Skip to content

Remote Codex 0.12.16

Choose a tag to compare

@github-actions github-actions released this 06 Sep 18:02

Account security and encrypted relay transport, plus the latest Codex composer fixes.

  • Manage authenticator apps, passkeys, recovery codes, trusted browsers, and active sessions in Account → Security (also available to administrators).
  • Trust a verified browser for 30 days; sensitive account changes require recent verification.
  • Harden attachment access, WebSocket authorization, session revocation, browser origins, and OAuth state/PKCE.
  • Add browser-to-device encrypted HTTP and WebSocket transport, streamed file downloads, device fingerprints, and restart recovery. Older device handshakes remain compatible.
  • Restore Codex effort controls when model metadata is missing, hide skill entries from slash commands, and show actionable fork errors.

Upgrade relay and device runtimes to use encrypted transport. Existing relay sessions require signing in again. Keep the relay database and its persistent session secret backed up together: that secret also protects authenticator enrollment data. Configure the public HTTPS origin for passkeys/OAuth. Encryption does not remove the relay's existing device permissions or trust in relay-served JavaScript.

Includes macOS arm64, Linux x64/arm64, and Windows x64 CLI assets. Windows Device Manager is independently released and unchanged. Native binaries are unsigned; verify downloads with SHA256SUMS.