OpenAI Codex CLI: First Task and Team Settings

Install Codex CLI, sign in, complete a useful first task, then set up models, approvals, AGENTS.md, MCP servers and worktrees for your team.

Published

OpenAI Codex CLI: First Task and Team Settings

OpenAI Codex CLI lets you turn a small development task into a patch you can inspect and test without leaving your terminal. Start with one missing test or a narrow bug, then give the team shared instructions and predictable permissions. The payoff is less repetitive repository work and a clearer handoff to the human reviewing the change.

Use the first 15 minutes as a setup timebox, assuming you already have a working project and an account with access. Installation, sign-in or a slow test suite can take longer. A useful first result is a small verified change, or a precise explanation of what blocks it. Commands checked on October 11, 2026.

Install Codex CLI and Finish One Useful Task

Codex works inside your project: it can inspect files, edit them and run tools installed on your machine. Think of it as a contributor at a separate workbench. You supply the task and boundaries; you still decide whether the result belongs in the product. OpenAI’s CLI guide

Minutes 0 to 3: Choose One Install Method

On macOS or Linux, the standalone installer is:

Bash
curl -fsSL https://chatgpt.com/codex/install.sh | sh

Use an alternative if it fits your existing setup. Pick one method so you know how to update it later.

Install routeExact command or source
npmnpm install -g @openai/codex
Homebrewbrew install --cask codex
Direct executableDownload your platform’s binary from OpenAI’s Codex releases.

For Windows, the docs provide this exact command to run in a new PowerShell window: powershell -ExecutionPolicy ByPass -c "irm https://chatgpt.com/codex/install.ps1 | iex".

These are the install routes in the current CLI documentation and official repository. Open your project directory in the terminal before starting Codex.

Minutes 3 to 5: Choose ChatGPT Sign-In or an API Key

For a first interactive session, use ChatGPT sign-in if your plan and workspace provide access. Run codex login and complete the browser flow. Starting codex without an existing login also offers Sign in with ChatGPT.

Choose API-key authentication when you intend to use your OpenAI Platform account, such as for programmatic workflows. With OPENAI_API_KEY already supplied in your shell environment, the documented macOS/Linux command is printenv OPENAI_API_KEY | codex login --with-api-key. Keep the key out of repository files.

Run codex login status to confirm which method is active. This matters on a team: ChatGPT authentication follows the ChatGPT workspace’s controls, while API authentication follows the API organization’s controls. Authentication guide

Cost: ChatGPT sign-in uses the access included with your eligible plan; API-key usage is billed separately through OpenAI Platform at API rates. Use our Codex pricing guide for the plan comparison. For a team trial, measure manual task time against prompting, review and correction time, then subtract incremental usage cost from the value of the time actually saved. A faster first draft only pays when the total work to accept it falls. OpenAI authentication and billing distinction

Minutes 5 to 8: Inspect Before Editing

Create a Git checkpoint first. From your project’s shell prompt, start an inspection session with the documented command codex --sandbox read-only --ask-for-approval on-request.

Give it a bounded investigation. For example, adapt this suggested prompt to your project:

Find the request-validation code and its tests. Explain one existing validation rule that lacks a focused test. Identify the files and the repository’s test command. Do not edit anything yet.

This prompt is a workflow suggestion, not a special Codex command. Read the answer and confirm that it has found the right part of the application. The read-only sandbox allows inspection and commands within its boundary; actions outside that boundary can require approval. Approval and sandbox guide

Minutes 8 to 12: Authorize One Small Change

Use /permissions to switch to workspace editing when you are ready. For a new session, the documented combination is codex --sandbox workspace-write --ask-for-approval on-request.

Then give an acceptance condition:

Add one focused test for that existing rule using the project’s current test framework. Run the relevant test command. Do not change production code or add dependencies. Report the diff and the test result, including any command you could not run.

Start with something you can judge quickly. A test of known behavior is a better first assignment than an open-ended request to improve the architecture.

Minutes 12 to 15: Review the Diff and Evidence

Use /diff to inspect the patch and /review to request a review. Check the actual test output, the files touched and whether the change meets your acceptance condition. Commit only after your own review. Those slash commands belong inside the Codex session, not at your shell prompt. CLI command reference

Four architectural workstations form a loop: Inspect, Change, Test and Review.
Keep the first assignment small enough to complete the entire inspection, change, test and review loop.

Choose the Model After You Have a Baseline

Start with the model available in your session, then use /model to choose another model or adjust reasoning effort. OpenAI’s current launch example is codex --model gpt-6.1-sol.

The current recommendation is GPT-6.1 Sol for complex coding when your account and client have access, and GPT-6 Luna for focused, repeatable tasks. More reasoning can help difficult analysis, but also takes longer and uses more tokens. Keep the initial task and effort setting consistent when comparing results. Codex model guidance

For team onboarding, record the model used alongside the task and test outcome. Selecting a model name does not give an account access to it.

Set Sandbox Access and Approvals Separately

The sandbox defines what commands can access. The approval policy defines when Codex must ask before acting. Think of the sandbox as the workroom walls and the approval policy as the permission to open a door.

Sandbox modeWhat it means for your workflow
read-onlyInspect accessible files and run commands within a read-only boundary. Use it for orientation and analysis.
workspace-writeAllow work in the active workspace. Command network access is off by default; protected paths can still require approval.
danger-full-accessRemove the sandbox restriction. This is not a sensible starting point for an ordinary developer laptop.

Use on-request for interactive work: actions allowed inside the sandbox can proceed, while actions needing broader access can prompt. never means Codex cannot ask for approval; it does not remove the sandbox. A blocked action can remain blocked.

A write boundary is not a promise to prompt before every edit. With workspace-write and on-request, Codex can change workspace files and run permitted commands automatically. Inspect the active settings with /permissions. OpenAI’s sandbox and approval behavior

Two workshop bays distinguish Sandbox, the access boundary, from Approvals, when to ask or continue.
Configure both controls: where commands may operate and when an action needs approval.

If an old team template sets approval_policy = "untrusted", update it: OpenAI has retired that explicit setting and says it can prevent startup. The older codex exec --full-auto path is also deprecated. Use the documented sandbox and approval settings instead. Current migration guidance

Put Working Agreements in AGENTS.md

Use AGENTS.md to stop repeating how your repository works. Codex reads these instructions when a run starts. /init can generate a scaffold, which a maintainer should edit before the team relies on it.

A useful repository file answers four questions:

  • How do developers install dependencies and run the project?
  • Which tests and checks apply to a change?
  • Which directories contain generated files or require special care?
  • What should a completion report include, such as changed behavior, tests run and unresolved failures?

Write your real commands and conventions, not a generic wish list. Keep personal preferences in ~/.codex/AGENTS.md; commit shared repository guidance at the project root.

Codex loads global guidance and then walks from the project root toward the current directory. More local instructions take precedence over earlier guidance; AGENTS.override.md wins over AGENTS.md in the same directory. Restart the session after changing instructions, and ask Codex to summarize the guidance it loaded. AGENTS.md discovery rules

Treat this file as a contributor handbook. Use configuration and managed requirements for technical restrictions.

Keep config.toml Small and Reviewable

Store personal defaults in ~/.codex/config.toml. Put shared project defaults in .codex/config.toml, which Codex loads only for trusted projects. These settings use TOML, a text format for named settings.

This starter combines the values shown in OpenAI’s configuration guide. Use the model line only when that model is available to your account:

TOML
model = "gpt-6.1-sol"
model_reasoning_effort = "medium"
approval_policy = "on-request"
sandbox_mode = "workspace-write"
web_search = "cached"

The CLI’s flags and --config overrides take precedence over project configuration. Trusted project settings take precedence over selected profiles and your user defaults. Organization requirements can constrain what is allowed regardless of those defaults. Configuration basics

web_search = "cached" selects cached web-search results. It is separate from network access for shell commands. A dependency download can need approval even when Codex has a web-search tool. Keep that distinction in the onboarding notes instead of loosening permissions whenever a command fails.

Add an MCP Server Only for a Concrete Need

MCP, or Model Context Protocol, connects Codex to tools and external context. A local server runs as a process; a remote server is reached through an HTTP address. Add one when a task needs information or an action your repository cannot provide.

OpenAI’s documentation example is codex mcp add context7 -- npx -y @upstash/context7-mcp. This starts a documentation server through npx, so that launcher must be available. Run codex mcp list to see configured servers, then /mcp inside a session to inspect active connections. For an OAuth-capable server, use codex mcp login <server-name>, replacing the placeholder with its configured name.

Server configuration belongs under [mcp_servers.<server-name>] in the same TOML configuration system. A team can restrict exposed tools with enabled_tools and disabled_tools; the deny list is applied after the allow list. Start with the smallest useful tool set. MCP setup and settings

For the separate issue of large tool responses, read our Codex CLI MCP output-limits explainer. Connecting a server and controlling how much output it returns are different setup decisions.

Use Worktrees When Tasks Need Separate Checkouts

A Git worktree gives a task a separate checkout of the repository. It is useful when you want to keep an experiment’s edits apart from the files you are actively working on.

OpenAI’s 0.154.0 release added managed worktrees for CLI tasks, interactive sessions and forks. The implementation gates them behind the experimental worktrees feature and restricts them to local sessions. Enable that named feature with codex features enable worktrees, using the CLI’s documented feature-enable command, then start with codex --worktree. Release notes, interactive worktree implementation, feature commands

Inside a supported session, /worktree offers a fresh conversation or a fork into a managed checkout. A fork carries conversation history; a new conversation starts fresh. These options require an enabled feature and a local Git repository. Worktree session commands

Plan to review, integrate and clean up the work yourself. The CLI implementation leaves automatic cleanup disabled for its managed allocations. A separate checkout also does not replace sandbox settings or merge review. Managed checkout lifecycle

Use our Codex CLI worktree guide when you are ready for parallel tasks. For a first test-writing assignment, a single checkout is enough.

Six Useful Tasks, Ranked for a Small Team

These are suggested assignments, not measured productivity claims. Start where the acceptance condition is easiest to check.

Priority and readerBounded assignmentWhy it can pay
1. Maintainer with a reproducible bugSupply the failing case; request the smallest fix and a regression test.Connects implementation directly to an observable failure.
2. Founder protecting an important workflowAdd missing tests around known validation or business rules.Turns undocumented expectations into repeatable checks.
3. Developer joining an unfamiliar serviceTrace one request from entry point to storage and identify relevant tests.Reduces the amount of code to read before contributing.
4. Engineer preparing a pull requestRun /review, then verify each finding against the diff.Can surface issues before another teammate spends review time.
5. Team changing an internal interfaceUpdate a bounded set of call sites and run the affected tests.Makes repetitive edits easier to audit as one coherent change.
6. Maintainer correcting stale documentationCompare one documented workflow with its implementation and propose corrections.Can reduce repeated onboarding questions.

Codex does not supply missing product decisions or prove that a passing test suite covers every risk. Your acceptance criteria and review remain part of the job. For broader evaluation, use our Codex review; for a purchasing comparison, see Codex vs Claude Code.

Two Focused Tools a Technical Founder Could Build

The stronger opportunity is a regression-test service for one stack. Sell a reviewed test patch to small teams with known bugs and weak coverage. The smallest useful version takes a reproducible case, runs a bounded Codex task in a separate checkout and returns the patch plus test evidence. DataForSEO’s US keyword estimate retrieved on October 11, 2026 is 880 monthly searches for “automated software testing services.” That measures interest in the job, not willingness to buy this product. The hard part is reliable fixtures and meaningful assertions; a test that merely repeats the implementation adds little value.

A repository-specific review assistant is the second option. An engineering lead could pay for reviews that apply the team’s documented conventions and return a short, verifiable findings list. Start with one repository, its AGENTS.md and a repeatable review run. The same demand check estimates 1,300 US monthly searches for “ai code review.” The catch is differentiation: Codex already reviews code, so the product must improve relevance and reduce false alarms. Test generation has the clearer initial deliverable because the buyer can inspect and run what you return.

Questions That Come Up During Setup

How do I update Codex CLI after installing it?

Use the same installation route. The standalone installer and npm route repeat their install commands; Homebrew uses brew upgrade --cask codex. OpenAI lists the exact update command beside each installation method in its CLI guide.

What if the ChatGPT login browser flow does not work?

Check your current state with codex login status. The CLI also documents codex login --device-auth for a device-code sign-in flow. Follow the displayed instructions and your workspace’s access requirements. Login options

Which commands go in the shell and which go inside Codex?

Commands beginning with codex, such as codex login and codex mcp list, run in your shell. Slash commands such as /model, /permissions, /diff and /review run in the interactive Codex session. Command reference

Can I use Codex CLI from VS Code?

You can use the CLI from a terminal opened to your project, including your editor’s integrated terminal. The Codex IDE extension is a separate interface. OpenAI’s repository distinguishes the terminal CLI from the editor extension; choose the interface that fits your workflow. Official Codex repository

On Monday, have one maintainer run the same small task with two teammates, record the review and correction effort, and fix the shared instructions where the handoff breaks. Expand only after the team can repeat that loop confidently.

If you want a repository workflow built around these controls, we build AI production systems.

Published
Category
Build
Related Articles
Claude Code Best Practices

Claude Code Best Practices

Claude Code habits in adoption order: verification, planning, CLAUDE.md, context, costs, permissions, hooks, subagents, and worktrees.Oct 11, 2026Build
Codex Plugin

Codex Plugin

Install a Codex plugin, build a three-file team package, and share it through a repo marketplace with clear authentication and admin controls.Oct 11, 2026Build
CLAUDE.md: Write It Once, Start Every Session Right

CLAUDE.md: Write It Once, Start Every Session Right

Write a useful CLAUDE.md, scope project rules, and manage Claude Code auto memory with a 35-line starter and a monthly cleanup routine.Oct 11, 2026Build
Jev Alternatives in 2026: OpenAI, Microsoft, Clef, d1, Perplexity and Strands (Compared)

Jev Alternatives in 2026: OpenAI, Microsoft, Clef, d1, Perplexity and Strands (Compared)

Compare Jev alternatives by job, maker-verified input pricing, licences and deployment: OpenAI, Microsoft, Clef, Liquid d1, Perplexity and Strands.Oct 11, 2026Build
OpenAI Decisions API

OpenAI Decisions API

Use OpenAI Decisions API for ticket routing, labels, and action gates. Three guide requests, refusal handling, pricing, limits, and when to keep your LLM.Oct 11, 2026Build
Claude Code Remote Control

Claude Code Remote Control

Set up Claude Code Remote Control from CLI, VS Code or Desktop, connect your phone or browser, and fix documented login and connection failures.Oct 9, 2026Build
Cursor Remote Control

Cursor Remote Control

Set up Cursor Remote Control on iPhone, pair your laptop, keep local agents reachable, and compare cloud agents, Claude Code and Codex.Oct 9, 2026Build
Firecrawl Pricing 2026: What Your Pages Cost

Firecrawl Pricing 2026: What Your Pages Cost

Firecrawl plans and credit packs verified October 2026. Calculate JSON extraction, failed pages and weekly crawl bills at your volume.Oct 9, 2026Build
Newsletter

One letter, every Sunday.Working systems, not hot takes.

Weekly. No spam. Unsubscribe anytime.