLite diagnostic log writes fail @dkovalenko-oai
- #47889 Include TUI client logs in diagnostic uploads @etraut-openai
- #47891 Support client secrets for pre-registered MCP OAuth clients @willwang-openai
- #47894 Clean up temporary Codex homes after TUI tests @fcoury-oai
- #47896 Preserve Markdown formatting when copying transcript selections @fcoury-oai
- #47898 Preserve local-binding inheritance in environment network policies @seanh-oai
- #47899 Add diagnostic reasons to MCP attribution errors @peilin-openai
- #47900 Default local threads to paginated history @owenlin0
- #47901 Add bounded credential-storage telemetry helpers @celia-oai
- #47902 Avoid repeated table clones during config merging @imac-oai
- #47903 Move config key alias normalization ahead of merging @imac-oai
- #47904 Support nested canonical paths in config key aliases @imac-oai
- #47908 Alias tui.whimsy to tui.effects.starfield @imac-oai
- #47912 Fix attestation routing during thread startup @charliemarsh-oai
- #47913 Add an opt-in flag to defer mailbox preemption @jif-oai
- #47915 Reuse verified V8 checksum manifests from the artifact cache @aibrahim-oai
- #47918 Parameterize the turn-start originator header test @aibrahim-oai
- #47919 Transport large Windows sandbox launch payloads through the environment @malsamiri-oai
- #47920 Allow directory moves under global Seatbelt basename denies @chess-oai
- #47922 Allow full-access Windows setup to provision through registered Core @zm-oai
- #47924 Make project trust lookup paths explicit and defer root resolution @seanh-oai
- #47926 Retry file blob uploads on HTTP 502 and 504 @mtsui-oai
- #47927 Use 127.0.0.1 for local login redirects @willwang-openai
- #47932 Remove GPT-5.4 from bundled catalogs and preserve migration prompts @andrewgu-oai
- #47934 Apply the unchanged-model compaction shortcut to all session sources @hlevy-openai
- #47935 Allow cached catalogs to satisfy MCP startup readiness @hlevy-openai
- #47936 Make MCP and Code Mode input schema budgets configurable @vivi
- #47937 Add direct replies for thread settings updates @sayan-oai
- #47939 Separate selected plugin identities from MCP contributions @sayan-oai
- #47943 Remove unused Windows world-writable audit code @iceweasel-oai
- #47945 Parameterize the thread initialization analytics test by originator @eddie-openai
- #47946 Add an in-memory agent message board for ephemeral sessions @jif-oai
- #47947 Expand root authorization context to 16 messages @felixxia-oai
- #47951 Use prebuilt V8 archives for Bazel on macOS and GNU Linux @aibrahim-oai
- #47952 Prune expired in-memory message board registry entries @jif-oai
- #47954 Move fullscreen startup tips into the transcript @etraut-openai
- #47956 Support file references in image edit requests @kchainani-oai
- #47957 Bound tool-call observations to the outgoing Responses message budget @ningyi-oai
- #47962 Request transparent huge pages for Cargo and eligible Bazel rustc jobs @aibrahim-oai
- #47964 Preserve the client-agent header for Amazon Bedrock Runtime @celia-oai
- #47967 Surface Flex capacity failures as a distinct terminal error @sdcoffey
- #47968 Handle Btrfs device mismatches when masking daemon sockets @etraut-openai
- #47970 Expose current environment selections for a running turn @sayan-oai
- #47971 Add Pro Max plan support and update Pro display names @etraut-openai
- #47974 Preserve Git directory protections across writable roots @aionescu-oai
- #47975 Prevent stale voice answers from reappearing during speech recovery @etraut-openai
- #47981 Prepare MCP calls directly from advertised tool identities @hlevy-openai
- #47984 Add multi-agent spawn latency and failure metrics @owenlin0
- #47988 Reuse MCP handlers across equivalent bindings @hlevy-openai
- #47989 Add startup-only PID namespace inheritance to exec-server @open-matt
- #48004 Respect configured authentication in the thread manager sample @celia-oai
- #48015 Validate tool suggestion install URLs before showing the app link @aionescu-oai
- #48017 Test same-cell permission grants and strict review in code mode @anp-oai
- #48035 Remove plugin extension metadata from discovery and summaries @victor-openai
- #48060 Deduplicate retained instructions across Guardian reviews @felixxia-oai
- #48069 Handle early command yields in the Guardian network approval test @jif-oai
- #48072 Skip message-board notification previews when there are no recipients @jif-oai
- #48073 Avoid stdin approval for runtime-only permission grants @jif-oai
- #48077 Add Serde support to agent message board request types @jif-oai
- #48078 Replay exec-server shell snapshots through unnamed files @jif-oai
- #48098 Preserve recent authorization context for Guardian reviews @felixxia-oai
- #48099 Honor shell environment policy in legacy snapshots @jif-oai
- #48100 Add an HTTP client for remote agent message boards @jif-oai
- #48101 Show multiline command previews in /ps @etraut-openai
- #48109 Deduplicate retained instructions against Guardian transcripts @felixxia-oai
- #48110 Deduplicate retained instructions in async Guardian context @felixxia-oai
- #48115 Preserve user text parts during local compaction @felixxia-oai
- #48116 Allow reasoning shortcuts to reach Max @etraut-openai
- #48118 Add configurable right-click paste to the fullscreen TUI @fcoury-oai
- #48119 Prevent worker completion races in the guardian authorization test @felixxia-oai
- #48121 Keep startup drafts visible during command center session handoff @etraut-openai
- #48123 Add early yielding for code-mode observations @pakrym-oai
- #48130 Use request notifications in the cloud config loader lifetime test @felixxia-oai
- #48132 Allow Left to open the command center from read-only conversations @etraut-openai
0.157.0
September 25, 2026
- •Added GPT-6 Sol and Luna, including Amazon Bedrock support and migration prompts for older models. (#47332, #47347)
- •Enabled fullscreen transcripts by default and added Shift-click to extend text selections. (#47178, #47414)
- •Enabled automatic background-server startup for eligible interactive sessions, with recovery choices when server settings are incompatible. (#47179, #47318)
- •Added an
fshortcut to fork conversations open in another app, preserving drafts and queued prompts. (#47185) - •Made
/importavailable in remote sessions and local background-server sessions. (#47317) - •Improved terminal rendering with Unicode bullets, checkboxes, aligned equations, and optimization notation. (#47191, #47322)
- •Preserved active voice conversations when switching threads. (#47381)
- •Recovered unsent question answers into the composer when turns end, without disrupting active history searches. (#47422, #47423)
- •Respected tmux mouse settings and restored native scrollback for Terminal.app over SSH in automatic screen mode. (#47399, #47417)
- •Fixed configured proxy routing for realtime connections and standalone web search, including search redirects. (#47101, #47142, #47204)
- •Added retries for transient file-upload failures and increased the upload timeout to five minutes. (#47122, #47393)
- •Enforced network restrictions across redirects and ongoing HTTP and WebSocket traffic, including cancellation when policy changes revoke access. (#47389, #47407)
0.156.1
September 23, 2026
- •Choose GPT-6 Sol or GPT-6 Luna from the model picker. The rate-limit switch prompt now recommends GPT-6 Luna. (#47405)
0.156.0
September 22, 2026
- •Choose an optional fullscreen UI with
/tuifor your next launch, including transcript search, mouse selection, and right-click copying. (#46732, #46734, #46883, #46895) - •Voice conversations are enabled by default, with an F8 toggle, a
/voice settingspicker, and bundled audio runtimes for Linux and Windows. (#44921, #46071, #44622, #44714, #44922) - •Explore account usage, token totals, and plugin and skill activity through the
/usageanalytics dashboard. (#45764, #45769) - •Filter tasks by status and create worktree sessions from the agent command center; worktree support is now enabled by default. (#46839, #45276, #44870)
- •Customize the terminal with six new themes and view supported Mermaid diagrams and display equations directly in responses. (#46504, #46054, #45612)
- •Update the local background server through
/daemon, or bypass it with--no-daemon. (#45854, #46088) - •Preserve streamed answers and plans when turns fail, are interrupted, or receive subagent completion events. (#45549, #46867)
- •Fix clipboard forwarding in tmux and SSH sessions and preserve tab indentation when terminals send pasted text as individual keystrokes. (#45457, #45454)
- •Restore Plan mode when resuming sessions and preserve thread identity and settings when editing earlier prompts. (#45519, #45845)
- •Recover login through system proxies and refresh MCP credentials when OAuth discovery returns a 503 error. (#46562, #44636)
- •Prevent speech from being dropped during playback pauses or bursts of incoming audio. (#46880)
- •Close sandbox isolation gaps involving inbound Windows connections, privileged Linux/macOS sockets, and writes through read-only macOS file handles. (#44639, #45984, #46500)
- •Clarify that deprecated
friendlyandpragmaticpersonality settings no longer select response styles. (#45809) - •Explain how
?matches a single character in network proxy allow and deny patterns. (#46027) - •Update bundled TLS dependencies, including OpenSSL 3.6.4 for Linux musl builds. (#45149, #45489)
0.155.0
September 18, 2026
- •Added experimental
/voiceconversations with live transcripts and microphone controls on supported builds, enabled through/experimental. (#43581, #43651, #44331) - •The TUI now shows live reasoning summaries in the status row and completion timestamps after successful turns. (#43558, #43921)
- •Added task hiding, archiving, and deletion in the agents overview, plus worktree ownership details and confirmed deletion of clean managed worktrees. (#43942, #44424, #44433)
- •Added Touch ID verification for MCP requests in local TUI sessions on supported Macs. (#43624, #43712, #43715)
- •Added configurable daemon update schedules and
codex app-server daemon update; saved threads and active goals can recover after daemon restarts. (#43542, #43562, #44314) - •Amazon Bedrock can now obtain AWS credentials from configured commands, with caching, expiration-based refresh, and authentication recovery. (#44028)
- •Accepted prompts are now saved even when compaction fails before a turn starts. (#44487)
- •Fixed missed tmux resizes, transcript viewport restoration, and stale history appearing after switching threads. (#43603, #43889, #43994)
- •MCP servers now report expired OAuth credentials accurately and provide reconnect guidance when token refresh fails. (#43947, #44359)
- •Automatic approval reviews now preserve complete actions and authorization evidence more reliably, retry transient failures, and distinguish review failures from unsafe-action findings. (#44482, #44569, #44570)
- •Switching accounts now invalidates remote-control sessions, cached WebSocket state, and model catalogs belonging to the previous identity. (#43906, #44341, #44489)
- •Blocked Windows-process escapes from restricted WSL sandboxes and hardened brokered shell snapshots against credential exposure. (#44286, #43909, #44040)
- •Aligned Python SDK and runtime publishing with stable CLI releases, using matching versions and verifying runtime assets before SDK publication. (#44067)
Python SDK 0.154.0
September 10, 2026
- •Add
maxandultrareasoning-effort values. #39662 - •Add
ExternalMessageto synchronous and asynchronousrun()andturn()calls. External content can start a turn or join an active regular turn with tool-level authority; it does not grant user authorization. Consumers receive independent event streams. #44086 - •Add
include_turnson resume/fork,turn_service_tierfor one newly started turn, andsourcemetadata. History selection changes the returned response, not model context. Existing defaults are preserved when these options are omitted. #44084 - •Refresh generated protocol models and notifications, and preserve completion events that arrive before a turn-start response. #44032, #44400
- •
HookMetadatawraps its handler in.root. Replace accesses such ashook.commandwithhook.root.command, checkinghook.root.handler_typebefore reading handler-specific fields. - •Some previously unknown notifications now have typed payloads. Read named fields instead of
.params; unknown or invalid payloads still useUnknownNotification. - •Manually constructed or late-joining turn handles receive events from their attachment point. Earlier output is not replayed, so collected results can be partial; attaching after completion can raise
TransportClosedError. Usethread.read(include_turns=True)for saved history. Handles returned directly bythread.turn(...)retain events from when their request is sent.
0.154.0
September 10, 2026
- •GPT-6-Astra is now available in the model picker and Amazon Bedrock catalogs. (#42879, #42619)
- •Experimental worktree support lets you create isolated checkouts for new or forked sessions using
--worktreeor/worktree, then browse and resume them. (#42652, #43069, #43120, #43286) - •Answer questions inline while Codex continues working, using suggested choices or custom text without losing your main draft. (#42891, #42894, #42897)
- •Windows sessions can now share a background Codex server, with daemon lifecycle commands and managed updates. (#42405, #42392)
- •Vim editing gains
Rreplace mode with undo and dot-repeat, plus more reliable Escape handling in legacy terminals. (#42194, #42584) - •Copying responses preserves formatting in rich-text apps, and
/copycan copy status output or individual session fields. (#42847, #43055) - •Existing sessions pick up newly installed plugin tools and refresh skills and hooks after external plugin upgrades or rollbacks. (#42284, #42593, #42990)
- •MCP connections coordinate OAuth token refreshes and surface login challenges when refresh fails, without automatically replaying rejected tool calls. (#42413, #42552)
- •Startup avoids running workspace-controlled helpers before trust is established, and the macOS sandbox blocks terminal input injection. (#42324, #42590)
- •Remote resume and fork operations preserve saved permissions; fresh sessions and forks respect server model defaults unless explicitly overridden. (#43330, #43177, #43355)
- •Resuming a conversation open in another app now shows a read-only transcript with a retry option while preserving your draft. (#43253)
- •Automatic approval reviews better preserve authorization context through compaction and reject approvals invalidated by new user instructions or answers. (#42844, #42852, #43442)
- •Updated the bundled OpenAI Docs skill with GPT-6-Astra migration, compatibility, and prompting guidance. (#42931)
- •The deprecated
codex mcp-serverentry point is no longer available. (#42993)
0.153.3
September 4, 2026
- •Added GPT-6-Astra to the Amazon Bedrock model picker for Mantle and Runtime global/US routes. (#42805)
- •Corrected GPT-6-Astra’s guidance for asynchronous clarification questions to use the supported tool and recognize that it accepts text only. (#42809)
0.153.1
September 3, 2026
- •Added support for configuring GPT-6-Astra through the API without changing the default model or showing it in the model picker. (#42605)
0.153.0
September 3, 2026
- •Vim mode now supports undo with
uand redo withCtrl+R, preserving complete drafts including pasted content and attachments. (#41941, #42140) - •The plugin CLI can list, install, and remove plugins from remote marketplaces. (#42150)
- •Set
tui.auto_recap = falseto disable automatic recaps while keeping manual/recapavailable. (#42101) - •TUI history shows complete patches, input sent to background terminals, and individual completed commands. (#41893, #42107)
- •Plus and Team users receive an earlier warning when less than half of their allowance remains in an approximately five-hour usage window. (#42142)
- •TUI sessions reconnect after an external app-server connection drops, preserving drafts and transcripts while keeping uncertain or queued submissions paused for review. (#41911, #41916, #41918)
- •Full Access skips Guardian reviews for confirmation-only actions. User approval mode skips background Guardian scoring and prewarming, while sensitive-action checks and requests for user input retain their existing handling. (#42147, #42256)
- •Guardian review history survives compaction, restarts, and user-created forks while respecting rollback boundaries and isolating subagent history. (#41879, #42065)
- •Remembered MCP tool approvals are scoped to the selected app account, and relative MCP executable paths start more reliably on macOS. (#42133, #42117)
- •Rollout compression includes shared histories,
codex exec resumehandles compressed rollouts when selecting by working directory, and thread forks work with symlinked session roots. (#42039, #42135) - •App-server thread metadata includes nullable
modelandreasoningEffortfields. Structured asynchronous questions are supported throughrequest_user_input_asyncwhen enabled by the model catalog. (#42151, #42178) - •
tui.disable_paste_burstreplaces the top-level setting, which remains supported as a fallback. (#41976) - •Adds the disabled-by-default
features.context_management.experimental_modeconfiguration. When enabled for eligible ChatGPT Plus, Pro, or Pro Lite sessions using the Codex backend, it activates token-budget context, history notes, and thenew_contexttool. API-key sessions, custom providers, and temporary structured threads remain excluded. (#42385) - •#41870 Use shared transcript collection for Guardian reviews
- •#41879 Preserve Guardian review evidence across compaction
0.152.0
September 1, 2026
- •Vim mode supports
/and?searches within drafts, highlighted matches, and repeat navigation withnandN. (#41586) - •Rate-limit banners offer actions for checking usage, managing credits, resetting limits, and managing plans. (#41742)
- •The terminal UI and
codex execshow credential-refresh progress, including Amazon Bedrock reauthentication. (#41239) - •MCP server names can contain
:,@,/, and., supporting package-style names throughout CLI commands and authentication. (#41700) - •Individual MCP tools support an
output_token_limitsetting, with consistent truncation across session resumes. (#41421) - •App-server clients can configure
thread/shellCommandtimeouts, including deadlines longer than one hour. (#41384) - •Vim-enabled composers now start fresh drafts in Insert mode, including after submitting messages or dispatching slash commands. (#41921)
- •Automatic approval reviews can retain longer messages and a larger conversation transcript. (#41931)
- •Automatic approval reviews preserve user instructions, answers, and valid authorizations across history compaction. (#41660, #41846, #41852)
- •Resumed threads restore their saved working directory when none is supplied, and client metadata updates preserve filesystem permissions. (#41567, #41464)
- •MCP tools remain available through cache refreshes and remote plugin changes; authentication retries use refreshed helper-provided headers. (#41336, #41344, #41396, #41400)
- •Opening the model picker refreshes available models without losing the highlighted choice. (#41467)
- •Fixed Windows sandbox execution with Microsoft Store PowerShell, subprocess hangs on terminal queries, and cursor-related display corruption in older JediTerm terminals. (#41227, #41436, #41673)
- •Cloud task requests reject untrusted backend URLs and disable redirects to protect saved credentials. (#41403)
- •The planning tool is disabled by default; enable it with
tools.update_plan.enabled = true. (#41744)
0.151.0
August 29, 2026
- •Added a configurable grace period for discovering tools from optional MCP servers. (#41199)
- •Extensions can now inspect or replace MCP tool results before they reach the model. (#41202)
- •Plugin catalogs now combine per-repository configuration and report invalid project marketplaces without hiding valid plugins. (#41208)
- •Preserved restored permission profiles across TUI turns and prevented
/cdfrom weakening sandbox restrictions. (#41192) - •Kept tool availability and reasoning effort correct when switching models or falling back to another model. (#41195, #41206)
- •Improved remote sandbox enforcement using the executor’s actual home directory, operating system, and path conventions. (#41196, #41204, #41207, #41209)
- •Preserved structured MCP tool and resource errors in app-server responses. (#41196)
- •Counted nested subagent token usage toward root goal budgets. (#41183)
- •Prevented stale Guardian classifications from authorizing actions after permission state changes. (#41196)
- •Added telemetry for escalated stdin reviews and remote executor MCP discovery. (#41189, #41205)
- •Stabilized Guardian WebSocket and core fixture tests under slow or highly concurrent CI. (#41191, #41194)
0.150.0
August 26, 2026
- •Reference other Codex tasks with
@mentions, and ask agents to read, create, or message tasks from the terminal. (#40308, #40315) - •
/copynow offers a picker for full responses, individual code blocks, and blockquotes. (#39997) - •Unnamed terminal tasks receive descriptive titles automatically, and
/renamesuggests an editable title based on the conversation. (#40492, #40495) - •Markdown links appear as clickable labels in supported terminals, with visible URLs retained elsewhere. (#40471)
- •Bind shortcuts to cycle permission modes, and use
.in Vim mode to repeat your last edit. (#39873, #40521) - •New
Interrupthooks can run commands or MCP handlers when an active top-level turn is interrupted. (#40511) - •Untrusted projects no longer supply project-level
AGENTS.mdinstructions, and managed deny-read rules remain enforced after permission changes. (#39837, #40004) - •Improved credential redaction in app-server diagnostics, including provider, authentication refresh, and attestation fields. (#39993)
- •Fixed remote MCP bearer-token lookup and required-server startup while preserving compatibility with older executors. (#39926, #39952, #39979)
- •Fixed elevated Windows sandbox setup and launch aliases under Unicode user paths. (#39971, #40570)
- •Prevented Unix shutdown hangs caused by detached processes retaining a terminal or full terminal output buffers. (#40460)
- •Fixed conversation compaction and multi-agent compatibility for Amazon Bedrock models. (#39804, #39825)
0.149.0
August 20, 2026
- •Added an interactive
codex agentsdashboard for searching, starting, opening, renaming, and stopping tasks, with configurable shortcuts. (#39094, #39112, #39114, #39142) - •Added
/cd,/pwd, and/cwdcommands for managing the working directory in TUI sessions. (#38894) - •Added
codex queuefor sending messages to existing local or remote sessions. (#39092) - •Expanded Vim editing with character replacement and more change motions such as
cw,c$, andcc. (#39661) - •
codex doctornow diagnoses endpoint protection, network/proxy failures, desktop app state, and update connectivity. (#38827, #38918, #39060, #39074) - •SDK users can now pass exact CLI config overrides and select
maxorultrareasoning effort. (#38817, #39662) - •Queued messages now wake idle sessions reliably, resolve duplicate session names more usefully, and preserve pasted or deferred command semantics. (#39034, #39385, #39604)
- •Resumed and forked threads now restore their active permission profile instead of silently falling back to current defaults. (#39153)
- •Fixed duplicate sub-agent activity and tightened TUI routing for sub-agent notifications and approvals. (#39049, #39088)
- •Realtime WebRTC sideband connections now reconnect after unexpected transport loss without dropping pending output. (#39257)
- •Inline TUI history now remains available in Windows Terminal scrollback. (#39619)
- •Inactive TUI thread replay buffers are now bounded to prevent excessive retained streamed output. (#39081)
- •Clarified that external contributions should go through issues and design discussion rather than pull requests. (#39089)
- •Documented DNS exfiltration risks and trust limitations for secure devcontainers. (#39283)
0.148.0
August 19, 2026
- •Export complete TUI conversations to Markdown with
/export, either to the clipboard or a new file. (#37358) - •Fork sessions with
codex exec fork, and archive or restore sessions from the TUI resume picker. (#37367, #37369, #37371) - •Draft prompts while the TUI initializes, with resume and fork progress shown during startup. (#38642, #38788)
- •View estimated thread credits or cost in
/status, status lines, and terminal titles for eligible workspaces. (#38281, #38282) - •Use Amazon Bedrock Runtime as a built-in provider with AWS profile, region, and GPT-5.6 routing support. (#38470)
- •Hooks can now run commands asynchronously and invoke MCP tools. (#37533, #38705)
- •Model switches and settings updates no longer leave stale instructions behind or change an active turn midstream. (#37260, #38785)
- •Resumed sessions now restore their persisted working directory and approval policy, with more accurate transcript previews. (#37198, #37368, #38605)
- •Turns reconnect through temporary provider outages, and MCP servers recover after OAuth reauthentication without restarting Codex. (#37337, #37485, #38418)
- •TUI startup no longer lets buffered terminal input activate prompts accidentally, and onboarding appears when authentication is missing. (#38641, #38643, #38644)
- •Composer and transcript rendering now handle CRLF pastes, wrapped whitespace, and long URLs correctly. (#37709, #38380, #38704)
- •Sandbox restrictions now fail closed for denied or unreadable paths across Linux and Windows. (#37875, #38026, #38416, #38660)
- •The bundled skill-creator guide is more focused, and validation now rejects unfinished TODO placeholders. (#38384)
0.147.0
August 7, 2026
- •Install portable Agent Plugins and search across local, personal, workspace, and remote plugin catalogs. (#36544, #36409, #36919, #36796)
- •Organize conversations into persistent, manually ordered sections and browse long transcripts incrementally. (#35722, #36007, #36380, #36948, #36950)
- •Enable automatically reviewed approvals with the new
--approve-for-meCLI flag. (#36373) - •Import Cursor-managed skills and synchronize changes to imported Claude and Cursor conversations without creating duplicates. (#36361, #36356, #35623)
- •Support the opt-in MCP 2026-07-28 protocol, including paginated discovery, multi-round requests, and non-blocking server startup. (#35724, #35725, #35590, #35742)
- •Enable cached web search and remote conversation compaction for Amazon Bedrock. (#36938, #36981)
- •Redact secrets and complete bearer tokens from displayed commands and replayed conversation history. (#36893, #36908)
- •Prevent lost or stalled terminal input when focus returns, MCP servers initialize, or Ghostty handles keyboard shortcuts. (#35649, #35957, #36834)
- •Correct rendering and cursor positioning for Japanese characters, emoji, hyperlinks, and text near viewport boundaries. (#35960, #35962, #37166)
- •Properly interrupt Windows background processes and handle Windows filesystem paths consistently. (#35655, #35851, #37129)
- •Require explicit trust for unfamiliar local projects and enforce managed authentication restrictions before credentials are used. (#36960, #37132)
- •Harden plugin isolation and deny network access when policy updates fail. (#37027, #36967, #36037)
- •Improve the bundled OpenAI documentation skill with targeted official-source lookup and clearer guidance for Codex, model selection, and API workflows. (#36014)
- •Upgrade the MCP SDK to 3.0.0, Ratatui to 0.30.2, and V8 to 150.4.0. (#36001, #35959, #35831)
- •Secure macOS release notarization using Azure Key Vault instead of exporting private signing keys. (#37154)