Codex CLI 0.158.0 is out
OpenAI shipped Codex CLI version 0.158 on September 28th. It's the open source coding agent that runs in your terminal. The biggest changes are about what the agent can do without asking you, and which models it offers.
Codex asks before typing into commands with extra permissions
codex-cli 0.158.0Codex now asks before it types into a command running with extra permissions
On by default. Commands inside the normal sandbox don't prompt.
First, a new approval. The agent can start a command and then type into it, to answer a prompt, for example. If that command is running with more permissions than the sandbox normally allows, Codex now asks you before the agent sends it anything. This was an experimental setting, and it's now on for everyone. A follow up fix means permissions Codex grants its own plugins no longer set off the prompt.
GPT-5.4 leaves the model list
codex-cli 0.158.0If you saved it as your model, Codex offers to switch you to GPT-6 Sol.
Second, GPT-5.4 is gone from the models Codex ships with, on OpenAI and on Amazon Bedrock. If you'd picked it and saved that choice, Codex doesn't break. It asks whether to move you to GPT-6 Sol, OpenAI's new model for balancing capability and cost, and keeps your provider as it was.
MCP servers that need a client secret now connect
codex-cli 0.158.0MCP servers that require a client secret can now sign in
The secret stays out of logs, sign-in links and saved tokens.
Third, a fix for company tools. Some MCP servers only accept sign in from an app that was registered ahead of time, with an ID and a secret. Codex could hold the ID but not the secret, so those servers wouldn't connect. Now you can give it both, and Codex keeps the secret out of its debug output, out of the sign in link, and out of the tokens it saves.
Smaller changes you'll notice
codex-cli 0.158.0A few smaller things. In the fullscreen view you can now copy by selecting and paste with a right click, and a copied answer keeps its Markdown formatting. Image generation can ask for a transparent background, and edits can start from an image file in the conversation. And Codex now supports the new Pro Max plan, and shows it by name in its account screens.
Fixes and who should update
codex-cli 0.158.0Then the fixes.
Sandbox fixes on Windows, Linux and macOS
codex-cli 0.158.0Sandbox fixes on every platform
Most of the fixes are in the sandbox that keeps the agent's commands contained. On Windows, it stopped failing on ordinary Windows 10 paths, on saved credentials the system had rejected, and on large permission policies. On Linux, it now starts when writable folders sit inside each other, and on Linux and macOS your Git folders stay protected across them. And on macOS, paths that are just aliases of system folders no longer trigger extra approval prompts.
Who should update
codex-cli 0.158.0Who should update first
So who should update first? Windows users whose sandbox has been failing. Teams whose MCP servers need a client secret. And anyone with GPT-5.4 saved as their model, since it's no longer on the list.
Where the release notes are
codex-cli 0.158.0The release notes list every change
github.com/openai/codex › Releases › 0.158.0
One limit: the new approval only covers commands running with extra permissions. Everything inside the normal sandbox behaves as before. The full list of changes is in the release notes on the Codex GitHub page. That's Codex CLI 0.158: it asks before typing into commands with extra permissions, and drops GPT-5.4.








