---
title: "Codex"
description: "Connect Anlyon to Codex: governed actions and approvals over MCP, with OAuth or a scoped API key"
icon: "terminal"
---

Anlyon executes named production actions on an agent's behalf and routes sensitive ones to a human reviewer first. Connect a workspace to list its actions, invoke one, request approval, and, with the decide permission, approve or deny pending requests. A tool your own code calls directly is not routed through Anlyon and is not governed by it.

## Connect

Codex connects to Anlyon's hosted MCP endpoint and signs you in with OAuth ("Login with Anlyon"). There is no API key to paste.

Add the server to `~/.codex/config.toml`:

```toml
[mcp_servers.anlyon]
url = "https://api.anlyon.com/mcp"
```

Then sign in:

```bash
codex mcp login anlyon
```

A browser opens. Sign in to Anlyon or create an account (a new account gets a free workspace during sign-in), and choose permissions. If you belong to more than one workspace, Anlyon first asks which workspace and environment Codex acts in. With one workspace, the connection is bound to its default environment. "Approve on your behalf" is off unless you turn it on. Codex sees only the tools the permissions you granted cover.

Codex's configuration format changes between releases. If the block above is refused, check Codex's MCP documentation for your version.

### Running Codex in CI or without a browser

OAuth needs a browser once. For a headless run, use the self-hosted server with an API key instead, scoped to what the run should be able to do:

```toml
[mcp_servers.anlyon]
command = "npx"
args = ["-y", "@anlyonhq/mcp-server"]
env = { ANLYON_API_KEY = "anlyon_live_..." }
```

Keep the key out of the repository. The key's scopes are exactly what Codex can do. The self-hosted server exposes the governed tools only.

## Tools

By default the server exposes the governed set and nothing else:

| Tool | What it does |
| --- | --- |
| `list_actions` | List the workspace's actions and say which require approval |
| `invoke_action` | Invoke an action by name. Actions also appear as tools named `action_<name>` |
| `request_approval` | Ask a human to decide something outside an action |
| `check_approval` | Read an approval's status once |
| `wait_for_approval` | Wait for a reviewer's decision, up to 120 seconds a call, 60 by default. Returns the still pending approval if nobody has decided |
| `list_pending_approvals`, `decide_approval` | Review and decide. On the hosted endpoint, shown only with "Approve on your behalf". With an API key, the key needs `approvals:decide` |
| `list_workspaces`, `select_workspace` | Choose which workspace and environment Codex acts in. Switching is OAuth only and needs "Switch between your workspaces" |

## Actions and approvals

Codex lists the workspace's actions and invokes them as tools named `action_<name>`. The model never sees a credential: an action references `{{secret:NAME}}` and Anlyon resolves it at dispatch. This covers credentials in the Anlyon vault, not a key your own process already holds. An action that requires approval waits for a reviewer, and Codex can wait with `wait_for_approval`. Anlyon does not retry an action invocation. Where a request may have reached the destination and the outcome cannot be confirmed, the invocation is recorded as `unknown` and you reconcile before retrying.

With "Approve on your behalf" granted, `list_pending_approvals` and `decide_approval` let you review from Codex. Your decision is recorded against your name and counts as one user toward an N-of-M rule.

## Connect a second tool

An approval one tool requests can be reviewed from another. Connect the second one to the **same workspace** and environment.

**Claude Code**

```bash
claude mcp add --transport http anlyon https://api.anlyon.com/mcp   # then run /mcp to sign in
```

**Cursor:** add `https://api.anlyon.com/mcp` through Settings, "Add MCP server".
