Codex CLI v0.158.0: copy-on-select TUI, MCP OAuth secrets, exec-server tokens#

Published by

Part of the Codex CLI Version Tracker series. | Codex on GitHub | Official Changelog

Codex CLI v0.158.0 follows v0.157.1 with configurable copy-on-select and right-click paste in the fullscreen terminal, transcript copies that keep Markdown formatting, MCP servers reachable through pre-registered OAuth client secrets via codex mcp add --oauth-client-secret, and bearer-token authentication for direct exec-server WebSocket connections.[1]

What Shipped#

FeatureWhat It Does
Copy-on-selectConfigurable copy-on-select and right-click paste in the fullscreen TUI. Copied transcript selections preserve Markdown formatting.[1]
MCP OAuth client secretsConnect to MCP servers that require pre-registered OAuth client secrets, including through codex mcp add --oauth-client-secret.[1]
Exec-server bearer tokensSecure direct exec-server WebSocket connections with bearer tokens, including connections configured through app-server.[1]
Image background controlImage generation and editing can explicitly request transparent backgrounds, and edits now accept file-backed conversation images.[1]
Elevated-command approvalTerminal input approval is on by default for commands running with elevated permissions; runtime-only grants no longer trigger reviews.[1]

Process and WebSocket Changes#

WebSocket authentication was pulled into a dedicated codex-websocket-auth component, and direct exec-server WebSocket connections, including those configured through app-server, can now carry opt-in bearer tokens.[2] That is the transport layer between the front-ends and the process that runs commands getting an authentication story of its own.

Process spawning was consolidated too. Pipe processes, Unix shell snapshots, Linux PTY launches, and command hooks now route through a shared child-process launcher.[2] The release adds a reap-only drop policy for child processes and makes Linux descriptor cleanup fork-safe.[2]

Fixes Worth Noting#

  • Windows sandbox failures on ordinary Windows 10 paths, with rejected stored credentials, and under large permission policies.[1]
  • Linux sandbox startup with nested writable roots, plus Git metadata protections preserved across writable roots on Linux and macOS.[1]
  • macOS patch operations now recognize system path aliases already covered by existing permissions, so they stop asking for redundant approvals.[1]
  • Approval reviews retry when new user input arrives, so a status question no longer aborts a pending action.[1]
  • Mermaid flowcharts render quoted labels and ampersands; unsupported diagrams explain why they fall back to source.[1]
  • Command completion events now include early output and report process-launch failures to clients.[1]

What This Tells Us#

v0.158.0 hardens the transport and spawning layers beneath Codex's client/server split. Bearer tokens now guard exec-server WebSocket connections, WebSocket auth lives in its own component, and a shared child-process launcher with a reaper sits under every spawned command. For a tool that runs commands under a user's account across several clients, that connective tissue is what was hardened this cycle.

External connections got the same attention. MCP servers that require pre-registered OAuth client secrets are now reachable, and the Guardian authorization reviewer extended its computer-use review to the Browser connector.[2] The exec-server and app-server split has one background process serve several front-ends, and this cycle it authenticates the link between them.

Multi-agent v2 kept moving alongside the ergonomics work. An option now disables multi-agent v2 direct messaging.[2] That runs next to the terminal polish, copy-on-select and Markdown-preserving copy, that daily users touch first.

Sources#

  1. Codex CLI release notes, rust-v0.158.0
  2. Official Changelog, rust-v0.157.0...rust-v0.158.0

Previous Codex CLI analysis: v0.157.1 (September 26, 2026)

All 7 Codex CLI analyses: Codex CLI Version Tracker · Official Codex CLI changelog