Skip to content

Codex Portable 0.121.0

Choose a tag to compare

@HansBug HansBug released this 17 Apr 08:44
· 60 commits to main since this release

Portable bundles for OpenAI Codex CLI 0.121.0.

OpenAI Codex CLI 0.121.0 expands several day-to-day workflows at once: plugin marketplace installation, TUI history and memory controls, richer MCP integrations, and broader app-server and realtime APIs. It also tightens behavior across macOS, Windows, sandboxing, and thread persistence so the new surface area is backed by more predictable runtime behavior.

Highlights

  • codex marketplace add now supports installing plugin marketplaces from GitHub, arbitrary git URLs, local directories, and direct marketplace.json URLs, with matching app-server support so marketplace setup works across both CLI and server-driven workflows.
  • The TUI composer now has Ctrl+R reverse history search and local recall for accepted slash commands, making it much faster to rerun prior prompts and command sequences without retyping them.
  • Memory management is now exposed directly in both the TUI and app-server, including memory mode controls, memory reset and deletion actions, and cleanup for memory extensions.
  • MCP and plugin integration grew substantially with MCP Apps tool-call support, namespaced MCP registration, opt-in parallel tool-call support, and sandbox-state metadata passed through for MCP servers.
  • Realtime and app-server APIs now expose output modality control, transcript completion events, raw turn item injection, and symlink-aware filesystem metadata, which broadens what external clients can observe and drive programmatically.
  • A secure devcontainer profile was added with bubblewrap support, alongside macOS sandbox allowlists for Unix sockets, improving isolation options for users running Codex in stricter local environments.

Stability and fixes

  • macOS sandbox networking was corrected to work with private DNS and proxy setups, and the prior danger-full-access denylist-only network mode was removed.
  • Windows path handling was fixed so resume --last and thread/list behave correctly when the working directory uses verbatim path prefixes.
  • Guardian timeouts are now treated distinctly from policy denials, with timeout-specific guidance and visible TUI history entries instead of collapsing these cases into a generic refusal path.
  • App-server reliability improved by avoiding premature thread unloads, tolerating failed trust persistence during startup, and skipping broken symlinks during fs/readDirectory.
  • MCP tool-call edge cases were fixed around flattened deferred tool names, elicitation timeout accounting, and empty namespace descriptions.

Engineering notes

  • Release verification was strengthened so release-only Rust code is compiled during verification, reducing the chance of release-specific build regressions escaping earlier checks.
  • Local thread storage was refactored behind a new codex-thread-store crate and interface, and local thread listing was moved onto that abstraction.
  • Rust internals were simplified with broader use of absolute-path types and removal of unused helper APIs, which reduces maintenance surface and path-handling ambiguity for advanced integrations.

Source links

Portable artifacts for Linux, macOS, and Windows are attached after the release smoke tests pass.