← All agent setup guides

CONFIGURATION, EXPLAINED

Codex Config: config.toml Settings & API Setup

Read one continuous config, with model, access, permissions and tools marked inside the code. Select a setting to see its explanation beside it.

Official sources reviewed 2026-10-08One config · select a setting to read its explanation
~/.codex/config.toml

One continuous config. Click a line for its explanation. Commented lines show optional settings, alternatives or separate setup; the copy button includes active settings only.

TOML CONFIGSections are marked inside the codeSELECTED SETTINGOnly what you click is explained here

Model & responses

Choose the model

model

Selects the model that handles your task.

In the main config~/.codex/config.toml
In this example
gpt-6-astra is the model chosen for this example. Replace it with an ID your account can use.
If you leave it unset
Omitting this key leaves model selection to the client and its effective defaults.
When to change it
Change it when comparing the same task on another available model.
What changes / what to watch
Capability, latency, and usage depend on the model and your plan; the name alone does not establish a task price.
Check that it worked
Start a fresh session and inspect the selected model in /model.
Official reference ↗

Copy keeps the parent structure. Merge it into the file shown above.

# ── Connection alternatives & separate-file setup ──
# ~/.codex/config.toml · alternative provider section
#
# [model_providers.example]
# Terminal · choose one authentication route
# Terminal · choose one authentication route
# ~/.codex/config.toml
# ~/.codex/config.toml
# [model_providers.example]
# ~/.codex/config.toml
#
# [model_providers.amazon-bedrock.aws]
# ~/.codex/config.toml
# ~/.codex/config.toml
#
# [permissions.project]
#
# [permissions.project.network]
# ~/.codex/config.toml
# [mcp_servers.docs]
# ~/.codex/config.toml
#
# [model_providers.company]
#
# [model_providers.company.auth]
# ~/.codex/review.config.toml
Look up any documented key

SETTINGS AND OFFICIAL SOURCES

Full reference index

This dated index covers all entries in the reviewed official reference, including managed settings, stored state and legacy options. Entries with a worked example link back to the annotated config above; other entries link to their official specification. The index is not a file to paste, and not every key is available in every client or scope.

297 of 297 documented entries · showing 30

approval_policyon-request | never | { granular = { sandbox_approval = bool, rules = bool, mcp_elicitations = bool, request_permissions = bool, skill_approval = bool } }

Permissions and sandbox · Check scope in reference · Deprecated / legacy

sandbox_workspace_write.exclude_tmpdir_env_varboolean

Permissions and sandbox · Check scope in reference

Setup, troubleshooting & official sources

Where settings take effect

Codex local configuration. Reviewed against official documentation on 8 October 2026. Examples cover common complete workflows; the separate key index includes documented advanced, managed and legacy fields. Installed versions and account policies can differ.

  1. Open ~/.codex/config.toml for your personal defaults. Compare this example with the file you already have and merge only the settings you want.
  2. Trusted projects can also load .codex/config.toml. CLI overrides take priority over project files, which take priority over selected profiles and user defaults. Organization requirements can constrain the result.
  3. Sign in through Codex separately. The first example uses the built-in OpenAI provider; choose a model available in your own model picker. Restart your local session after editing and check the active settings.
  4. For isolated preferences, the current reference uses sibling profile files such as ~/.codex/review.config.toml, selected with --profile review. A role config file is different from a profile. Trusted project config cannot redefine user-level provider connections.
  5. Choose one model-provider route. Commented alternatives and separate-file instructions appear in the same reading window; only active main-file settings are included in the full-config copy. Replace marked paths, model IDs and endpoints, and supply secrets through the documented local credential mechanism.

OFFICIAL AND THIRD-PARTY ACCESS

Choose how the agent connects.

Use one model-provider route per session. MCP connects tools and data; it does not replace model authentication.

Official ChatGPT account

Built-in OpenAI provider with account sign-in.

Authentication
codex login; check codex login status.
Verify
Check model entitlement and the account shown by the client.
Open annotated setup →

Official OpenAI API

Built-in OpenAI provider with API billing.

Authentication
OPENAI_API_KEY supplied through the documented login command.
Verify
Check API authentication status and available model IDs.
Open annotated setup →

Third-party gateway

Custom provider with a compatible Responses endpoint.

Authentication
env_key, environment-backed headers, or a documented auth helper; choose the service's required method.
Verify
Verify protocol, streaming/tool compatibility, base path and model ID. ‘OpenAI compatible’ alone is insufficient.
Open annotated setup →

Amazon Bedrock

Documented amazon-bedrock provider.

Authentication
AWS credential profile and region.
Verify
Verify installed-client support and AWS model/IAM access.
Open annotated setup →

Local model

--oss with a supported local provider.

Authentication
Local service setup rather than an OpenAI account key.
Verify
Start the service and select an installed, compatible model.
Open annotated setup →

AFTER YOU EDIT

Check the effective settings.

  1. Validate JSON/TOML syntax and the file location. A valid file can still contain an unsupported or wrong-scope key.
  2. Check codex login status and the effective model/provider after restarting. Check which profile and project layer loaded.
  3. For 401/403 errors, check the authentication route, credential lifetime and model entitlement. For missing endpoints or models, check base path, protocol, region and model/deployment ID.
  4. For a setting that has no effect, check version support, scope, higher-priority overrides and model capabilities before adding more parameters.
  5. For tool/startup errors, inspect the MCP launch command, required variables and timeouts; use a harmless read-only request before a real operation.
  6. Change one tuning control at a time. Compare the same task using observed quality, duration, tokens and actual billed usage. Examples here are documentation-checked, not live gateway benchmarks.

Documentation-based examples. No live model calls or measured cost savings are claimed.

COMMON QUESTIONS

A few useful distinctions.

Where is temperature?

This guide covers documented Codex settings. A model API parameter is not automatically a supported Codex config key. Use the client's documented reasoning controls instead of adding an unverified temperature key.

Does this also configure cloud tasks?

The examples target local Codex configuration. Cloud environments and managed Work policies have their own supported fields; do not assume a local provider or sandbox setting carries over.

Official sources

Checked 2026-10-08. Follow the documentation for your installed version and selected model.

Back to the Codex profile →