Read one continuous config, with model, access, permissions and tools marked inside the code. Select a setting to see its explanation beside it.
Official sources reviewed 2026-10-08One config · select a setting to read its explanation
~/.codex/config.toml
One continuous config. Click a line for its explanation. Commented lines show optional settings, alternatives or separate setup; the copy button includes active settings only.
TOML CONFIGSections are marked inside the codeSELECTED SETTINGOnly what you click is explained here
1
2
3
Model & responses
Choose the model
model
Selects the model that handles your task.
In the main config~/.codex/config.toml
In this example
gpt-6-astra is the model chosen for this example. Replace it with an ID your account can use.
If you leave it unset
Omitting this key leaves model selection to the client and its effective defaults.
When to change it
Change it when comparing the same task on another available model.
What changes / what to watch
Capability, latency, and usage depend on the model and your plan; the name alone does not establish a task price.
Check that it worked
Start a fresh session and inspect the selected model in /model.
89# ~/.codex/config.toml · alternative provider section
90
91
92#
93# [model_providers.example]
94
95
96
97
98
99
100
101# Terminal · choose one authentication route
102
103
104
105
106# Terminal · choose one authentication route
107
108
109
110
111# ~/.codex/config.toml
112
113
114
115
116# ~/.codex/config.toml
117# [model_providers.example]
118
119
120
121
122
123
124
125
126
127
128# ~/.codex/config.toml
129
130
131#
132# [model_providers.amazon-bedrock.aws]
133
134
135
136
137# ~/.codex/config.toml
138
139
140
141
142# ~/.codex/config.toml
143
144#
145# [permissions.project]
146
147
148#
149# [permissions.project.network]
150
151
152
153# ~/.codex/config.toml
154# [mcp_servers.docs]
155
156
157
158
159
160# ~/.codex/config.toml
161
162
163#
164# [model_providers.company]
165
166
167#
168# [model_providers.company.auth]
169
170
171
172
173
174# ~/.codex/review.config.toml
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
Look up any documented key
SETTINGS AND OFFICIAL SOURCES
Full reference index
This dated index covers all entries in the reviewed official reference, including managed settings, stored state and legacy options. Entries with a worked example link back to the annotated config above; other entries link to their official specification. The index is not a file to paste, and not every key is available in every client or scope.
Codex local configuration. Reviewed against official documentation on 8 October 2026. Examples cover common complete workflows; the separate key index includes documented advanced, managed and legacy fields. Installed versions and account policies can differ.
Open ~/.codex/config.toml for your personal defaults. Compare this example with the file you already have and merge only the settings you want.
Trusted projects can also load .codex/config.toml. CLI overrides take priority over project files, which take priority over selected profiles and user defaults. Organization requirements can constrain the result.
Sign in through Codex separately. The first example uses the built-in OpenAI provider; choose a model available in your own model picker. Restart your local session after editing and check the active settings.
For isolated preferences, the current reference uses sibling profile files such as ~/.codex/review.config.toml, selected with --profile review. A role config file is different from a profile. Trusted project config cannot redefine user-level provider connections.
Choose one model-provider route. Commented alternatives and separate-file instructions appear in the same reading window; only active main-file settings are included in the full-config copy. Replace marked paths, model IDs and endpoints, and supply secrets through the documented local credential mechanism.
OFFICIAL AND THIRD-PARTY ACCESS
Choose how the agent connects.
Use one model-provider route per session. MCP connects tools and data; it does not replace model authentication.
Official ChatGPT account
Built-in OpenAI provider with account sign-in.
Authentication
codex login; check codex login status.
Verify
Check model entitlement and the account shown by the client.
Validate JSON/TOML syntax and the file location. A valid file can still contain an unsupported or wrong-scope key.
Check codex login status and the effective model/provider after restarting. Check which profile and project layer loaded.
For 401/403 errors, check the authentication route, credential lifetime and model entitlement. For missing endpoints or models, check base path, protocol, region and model/deployment ID.
For a setting that has no effect, check version support, scope, higher-priority overrides and model capabilities before adding more parameters.
For tool/startup errors, inspect the MCP launch command, required variables and timeouts; use a harmless read-only request before a real operation.
Change one tuning control at a time. Compare the same task using observed quality, duration, tokens and actual billed usage. Examples here are documentation-checked, not live gateway benchmarks.
Documentation-based examples. No live model calls or measured cost savings are claimed.
COMMON QUESTIONS
A few useful distinctions.
Where is temperature?
This guide covers documented Codex settings. A model API parameter is not automatically a supported Codex config key. Use the client's documented reasoning controls instead of adding an unverified temperature key.
Does this also configure cloud tasks?
The examples target local Codex configuration. Cloud environments and managed Work policies have their own supported fields; do not assume a local provider or sandbox setting carries over.
Official sources
Checked 2026-10-08. Follow the documentation for your installed version and selected model.