{"slug": "codex-cli-v0-158-mcp-oauth-client-secrets-and-approval-for-elevated-commands", "title": "Codex CLI v0.158: MCP OAuth client secrets and approval for elevated commands", "summary": "OpenAI shipped Codex CLI v0.158.0, which enables terminal input approval by default for commands running with elevated permissions and adds support for connecting to MCP servers that require pre-registered OAuth client secrets via the `codex mcp add --oauth-client-secret` flag. The release also fixes sandbox issues on Windows, Linux and macOS, including nested writable roots on Linux and Git metadata protections across writable roots, and secures direct exec-server WebSocket connections with bearer tokens. The `--oauth-client-secret` flag was not yet documented in the official configuration reference as of September 30, 2026, and v0.159.0 followed by protecting `.aws` directories by default under writable roots.", "body_md": "*Originally published at [https://aicoding-guide.com](https://aicoding-guide.com/en/posts/codex-update-0-158/).*\n\nCodex CLI v0.158.0 lands changes that touch MCP, the sandbox and approvals — the parts you notice in daily use.\n\nTwo items matter most: **terminal input approval is now on by default for commands running with elevated permissions**, and **Codex can now connect to MCP servers that require pre-registered OAuth client secrets**.\n\nThis article works from the v0.158.0 release notes as the primary source, covering what affects your configuration, and then what followed in v0.159.0 and v0.159.2.\n\n**Key point**\n\nWhat you will learn\n\n- Approval becoming the default for elevated commands\n- MCP OAuth client secret support, and where the configuration reference has not caught up\n- The sandbox fixes on Windows, Linux and macOS\n\nFrom the v0.158.0 New Features:\n\nTerminal input approval is enabled by default for commands running with elevated permissions; runtime-only grants no longer cause unnecessary reviews.\n\nIf you run commands with administrator or otherwise elevated permissions, expect an approval where there was none before. In the other direction, grants given only for the duration of a run should stop triggering repeat reviews.\n\nTwo related fixes ship alongside it:\n\nFor how approval policies and the sandbox combine, see [Codex approval modes and sandbox](https://aicoding-guide.com/en/posts/codex-approval-sandbox/).\n\nFrom the New Features:\n\nConnect to MCP servers that require pre-registered OAuth client secrets, including through `codex mcp add --oauth-client-secret`.\n\nServers that do not support Dynamic Client Registration make you register an OAuth app in their developer portal and take a client ID and secret back. Until now there was no way to hand Codex that secret, so those servers were out of reach.\n\n**This flag is not in the configuration reference yet**\n\n`--oauth-client-secret` appears in the v0.158.0 release notes, but **it was not in the official configuration reference as of September 30, 2026**. The OAuth keys that page does document for an MCP server are `oauth.client_id`, `oauth.callback_port` and `oauth.callback_url`, and it says nothing about where a client secret is stored. Treat the flag name and behavior as a release-note claim.\n\nWhat the reference does document today stops at the client ID and the callback:\n\n```\n[mcp_servers.example]\nurl = \"https://mcp.example.com/mcp\"\n\n[mcp_servers.example.oauth]\nclient_id = \"your-client-id\"\ncallback_port = 8080\n```\n\nThe same release also secures direct exec-server WebSocket connections with bearer tokens, including connections configured through app-server.\n\nThree of the Bug Fixes concern the sandbox, split across platforms.\n\n| Platform | What the release notes say | \n|---|---|\n| Windows | Sandbox failures involving ordinary Windows 10 paths, rejected stored credentials, and large permission policies | \n| Linux | Sandbox startup with nested writable roots | \n| Linux and macOS | Git metadata protections preserved across writable roots | \n| macOS | Patch operations now recognize system path aliases covered by existing permissions, avoiding unnecessary approval prompts | \n\nIf you configure several writable roots, a nested arrangement failed to start on Linux before this release. Configuration is covered in [Extending where Codex can write with writable_roots](https://aicoding-guide.com/en/posts/codex-writable-roots/).\n\nv0.159.0 widens the protection further: `.aws` directories are \"protected by default under writable roots\". That said, **which directories are protected by default inside a writable root could not be confirmed on the official sandboxing page** — read it as a release-note claim.\n\nv0.158.0 makes copy-on-select and right-click paste configurable in the fullscreen TUI, and copied transcript selections keep their Markdown formatting. Mermaid flowcharts render quoted labels and ampersands, and unsupported diagrams explain why they fall back to source.\n\nThe v0.159.0 New Features:\n\n`instant_interrupt`, letting new input steer Codex during model responses or long-running code-mode calls`k` to keep one\n`instant_interrupt` also **was not in the configuration reference as of September 30, 2026**, so where it goes and what value it takes are unconfirmed. For the file's structure generally, see [Configuring Codex with config.toml](https://aicoding-guide.com/en/posts/codex-config-toml/).\n\nv0.159.2 is a Windows-only patch with a single fix: console windows no longer flash when Codex launches background processes and sandboxed commands.\n\n`codex mcp add --oauth-client-secret`)`--oauth-client-secret` and", "url": "https://wpnews.pro/news/codex-cli-v0-158-mcp-oauth-client-secrets-and-approval-for-elevated-commands", "canonical_source": "https://dev.to/aicoding-guide/codex-cli-v0158-mcp-oauth-client-secrets-and-approval-for-elevated-commands-52o7", "published_at": "2026-09-30 19:10:03+00:00", "updated_at": "2026-09-30 19:16:58.587693+00:00", "lang": "en", "topics": ["ai-agents", "developer-tools", "agent-protocols", "ai-tools"], "entities": ["OpenAI", "Codex CLI", "MCP"], "also_reported_by": [], "alternates": {"html": "https://wpnews.pro/news/codex-cli-v0-158-mcp-oauth-client-secrets-and-approval-for-elevated-commands", "markdown": "https://wpnews.pro/news/codex-cli-v0-158-mcp-oauth-client-secrets-and-approval-for-elevated-commands.md", "text": "https://wpnews.pro/news/codex-cli-v0-158-mcp-oauth-client-secrets-and-approval-for-elevated-commands.txt", "jsonld": "https://wpnews.pro/news/codex-cli-v0-158-mcp-oauth-client-secrets-and-approval-for-elevated-commands.jsonld"}}