Large Language ModelsGenerate imagesGenerate videos

Codex MCP for Claude Code: Use Codex as an MCP Server

Codex used to run as an MCP server for Claude Code, but the codex mcp-server command was removed from the CLI. This article shows what broke, which replacements work today, the exact install commands, sandbox settings, and fixes for common errors.

Codex MCP for Claude Code: Use Codex as an MCP Server
Cristian Da Conceicao
Founder of Picasso IA

If you typed codex mcp-server into a terminal and got Error: stdin is not a terminal, your machine is fine. The command is gone. For a while, Codex MCP for Claude Code meant one setup: run Codex as an MCP server, register it with Claude Code, and let one coding agent ask the other for a second opinion. OpenAI has since removed that subcommand, and every tutorial that still shows it leads to a dead end.

This article explains what changed, which replacements work today, and the exact commands for each one. You get the official plugin, a community MCP wrapper, a short-lived stopgap with an older CLI, and the reverse setup where Codex calls Claude Code. Each command comes from OpenAI's documentation, the plugin repository, or the wrapper's README, so you can paste it without guessing.

💡 Short version: install the official Codex plugin for Claude Code. Choose a community MCP wrapper only when you need Codex to show up as real MCP tools.

Why Codex MCP Broke

What the Old Setup Did

Codex CLI used to ship a subcommand, codex mcp-server, that started Codex as a stdio MCP server. Claude Code could launch it like any other server, so a single claude mcp add line turned Codex into a tool. The server exposed two tools:

ToolWhat it didMain inputs
codexStarted a new Codex sessionprompt, approval-policy, sandbox
codex-replyContinued an existing sessionprompt, threadId

The first call returned a threadId. Passing it to codex-reply kept the conversation going, so Claude Code could hand Codex a task, read the answer, then follow up in the same session. The approval-policy field accepted untrusted, on-request or never, and sandbox accepted read-only, workspace-write or danger-full-access.

Hands pushing a braided cord into a brass jack on a vintage wooden switchboard

The old registration looked like the line below. It no longer works on a current CLI:

claude mcp add codex -- codex mcp-server

The Error You See Now

OpenAI's MCP documentation now states that the codex mcp-server command and the standalone codex-mcp-server binary have been removed. On a current CLI, mcp-server is not a recognized subcommand, so the CLI treats the word as a prompt and tries to open its interactive interface. Claude Code launches servers over a pipe with no terminal attached, so the CLI stops with Error: stdin is not a terminal. A bug report in the Quest project traces the failure to exactly this fall-through.

Inside Claude Code the symptom is a server that shows as failed in /mcp, with no tools listed. Nothing in your config is wrong. The thing it points at no longer exists.

Tired developer at a dim desk at night reading a terminal full of error text

When It Was Removed

A migration write-up dates the deprecation notice to Codex CLI 0.149.1, released on August 24, 2026. Bug reports from several projects that depended on the command, including Quest and the second-opinion skill from Trail of Bits, name Codex CLI 0.154.0 as the release where it disappeared. Check what you run:

codex --version

Any version from 0.154.0 onward lacks the subcommand, so no amount of config editing will bring it back.

Overhead view of a paper desk calendar with two circled dates and sticky notes

Three Ways to Reach Codex Today

Pick based on how you want Codex to appear inside Claude Code. The table shows the trade in one glance:

OptionMaintained byAppears asCatch
Codex plugin for Claude CodeOpenAISlash commands such as /codex:reviewNot MCP tools
Community MCP wrapperA third partyMCP tools such as ask-codexUnofficial, wraps codex exec
Older Codex CLIOpenAI, frozenThe original codex and codex-reply toolsNo updates, breaks on upgrade

If your goal is a second opinion on code, the plugin is the shortest path. If you already have prompts, scripts or subagents that call MCP tools by name, the wrapper keeps that shape with the least rewriting.

Aerial view of a gravel trail splitting into three paths across a sunrise meadow

The Official Plugin

OpenAI publishes openai/codex-plugin-cc. It wraps the Codex app server through the codex binary already on your machine, so it reuses your sign-in and your Codex configuration. It needs Node.js 18.18 or later plus a ChatGPT subscription (the Free tier counts) or an OpenAI API token. The trade: you get slash commands and background jobs, not MCP tools.

A Community MCP Wrapper

@cexll/codex-mcp-server keeps the MCP shape. It calls codex exec under the hood and exposes the tools ask-codex, brainstorm, ping and help. It needs Node.js 18 or later and a Codex CLI that is installed and signed in. Because it is third-party code that runs against your repository, read it before you trust it, and expect it to trail Codex CLI changes by days or weeks.

An Older CLI as a Stopgap

You can install a Codex CLI release from before the removal and keep codex mcp-server alive:

npm install -g @openai/codex@<a-version-before-0.154.0>

Confirm the subcommand exists before you wire it in. This only buys time. You freeze out new models and fixes, and the next upgrade breaks the setup again.

💡 Treat the older CLI as a bridge for a week, not as an architecture.

Set Up the Official Plugin

Install the Codex CLI first. The plugin relies on that global binary, and it uses whatever sign-in the binary already holds.

Woman's hands typing on a silver laptop at a marble cafe table beside a latte

Install in Four Commands

From a normal shell, install the CLI:

npm install -g @openai/codex

Then run these inside Claude Code, one at a time:

/plugin marketplace add openai/codex-plugin-cc
/plugin install codex@openai-codex
/reload-plugins
/codex:setup

/codex:setup checks that Codex is installed and authenticated. If it reports a problem, fix that before anything else, because every other command depends on it.

What Each Command Does

The plugin adds a small family of /codex: commands:

CommandUse it for
/codex:reviewA standard, read-only review of your changes
/codex:adversarial-reviewA steerable review that challenges design choices
/codex:rescueHanding a stuck task to Codex through a subagent
/codex:transferCreating a persistent Codex thread from the current session
/codex:statusListing running and recent Codex jobs
/codex:resultShowing the final output of a finished job
/codex:cancelStopping an active background job
/codex:setupVerifying installation and sign-in

A habit that works: after Claude Code finishes a change, run /codex:review to get a second model's opinion before you commit. Reach for /codex:rescue when Claude Code loops on the same bug, and watch /codex:status while the job runs in the background.

Set Up a Community MCP Wrapper

Choose this route when you need real MCP tools. The wrapper sits between Claude Code and the Codex CLI, translating tool calls into codex exec runs.

Macro shot of a white travel plug adapter sitting in a wall socket

Register It With Claude Code

npm install -g @openai/codex
claude mcp add codex-cli -- npx -y @cexll/codex-mcp-server

Then type /mcp inside Claude Code. The server should appear as connected, with its tools listed underneath. claude mcp list shows the same from the shell.

Share It Through .mcp.json

Add --scope project to the claude mcp add command and Claude Code writes the server into .mcp.json at the repository root, so the whole team gets the same setup:

{
  "mcpServers": {
    "codex-cli": {
      "command": "npx",
      "args": ["-y", "@cexll/codex-mcp-server"]
    }
  }
}

Claude Code asks each teammate to approve a project server before it runs, which is the right behavior for a tool that can touch files.

Sandbox and Approval Settings

The wrapper passes Codex's safety controls through, so you decide how much freedom Codex gets. The README lists these options:

SettingOptions
Sandboxread-only, workspace-write, danger-full-access
Approval policynever, on-request, on-failure, untrusted

Scientist behind a clear acrylic safety shield pouring blue liquid into a flask

💡 Start with read-only for reviews and questions. Move to workspace-write only when you want Codex to edit files. Pairing danger-full-access with never removes every brake, so keep that combination out of shared repositories.

The README also notes smart defaults since version 1.2: the wrapper picks workspace-write when a task needs it, to prevent permission errors. Check which mode a run actually used before you assume it stayed read-only.

Run It the Other Way Around

The connection works in both directions. Claude Code can call Codex, and Codex can call Claude Code or any other MCP server you trust.

Wide view of a footbridge at blue hour with two cyclists passing in opposite directions

Codex Calling MCP Servers

Codex consumes MCP servers natively. Add one from the CLI:

codex mcp add my-server -- npx -y your-mcp-server-package

Or write it into config.toml as an [mcp_servers.<name>] table:

[mcp_servers.my-server]
command = "npx"
args = ["-y", "your-mcp-server-package"]
startup_timeout_sec = 20
tool_timeout_sec = 120

Stdio servers also accept env, cwd, enabled_tools and disabled_tools, which lets you hide tools Codex should never call. HTTP servers take a url plus authentication options.

Claude Code as a Server

Claude Code can serve its own tools over MCP with claude mcp serve. Register that command in Codex:

codex mcp add claude-code -- claude mcp serve

Codex then sees Claude Code's tools, such as file reads, edits and shell access, as MCP tools. Try it in a throwaway repository first, because two agents with write access can overwrite each other's edits.

Fix the Usual Failures

Most failures fall into five buckets. Match the symptom, then apply the fix:

SymptomLikely causeFix
Error: stdin is not a terminalThe mcp-server subcommand was removedSwitch to the plugin or the wrapper
Server shows as failed in /mcpCodex CLI missing from PATH or not signed inRun codex --version, sign in, restart Claude Code
/codex: commands missingPlugin not reloadedRun /reload-plugins, then /codex:setup
npx fails on native Windowsnpx is a .cmd shimRegister with cmd /c npx -y @cexll/codex-mcp-server
Server times out on first startnpx downloads the package on the first runInstall it globally, or raise MCP_TIMEOUT

Technician's hands tightening a tiny screw on the open back of a laptop

A 30-second health check catches nearly everything else:

  1. Run codex --version to confirm the CLI is installed and recent.
  2. Run claude mcp list to confirm the server is registered and connected.
  3. Ask Claude Code to call ping (wrapper) or run /codex:setup (plugin).

If all three pass and a task still fails, the problem is the task, not the plumbing. Narrow the prompt, drop the sandbox to read-only, and run it again.

How to Use GPT 5.6 Sol on PicassoIA

When a setup still fails, a strong coding model can read the error with you. GPT 5.6 Sol on PicassoIA is built for coding, technical writing and multi-step reasoning, and it reads images, so a screenshot of the failing terminal works too.

Step by Step

  1. Open the GPT 5.6 Sol page on PicassoIA.
  2. Paste the exact error text, your codex --version output and the command that failed into the prompt field.
  3. Attach a screenshot through the image input when the error runs longer than a few lines.
  4. Add a system prompt such as: "You are a senior engineer who fixes MCP setups. Ask for missing facts before guessing."
  5. Raise reasoning effort to high for tangled issues. The default, none, favors speed.
  6. Increase max completion tokens when you raise the effort. The model's own settings warn that high effort can spend every token on reasoning and return an empty reply.
  7. Set verbosity to low when you only want the fixed command, and high when you want the reasoning spelled out.

Here is how the settings map to this kind of job:

SettingValuesGood for
reasoning_effortnone, low, medium, high, xhighnone for quick lookups, high for config conflicts
verbositylow, medium, highlow when you need only the command
max_completion_tokensIntegerRaise it together with the effort
system_promptTextSetting a role and a rule about guessing
image_inputList of imagesTerminal screenshots and diagrams

To compare answers, run the same prompt on Claude Sonnet 5 or Claude Fable 5, both in the same Large Language Models category. Two models disagreeing about your config is a useful signal to read the docs yourself.

Make Your Own Images on PicassoIA

Setup articles and READMEs read better with real visuals: a header photo, a diagram of how two agents connect, a short clip for a release note. PicassoIA also has its own developer API and MCP connector, so the same Claude Code session can request pictures without leaving the terminal.

The API is Replicate-style: the base URL is https://api.picassoia.com/v1, requests carry a Bearer token that starts with pia_sk_, and jobs are asynchronous, so you create a prediction, poll it, then fetch the result. An account can run 5 concurrent predictions, shared across tokens and MCP connections. Four models are available through the API and the MCP connector:

Check the pricing page for what your plan includes, since API and MCP access depend on it.

Pick one section of this article, write a 50-word photo prompt for it, and generate your first image on Picasso IA. Then feed that image to a video model and turn it into a five-second clip. One afternoon of experiments will show you which model fits your docs, and the prompt you end up with is worth saving for the next article.

Share this article