Codex CLI Commands and Config: A Reference

Every Codex CLI command worth knowing on one page: subcommands, flags, slash commands grouped by job, keyboard shortcuts, the config.toml keys people change most, and how to exit, update and uninstall.

7 min read

Codex CLI has three kinds of command. Subcommands run from your shell: codex opens the terminal UI, codex exec runs a task without it, codex resume picks up an old session and codex review reviews a diff. Slash commands run inside a session: /permissions, /model, /plan, /diff, /review, /status and /quit are the ones you will use every day. And settings that should stick live in ~/.codex/config.toml, where model, approval_policy, sandbox_mode and [mcp_servers.<name>] tables do most of the work. The lists below are one line each, so you can scan for the one you need.

This is a reference, not an install guide. Installing, signing in and writing your first AGENTS.md are in Codex CLI setup, and Windows paths are in Codex CLI on Windows. Everything here comes from OpenAI’s Codex developer commands reference (opens in a new tab), which changes often; codex --help on your own install is the final word.

Subcommands you run from the shell

Sessions
codex                          # open the terminal UI in this folder
codex "explain this repo"      # open it with a first prompt
codex resume                   # pick a saved session from a list
codex resume --last            # reopen the latest session from this folder
codex resume --all             # include sessions from other folders
codex fork --last              # copy the latest session into a new chat
codex archive <SESSION>        # hide a session; codex unarchive brings it back
codex delete <SESSION>         # delete a session permanently
Scripts, CI and review
codex exec "fix the failing test"             # run once, no UI (alias: codex e)
codex exec --json -o last.txt "..."            # JSONL events, final message to a file
echo "prompt" | codex exec -                   # read the prompt from stdin
codex exec resume --last "now add a test"      # continue the last exec run
codex review --uncommitted                     # review staged, unstaged and untracked changes
codex review --base main                       # review against a branch
codex review --commit <SHA>                    # review one commit
Account, tools and upkeep
codex login                    # browser sign-in with ChatGPT
codex login --device-auth      # device code, for machines without a browser
codex login status             # exits 0 when signed in
codex logout                   # remove stored credentials
codex mcp add <name> --url <https-url>   # add a remote MCP server
codex mcp list                 # also: get, remove, login, logout
codex features                 # list feature flags
codex doctor                   # diagnostic report: install, config, auth, Git
codex completion zsh           # shell completions (bash, zsh, fish, powershell)
codex update                   # self-update, where the release supports it
codex app                      # open the ChatGPT desktop app’s Codex view

Two more belong to Codex cloud: codex cloud browses and starts cloud tasks (OpenAI now calls them cloud chats) from the terminal, and codex apply <TASK_ID> applies a cloud task’s diff to your working tree. Both are covered in Codex cloud.

Flags that work on most commands

  • -m, --model — use a different model for this run.
  • -s, --sandbox — read-only, workspace-write or danger-full-access.
  • -a, --ask-for-approval — on-request or never.
  • -C, --cd — start in another folder.
  • --add-dir — give write access to one more folder; repeat for several.
  • -c key=value — override any config.toml key for one run.
  • -p, --profile — layer a named profile file over your config.
  • -i, --image — attach images to the first prompt.
  • --search — live web search instead of the cached default.
  • --yolo — no sandbox and no approvals. The reference says to use it only inside an externally hardened environment.

Slash commands, grouped by job

Chats and sessions

  • /new — a fresh chat in the same session.
  • /clear — clear the screen and start a fresh chat.
  • /resume — reopen a saved chat.
  • /fork — copy this chat so you can try another approach.
  • /side — a throwaway side chat that leaves the main one untouched.
  • /rename — name the chat so you can find it later.
  • /compact — summarise the chat so far to free context.
  • /archive and /delete — archive, or permanently delete, this session and exit.

Model, permissions and planning

  • /model — choose the model and, where offered, reasoning effort.
  • /permissions — change what Codex may do without asking.
  • /plan — plan mode, so Codex proposes steps before it edits.
  • /goal — set a goal Codex keeps working towards.
  • /status — model, approval policy, writable folders and context left.
  • /debug-config — which config layer set which value.

Context and review

  • /init — write a starter AGENTS.md in this folder.
  • /mention <path> — add a file to the chat.
  • /diff — the Git diff, including untracked files.
  • /review — ask Codex to review the working tree.
  • /copy — copy the latest finished answer.

Tools and extensions

  • /mcp — list connected MCP servers and tools; /mcp verbose adds diagnostics.
  • /apps, /plugins and /skills — browse and insert them.
  • /hooks — inspect and trust lifecycle hooks.
  • /agent — switch between subagent threads.
  • /ps and /stop — see or stop background terminals.

Leaving

  • /quit or /exit — end the session.
  • /logout — sign out on a shared machine.
  • /app — carry this chat into the desktop app.

Keyboard shortcuts in the terminal UI

  • @ — search for a file and add its path to the prompt.
  • ! at the start of a line — run a shell command under the current sandbox.
  • Tab while Codex works — queue a follow-up for the next turn.
  • Enter while Codex works — add instructions to the current turn.
  • Esc twice on an empty composer — edit your previous message and fork from there.
  • Up and Down — draft history. Ctrl+R — search prompt history.
  • Ctrl+O — copy the latest output. Ctrl+L — clear the screen, keep the chat.
  • Shift+Tab — toggle plan mode.
  • Ctrl+C — close the session.

/keymap remaps these, and the choices are saved under [tui.keymap] in config.toml.

The config.toml keys that matter

Your defaults live in ~/.codex/config.toml. A project can add its own .codex/config.toml, which loads only when you trust the project. According to OpenAI’s config basics (opens in a new tab), the CLI and the IDE extension share these layers, and flags and -c overrides beat project files, which beat profiles, which beat your user file.

~/.codex/config.toml
model = "gpt-6-sol"
model_reasoning_effort = "medium"
approval_policy = "on-request"      # or "never"
sandbox_mode = "workspace-write"    # or "read-only", "danger-full-access"
web_search = "cached"               # "live", "indexed" or "disabled"
review_model = "gpt-6-sol"          # model used by /review

[mcp_servers.fenbs]
url = "https://fenbs.ai/api/mcp"
  • approval_policy — on-request for interactive work, never for unattended runs. untrusted is no longer supported and on-failure is deprecated.
  • sandbox_mode — what commands may touch. workspace-write keeps .git and .codex read-only inside the writable folder.
  • [mcp_servers.<name>] — one table per server: url for remote, command and args for local, plus enabled_tools and timeouts.
  • project_doc_max_bytes — how much AGENTS.md text Codex reads.
  • [shell_environment_policy] — which environment variables reach the commands Codex runs.
  • check_for_update_on_startup — leave it on unless updates are managed for you.

Profiles have changed. The advanced config page (opens in a new tab) says that from Codex 0.134.0, --profile no longer reads [profiles.<name>] tables from config.toml. Each profile is now its own file, ~/.codex/<name>.config.toml, written with top-level keys, and codex --profile <name> layers it over your base config. Move old profile tables when you upgrade.

~/.codex/deep-review.config.toml
model_reasoning_effort = "high"
sandbox_mode = "read-only"
# use it with: codex --profile deep-review

Every key, with its allowed values, is in the configuration reference (opens in a new tab).

How to exit, update and uninstall Codex CLI

  • Exit: type /quit or /exit, or press Ctrl+C. Commit or save anything important first; the session itself is kept and codex resume reopens it.
  • Update a standalone install: run codex update, or run the install script again.
  • Update an npm install: npm install -g @openai/codex@latest.
  • Update a Homebrew install: brew upgrade --cask codex.
  • Uninstall from npm: npm uninstall -g @openai/codex. From Homebrew: brew uninstall --cask codex.
  • Uninstall the macOS or Linux script install: delete ~/.local/bin/codex and ~/.codex/packages/standalone. Keep the rest of ~/.codex if you might return; it holds your config and sign-in.
  • Two installs at once is the usual reason an update seems not to work. which codex (or where codex on Windows) shows which one runs.

Install commands for each platform are in the openai/codex README (opens in a new tab). Run codex --version afterwards to confirm the change.

A board beside the commands

Commands tell Codex how to work. What to work on is better kept outside the session, where the next session and the next person can find it. Add fenbs with codex mcp add fenbs --url https://fenbs.ai/api/mcp, check it with /mcp, and Codex can read the task in Next Up, move it to In Progress, comment what it changed and move it to Completed, under your role. Each change appears in the board’s history under the assistant’s name. The steps are on Codex CLI on fenbs.

Related

Habits that keep Codex runs reviewable: Codex CLI best practices. Which Codex surface to use: Codex app vs CLI vs IDE extension. Writing the instructions file: AGENTS.md examples.

Questions people ask.

How do I exit Codex CLI?

Type /quit or /exit and press Enter, or press Ctrl+C. The session is saved, so codex resume --last reopens it from the same folder.

How do I upgrade Codex CLI?

Use the same route you installed with: codex update or the install script for a standalone install, npm install -g @openai/codex@latest for npm, or brew upgrade --cask codex for Homebrew. Then check codex --version.

Where is the Codex CLI config file?

In ~/.codex/config.toml for your user, or under CODEX_HOME if you set it. A project can add .codex/config.toml, which Codex reads only for trusted projects. Profiles are separate files named after the profile.

What is the difference between codex exec and codex?

codex opens the interactive terminal UI. codex exec runs one task without it, prints results to the terminal or as JSON lines, and exits, which makes it the one to use in scripts and CI.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.