Module and user opt-in#
Codex is disabled by default. After module enablement/configuration, per-user preferences support opt-in, ChatGPT OAuth or API-key mode, models and reasoning. Bootstrap is registered disabled/internal; it is not a chat-exposed tool.
App Server bridge#
A stdio App Server process supports account/authentication, models, threads and turns. User/auth-mode homes, preferences and thread bindings are separate. YAADMIN registry tools become dynamic descriptors and execute through RuntimeSession RBAC/approvals. Live Activity receives turn/tool telemetry.
Access#
codex.use controls user routing with a special no_applicable_assignment fallback for assigned roles; explicit deny/require_approval and no-role denial remain blocked. codex.manage maps the internal bootstrap capability.
Exact registered tools#
codex.bootstrapcodex.manage
Internal Codex module anchor. Not exposed to the chat model.
Registration: RiskLevel.READ / ApprovalMode.NEVER · disabled/internal
local `{ok: true, module: codex, internal: true}` Runtime RBAC can raise deny or force approval even where metadata says NEVER/POLICY; static metadata is not final policy.
Exact input schema
{
"type": "object",
"required": [],
"additionalProperties": false,
"properties": []
}