Codex CLI v0.158: MCP OAuth client secrets and approval for elevated commands

Codex Published:

What changed in Codex CLI v0.158.0: MCP servers that need pre-registered OAuth client secrets, terminal approval on by default for elevated commands, and the sandbox fixes.

Verified on Sep 30, 2026 These tools change quickly. Please also check the latest official documentation.
Contents
  1. Approvals: a changed default
  2. MCP: OAuth client secrets
  3. Sandbox fixes
  4. TUI changes, and what followed in v0.159
  5. Summary

Codex CLI v0.158.0 lands changes that touch MCP, the sandbox and approvals — the parts you notice in daily use.

Two items matter most: terminal input approval is now on by default for commands running with elevated permissions, and Codex can now connect to MCP servers that require pre-registered OAuth client secrets.

This article works from the v0.158.0 release notes as the primary source, covering what affects your configuration, and then what followed in v0.159.0 and v0.159.2.

KEY POINT

What you will learn

  • Approval becoming the default for elevated commands
  • MCP OAuth client secret support, and where the configuration reference has not caught up
  • The sandbox fixes on Windows, Linux and macOS

Approvals: a changed default

From the v0.158.0 New Features:

Terminal input approval is enabled by default for commands running with elevated permissions; runtime-only grants no longer cause unnecessary reviews.

If you run commands with administrator or otherwise elevated permissions, expect an approval where there was none before. In the other direction, grants given only for the duration of a run should stop triggering repeat reviews.

Two related fixes ship alongside it:

  • "Approved commands retain explicit filesystem denials" (v0.159.0 Bug Fixes)
  • "Approval reviews now retry when new user input arrives, so a status question does not automatically abort a pending action" (v0.158.0 Bug Fixes)

For how approval policies and the sandbox combine, see Codex approval modes and sandbox.

MCP: OAuth client secrets

From the New Features:

Connect to MCP servers that require pre-registered OAuth client secrets, including through codex mcp add --oauth-client-secret.

Servers that do not support Dynamic Client Registration make you register an OAuth app in their developer portal and take a client ID and secret back. Until now there was no way to hand Codex that secret, so those servers were out of reach.

This flag is not in the configuration reference yet

--oauth-client-secret appears in the v0.158.0 release notes, but it was not in the official configuration reference as of September 30, 2026. The OAuth keys that page does document for an MCP server are oauth.client_id, oauth.callback_port and oauth.callback_url, and it says nothing about where a client secret is stored. Treat the flag name and behavior as a release-note claim.

What the reference does document today stops at the client ID and the callback:

[mcp_servers.example]
url = "https://mcp.example.com/mcp"

[mcp_servers.example.oauth]
client_id = "your-client-id"
callback_port = 8080

The same release also secures direct exec-server WebSocket connections with bearer tokens, including connections configured through app-server.

Sandbox fixes

Three of the Bug Fixes concern the sandbox, split across platforms.

PlatformWhat the release notes say
WindowsSandbox failures involving ordinary Windows 10 paths, rejected stored credentials, and large permission policies
LinuxSandbox startup with nested writable roots
Linux and macOSGit metadata protections preserved across writable roots
macOSPatch operations now recognize system path aliases covered by existing permissions, avoiding unnecessary approval prompts

If you configure several writable roots, a nested arrangement failed to start on Linux before this release. Configuration is covered in Extending where Codex can write with writable_roots.

v0.159.0 widens the protection further: .aws directories are "protected by default under writable roots". That said, which directories are protected by default inside a writable root could not be confirmed on the official sandboxing page — read it as a release-note claim.

TUI changes, and what followed in v0.159

v0.158.0 makes copy-on-select and right-click paste configurable in the fullscreen TUI, and copied transcript selections keep their Markdown formatting. Mermaid flowcharts render quoted labels and ampersands, and unsupported diagrams explain why they fall back to source.

The v0.159.0 New Features:

  • Opt-in instant_interrupt, letting new input steer Codex during model responses or long-running code-mode calls
  • A compact welcome screen for new sessions, with consistent headers
  • The warnings viewer dismisses reviewed warnings when closed; press k to keep one
  • You can scroll the transcript while deciding whether to implement a plan
  • Native Mermaid rendering covers more flowchart edges, labels and node groups

instant_interrupt also was not in the configuration reference as of September 30, 2026, so where it goes and what value it takes are unconfirmed. For the file's structure generally, see Configuring Codex with config.toml.

v0.159.2 is a Windows-only patch with a single fix: console windows no longer flash when Codex launches background processes and sandboxed commands.

Summary

  • v0.158.0 turns on terminal input approval by default for commands running with elevated permissions
  • Codex can now reach MCP servers that require pre-registered OAuth client secrets (codex mcp add --oauth-client-secret)
  • Sandbox fixes land on Windows, Linux and macOS; Linux nested writable roots start correctly from v0.158.0
  • v0.159.0 adds opt-in instant_interrupt and TUI work; v0.159.2 is the Windows console-window fix alone
  • --oauth-client-secret and instant_interrupt were both absent from the configuration reference on September 30, 2026

FAQ

What is the biggest change in v0.158?
Terminal input approval is enabled by default for commands running with elevated permissions. The release notes add that runtime-only grants no longer cause unnecessary reviews.
How do I pass an MCP server's OAuth client secret?
The release notes name codex mcp add --oauth-client-secret. That flag is not in the official configuration reference as of September 30, 2026.
Where does instant_interrupt go in config.toml?
The v0.159.0 release notes describe it as opt-in, but the key does not appear in the configuration reference as of September 30, 2026, so its location and value format could not be confirmed.
Is v0.159.2 worth taking?
On Windows, yes. It contains one fix: console windows no longer flash when Codex launches background processes and sandboxed commands.

Primary sources

This article was drafted by AI from official documentation and reviewed by the site operator before publishing. Found a mistake? Let us know via the contact page.