Codex CLI
Launch Codex CLI with Tokamak routing while preserving your native home and sessions
Complete Install and connect, using tokamak-stag in place of tokamak on staging. Authenticate, then run:
tokamak launch codex --model <catalog-id>Tokamak installs @openai/codex if missing. It supplies a custom Responses provider through per-run -c overrides, preserving your real HOME and CODEX_HOME, config.toml, auth.json, sessions, MCP servers, approvals and instructions. A missing namespaced Tokamak skill can be installed; edited skills and global AGENTS.md are preserved. Use --no-install-skills to skip that step.
The provider uses Tokamak's /v1 API, wire_api=responses, and env_key=TOKAMAK_API_KEY. The key stays in the child environment, not the command line or a generated provider file, and Codex's shell_environment_policy keeps it (and the telemetry headers) out of the commands Codex runs for you; your own exclusions are kept. The selected model must support Responses and the features your task needs. Native explicit model/provider overrides retain their own precedence.
The launcher was last reviewed against Codex 0.160.0 and supports 0.150.0 or newer. A launch warns below that, notes a newer release, and never blocks; --check prints the reviewed version without running Codex.
Models and native options
tokamak launch codex --model # Interactive catalog picker
tokamak launch codex --model <catalog-id>Use Codex's own supported arguments after --; for resuming a session, use the native resume command:
tokamak launch codex -- resumeWithout a saved or explicit Tokamak model, an interactive launch asks you to pick one from the catalog and saves it. Codex's own default model is an OpenAI id Tokamak does not list. Without a terminal, the launch warns and Codex keeps its own selection. Codex's background memory roles use the launch model. --model-selection is a Claude-only option and is rejected here.
Metering and client activity
Inference uses the authenticated Tokamak API and server usage metering. Codex OTLP logs and metrics use separate authenticated per-user endpoints (the trace exporter is off); prompt text is exported only when your organization turned on Insights prompt summaries, and the launch says so. Codex's optional export of its final answers and reviewer text stays off regardless of your own Codex settings. Missing telemetry identity disables exporters. Client activity is supplemental and never another token charge. The Tools tab shows attribution and coverage.
tokamak launch codex --check is an offline configuration inspection. It does not call the server, install a client, write settings or run Codex. tokamak status performs live reachability checks; tokamak usage reads recorded usage.
Codex App is a separate launcher with persistent configuration and offline restore. See the Codex App guide and Troubleshooting agents. Hosted/cloud features retain the client's account requirements. Configuration tests do not certify live compatibility. The recorded Windows run (Codex 0.153.4, September 2026) reached Responses but encountered an output-bound refusal; inspect the actual response and server usage after your first request. From Codex 0.158, a retryable error that carries Retry-After makes Codex wait that long before each retry, so a temporary refusal can hold a turn for tens of seconds.