Codex CLI 0.158.0 Tightens Terminal and MCP Control
Codex CLI 0.158.0 updates elevated-command approvals, MCP and WebSocket authentication, fullscreen terminal controls, image workflows and sandbox reliability.
Codex CLI 0.158.0 changes how elevated terminal commands are approved, how MCP and exec-server connections authenticate, and how images and transcripts behave in the terminal. Released September 28, 2026, it enables terminal input approval by default for elevated commands, adds pre-registered MCP OAuth client-secret support and bearer-token protection for direct exec-server WebSockets. It also introduces transparent-background image requests, file-backed conversation images and a set of TUI and sandbox fixes. Install the exact version with npm install -g @openai/codex@0.158.0. Read the official ChatGPT and Codex changelog.
Codex CLI 0.158.0 permissions and authentication
The highest-impact change is the new default for commands running with elevated permissions. Terminal input approval is now enabled for those commands, so interactive input receives an approval boundary without requiring a separate opt-in. The release also stops runtime-only grants from triggering reviews that are not needed. Together, those changes make the boundary more specific: elevated terminal input is reviewed by default, while a temporary grant should not create unrelated review friction.
MCP setup gains a separate authentication path. Codex can now connect to MCP servers that require a pre-registered OAuth client secret, including through codex mcp add --oauth-client-secret. This is useful when an MCP provider requires a confidential client registration instead of a public-client flow. The release confirms that the secret can be supplied for this connection type; it does not publish a universal configuration for every MCP server.
Direct exec-server WebSocket connections can now use bearer tokens, including connections configured through app-server. That adds an authentication option at the connection boundary. The changelog does not say that every WebSocket connection is automatically authenticated after installation, so existing app-server and exec-server configurations should be checked for whether a token is configured and expected on both sides.
Fullscreen TUI copying, pasting and output
The fullscreen TUI now lets users configure copy-on-select and right-click paste. Transcript selections preserve Markdown formatting, which matters when moving structured output into an issue, review note or documentation file. A copied response can retain headings, lists, links and code-oriented formatting instead of becoming an undifferentiated text block.
Command completion is more informative for clients as well. Completion events can include output produced early in the command lifecycle and can report failures that occur while launching a process. Integrations that listen for completion events can therefore receive evidence that previously might have disappeared before normal command output began. This does not mean every failed command is retried; it means clients get a clearer terminal event when process startup itself fails.
The previous Codex CLI 0.157.0 release focused on GPT-6 Sol and Luna support, Bedrock routes, background sessions, imports and transcript controls. Version 0.158.0 is a distinct follow-up centered on approval behavior, authenticated connections, image handling and reliability. It does not reannounce the 0.157 model or provider changes.
Transparent images and clearer Mermaid rendering
Image generation and editing can now explicitly request a transparent background. That gives workflows producing overlays, icons, cutouts and composited assets a direct background-control option rather than requiring a later removal step. Image edits also accept file-backed images already present in the conversation, allowing an existing conversation asset to serve as the edit input without first converting it into a different transport form.
The release does not define a new image model, image price or plan entitlement. It adds request and input capabilities to the Codex workflow. Verify that a requested transparent image retains the expected alpha channel and that an edit uses the intended file-backed conversation image.
Mermaid flowcharts receive two rendering fixes: quoted labels and ampersands now render, and unsupported diagrams explain why Codex falls back to displaying source. That makes failures easier to distinguish. A diagram that falls back with an explanation is different from a supported flowchart being silently misread. Test a small flowchart containing both a quoted label and an ampersand before moving a larger diagram-heavy workflow to the new version.
For teams preparing user-visible artifacts, the site’s frontend release check provides a compact way to separate source inspection from runtime evidence. It can frame the image, Markdown and Mermaid checks, while the Codex changelog remains the authority for what version 0.158.0 changed.
Sandbox fixes across Windows, Linux and macOS
The sandbox fixes address different failure modes on each desktop platform. On Windows, 0.158.0 corrects failures involving ordinary Windows 10 paths, rejected stored credentials and large permission policies.
On Linux, nested writable roots no longer prevent sandbox startup. The release also preserves Git metadata protections across writable roots on Linux and macOS. That combination matters for repositories whose allowed write locations are nested or spread across more than one root: the sandbox can start while the protected Git metadata boundary remains in force.
On macOS, patch operations now recognize system path aliases already covered by existing permissions. The expected result is fewer unnecessary approval prompts when the alias resolves to a path the current permission set already allows. This is not a blanket expansion of filesystem access; it is recognition of an existing permission through the operating system’s path alias.
Approval handling also recovers when new user input arrives. A status question sent while an action is awaiting review no longer automatically ends that pending action; the review can retry. This is especially relevant in long terminal sessions where the user checks progress before responding to an approval.
What to test after upgrading
Start by confirming codex --version reports 0.158.0. Then select checks that match the active workflow: exercise an elevated command that requests terminal input, reconnect one MCP server that uses a registered OAuth secret, and verify a token-protected exec-server WebSocket if that architecture is in use. Avoid creating synthetic infrastructure solely to cover features the team does not use.
For terminal behavior, copy a Markdown-rich transcript selection and test the chosen right-click action. For visual work, request one transparent image, edit one file-backed conversation image and render a Mermaid flowchart with quoted text and an ampersand. On the relevant operating system, reproduce the path, credential, nested-root or alias case that previously failed. Finally, trigger a harmless process-launch failure and confirm the client receives the early output or launch error through its completion event.
The access guide can help separate installation and sign-in checks from model availability questions. Codex CLI 0.158.0 does not announce a new model, price, subscription tier or broader regional rollout. Its value is operational: tighter approval defaults, explicit authentication options, more capable image inputs and fewer interruptions in terminal, diagram and sandbox workflows.