Codex CLI 0.158.0 asks before typing into commands with extra permissions, and drops GPT-5.4

20 hours ago

Codex CLI 0.158.0, released September 28, 2026: Codex now asks before the agent types into a command running with extra permissions, GPT-5.4 leaves the model list with a prompt to move to GPT-6 Sol, and MCP servers that need an OAuth client secret can sign in. Plus sandbox fixes on Windows, Linux and macOS. https://github.com/openai/codex/releases/tag/rust-v0.158.0 https://github.com/openai/codex/pull/47799 https://github.com/openai/codex/pull/47932 https://github.com/openai/codex/pull/47891

Ask

Ask about this presentation

Answers are generated from this presentation.

Chapters

  1. 0:00Codex CLI 0.158.0 is out
  2. 0:17Codex asks before typing into commands with extra permissions
  3. 0:41GPT-5.4 leaves the model list
  4. 1:01MCP servers that need a client secret now connect
  5. 1:23Smaller changes you'll notice
  6. 1:45Fixes and who should update
  7. 1:47Sandbox fixes on Windows, Linux and macOS
  8. 2:15Who should update
  9. 2:29Where the release notes are
Show transcript

Codex CLI 0.158.0 is out

0102What changed
openai/codex · GitHub release 0.158.0
Codex
Released September 28, 2026Stable release

OpenAI shipped Codex CLI version 0.158 on September 28th. It's the open source coding agent that runs in your terminal. The biggest changes are about what the agent can do without asking you, and which models it offers.

Codex asks before typing into commands with extra permissions

codex-cli 0.158.0
0102What changed
openai/codex · GitHub release 0.158.0 · openai/codex · pull request #47799

Codex now asks before it types into a command running with extra permissions

On by default. Commands inside the normal sandbox don't prompt.

First, a new approval. The agent can start a command and then type into it, to answer a prompt, for example. If that command is running with more permissions than the sandbox normally allows, Codex now asks you before the agent sends it anything. This was an experimental setting, and it's now on for everyone. A follow up fix means permissions Codex grants its own plugins no longer set off the prompt.

GPT-5.4 leaves the model list

codex-cli 0.158.0
0102What changed
openai/codex · pull request #47932

If you saved it as your model, Codex offers to switch you to GPT-6 Sol.

Second, GPT-5.4 is gone from the models Codex ships with, on OpenAI and on Amazon Bedrock. If you'd picked it and saved that choice, Codex doesn't break. It asks whether to move you to GPT-6 Sol, OpenAI's new model for balancing capability and cost, and keeps your provider as it was.

MCP servers that need a client secret now connect

codex-cli 0.158.0
0102What changed
openai/codex · GitHub release 0.158.0 · openai/codex · pull request #47891

MCP servers that require a client secret can now sign in

The secret stays out of logs, sign-in links and saved tokens.

Third, a fix for company tools. Some MCP servers only accept sign in from an app that was registered ahead of time, with an ID and a secret. Codex could hold the ID but not the secret, so those servers wouldn't connect. Now you can give it both, and Codex keeps the secret out of its debug output, out of the sign in link, and out of the tokens it saves.

Smaller changes you'll notice

codex-cli 0.158.0
0102What changed
openai/codex · GitHub release 0.158.0
Copy and pasteselect to copy and right-click to paste in the fullscreen view; copies keep their Markdown
Image generationcan ask for a transparent background, and edit images from files in the chat
Pro MaxCodex recognises the new plan and shows it as Pro (Max)

A few smaller things. In the fullscreen view you can now copy by selecting and paste with a right click, and a copied answer keeps its Markdown formatting. Image generation can ask for a transparent background, and edits can start from an image file in the conversation. And Codex now supports the new Pro Max plan, and shows it by name in its account screens.

Fixes and who should update

codex-cli 0.158.0
0102Fixes and who should update
02
Fixes and who should update

Then the fixes.

Sandbox fixes on Windows, Linux and macOS

codex-cli 0.158.0
0102Fixes and who should update
openai/codex · GitHub release 0.158.0

Sandbox fixes on every platform

Windowsfailures on ordinary Windows 10 paths, rejected saved credentials, large permission policies
Linux and macOSsandbox starts with nested writable folders; Git folders stay protected
macOSfewer needless approval prompts for system path aliases

Most of the fixes are in the sandbox that keeps the agent's commands contained. On Windows, it stopped failing on ordinary Windows 10 paths, on saved credentials the system had rejected, and on large permission policies. On Linux, it now starts when writable folders sit inside each other, and on Linux and macOS your Git folders stay protected across them. And on macOS, paths that are just aliases of system folders no longer trigger extra approval prompts.

Who should update

codex-cli 0.158.0
0102Fixes and who should update
openai/codex · GitHub release 0.158.0

Who should update first

Windows usersif the sandbox has been failing
Teams on company MCP serversthat need a client secret
Anyone pinned to GPT-5.4it's no longer listed

So who should update first? Windows users whose sandbox has been failing. Teams whose MCP servers need a client secret. And anyone with GPT-5.4 saved as their model, since it's no longer on the list.

Where the release notes are

codex-cli 0.158.0
0102Fixes and who should update
openai/codex · GitHub release 0.158.0

The release notes list every change

github.com/openai/codex › Releases › 0.158.0

One limit: the new approval only covers commands running with extra permissions. Everything inside the normal sandbox behaves as before. The full list of changes is in the release notes on the Codex GitHub page. That's Codex CLI 0.158: it asks before typing into commands with extra permissions, and drops GPT-5.4.