Codex CLI v0.161.0: /mcp login, Daybreak opt-in gating#
Published by Alex Sorokoletov
Part of the Codex CLI Version Tracker series. | Codex on GitHub | Official Changelog
Codex CLI v0.161.0 follows v0.160.0 and adds a /mcp login <name> command for signing into MCP servers from a running session, puts the Daybreak interface behind an opt-in cli_daybreak flag, and ships a round of sandbox, permission, and session-recovery fixes.[1]
What's New#
| Change | What It Does |
|---|---|
/mcp login <name> | Signs in to a configured MCP server from an active terminal session. Enterprise MCP sign-in adds account-scoped grant cleanup and fails closed on a config refresh.[1] |
cli_daybreak feature flag | Gates the Daybreak interface. It is enabled through --enable cli_daybreak or features.cli_daybreak=true; daybreak=true alone no longer turns it on. With the flag off, controls and indicators are hidden, /daybreak is unavailable, and automatic Cyber routing is omitted even for saved Daybreak threads.[1] |
codex exec --cyber-access-program | Selects a Cyber access program for a single turn, also exposed as the TypeScript SDK's cyberAccessProgram option. The explicit exec override works with cli_daybreak disabled and leaves the saved choice unchanged.[1] |
| Microphone input channels for voice | Choose the microphone, speaker, and microphone input channels for voice conversations, with the preferences saved locally.[1] |
None of the new configuration keys in this release are user-facing environment variables; the additions sit in config.toml and the exec command line.
MCP sign-in from the session#
The headline for day-to-day use is /mcp login <name>, which signs in to a configured MCP server from an active terminal session. On the enterprise path, MCP authentication is restricted and fails closed on a config refresh, and account-scoped grants are cleaned up when they no longer apply.[1]
Daybreak and the Cyber access program are the other moving pieces. Daybreak now stays dark unless cli_daybreak is set, and the per-turn codex exec --cyber-access-program flag (with its SDK equivalent) lets a single run pick an access program without changing the saved preference. The release notes state that opt-in routing also requires an eligible ChatGPT sign-in, the OpenAI provider, and advertised model or program support.[1]
GPT-6.1 Sol becomes the default model in the bundled and Amazon Bedrock catalogs, so a fresh session runs on it without configuration (#49318, #49339).[1]
Reliability and sandbox fixes#
The bug-fix list is where upgraders from v0.160.0 get the most. Approved filesystem escalation can grant broader write access while keeping denied reads and network restrictions intact, and background tasks keep the permissions of the turn that started them. Explicit launch permissions survive terminal reconnects and new sessions, and implicit client settings no longer overwrite server or saved-thread web-search settings.[1]
On Windows, elevated terminal sessions can start through an embedded server, and sandboxed PowerShell keeps relative paths under protected user profiles. In the input path, Enter submits buffered input correctly once paste detection expires, including in Vim insert mode. Thread resume now includes the latest committed history, startup detects recoverable SQLite corruption earlier and preserves the damaged database as a backup, and Responses retries plus the WebSocket-to-HTTP fallback honor server retry guidance to reduce premature failures during overload.[1]
What This Tells Us#
The interactive MCP sign-in and the enterprise-auth hardening point at managed deployments. Fail-closed behavior on config refresh and account-scoped grant cleanup are the kind of controls that matter when MCP servers sit behind an organization's identity rather than a local token file, and the authentication guidance in this release already accounts for keyring storage instead of assuming credentials live in auth.json. Claude Code and Gemini CLI both carry MCP support; adding in-session sign-in and enterprise grant handling pushes Codex further toward the team deployment the registry-managed harnesses are competing over.
The sandbox and permission work continues along the same lines as recent Codex releases: broader-but-bounded filesystem escalation, inherited permissions for background tasks, and Windows sandbox fixes for elevated terminals and PowerShell. A coding agent that executes commands lives or dies on how predictable its sandbox is, and this release tightens several edges of it at once.
Daybreak and the Cyber access program read as staged rollout. Putting the interface behind cli_daybreak and keeping the controls, the /daybreak command, and automatic routing hidden until the flag is set is the standard shape of a feature that ships ahead of general availability. The per-turn exec override gives automated runs a way to opt a single turn in without flipping the global flag.
All trademarks and software referenced belong to their respective owners.
Sources#
- Codex CLI release notes, rust-v0.161.0
Previous Codex CLI analysis: v0.160.0 (October 1, 2026)
All 12 Codex CLI analyses: Codex CLI Version Tracker · Official Codex CLI changelog