By NODVIEW editors

Sources

Codex 0.158.0 can connect to MCP servers that require an OAuth client secret

Codex 0.158.0 adds a way to connect to an MCP server with a pre-registered OAuth client when the server requires a client secret to sign in or refresh a token.

Codex 0.158.0 adds a way to connect to an MCP server with a pre-registered OAuth client when the server requires a client secret to sign in or refresh a token. Codex previously accepted a client ID but had no way to provide the corresponding secret, the change record says.

An MCP server gives Codex access to another service's tools or data. Some OAuth servers issue tokens only after the client authenticates with a secret, so a client ID alone cannot complete that flow. Version 0.158.0 accepts codex mcp add --oauth-client-secret or oauth.client_secret in configuration; it also requires a nonempty client ID. Codex passes those credentials through login and token refresh and invalidates a cached connection when the configured ID or secret changes.

The option is for MCP servers that use this particular OAuth setup. An open server, or an OAuth server that does not require a client secret, does not need it. OpenAI's implementation notes say the secret is redacted from debug output and omitted from authorization URLs and stored OAuth token records. The secret itself is stored in server configuration and still needs normal credential protection.

The release also adds optional bearer-token authentication for direct WebSocket connections to codex exec-server and fixes several Windows sandbox failures. WebSocket authentication is opt-in; the release notes do not say it is enabled by default.