Codex
Connect Anlyon to Codex: governed actions and approvals over MCP, with OAuth or a scoped API key
Anlyon executes named production actions on an agent’s behalf and routes sensitive ones to a human reviewer first. Connect a workspace to list its actions, invoke one, request approval, and, with the decide permission, approve or deny pending requests. A tool your own code calls directly is not routed through Anlyon and is not governed by it.
Connect
Codex connects to Anlyon’s hosted MCP endpoint and signs you in with OAuth (“Login with Anlyon”). There is no API key to paste.
Add the server to ~/.codex/config.toml:
[mcp_servers.anlyon]
url = "https://api.anlyon.com/mcp"
Then sign in:
codex mcp login anlyon
A browser opens. Sign in to Anlyon or create an account (a new account gets a free workspace during sign-in), and choose permissions. If you belong to more than one workspace, Anlyon first asks which workspace and environment Codex acts in. With one workspace, the connection is bound to its default environment. “Approve on your behalf” is off unless you turn it on. Codex sees only the tools the permissions you granted cover.
Codex’s configuration format changes between releases. If the block above is refused, check Codex’s MCP documentation for your version.
Running Codex in CI or without a browser
OAuth needs a browser once. For a headless run, use the self-hosted server with an API key instead, scoped to what the run should be able to do:
[mcp_servers.anlyon]
command = "npx"
args = ["-y", "@anlyonhq/mcp-server"]
env = { ANLYON_API_KEY = "anlyon_live_..." }
Keep the key out of the repository. The key’s scopes are exactly what Codex can do. The self-hosted server exposes the governed tools only.
Tools
By default the server exposes the governed set and nothing else:
| Tool | What it does |
|---|---|
list_actions |
List the workspace’s actions and say which require approval |
invoke_action |
Invoke an action by name. Actions also appear as tools named action_<name> |
request_approval |
Ask a human to decide something outside an action |
check_approval |
Read an approval’s status once |
wait_for_approval |
Wait for a reviewer’s decision, up to 120 seconds a call, 60 by default. Returns the still pending approval if nobody has decided |
list_pending_approvals, decide_approval |
Review and decide. On the hosted endpoint, shown only with “Approve on your behalf”. With an API key, the key needs approvals:decide |
list_workspaces, select_workspace |
Choose which workspace and environment Codex acts in. Switching is OAuth only and needs “Switch between your workspaces” |
Actions and approvals
Codex lists the workspace’s actions and invokes them as tools named action_<name>. The model never sees a credential: an action references {{secret:NAME}} and Anlyon resolves it at dispatch. This covers credentials in the Anlyon vault, not a key your own process already holds. An action that requires approval waits for a reviewer, and Codex can wait with wait_for_approval. Anlyon does not retry an action invocation. Where a request may have reached the destination and the outcome cannot be confirmed, the invocation is recorded as unknown and you reconcile before retrying.
With “Approve on your behalf” granted, list_pending_approvals and decide_approval let you review from Codex. Your decision is recorded against your name and counts as one user toward an N-of-M rule.
Connect a second tool
An approval one tool requests can be reviewed from another. Connect the second one to the same workspace and environment.
Claude Code
claude mcp add --transport http anlyon https://api.anlyon.com/mcp # then run /mcp to sign in
Cursor: add https://api.anlyon.com/mcp through Settings, “Add MCP server”.

