MCP server bridging Codex CLI to Claude Code, Cursor - (native) review, queries, and search with hardened subprocess management
- ✓Open-source license (MIT)
- ✓Recently active
- ✓Clear description
claude mcp add codex-mcp-bridge -- npx -y codex-mcp-bridge{
"mcpServers": {
"codex-mcp-bridge": {
"command": "npx",
"args": ["-y", "codex-mcp-bridge"]
}
}
}MCP Servers overview
# codex-mcp-bridge
[](https://www.npmjs.com/package/codex-mcp-bridge)
[](https://www.npmjs.com/package/codex-mcp-bridge)
[](https://github.com/hampsterx/codex-mcp-bridge/actions/workflows/ci.yml)
[](https://opensource.org/licenses/MIT)
[](https://nodejs.org/)
[](https://www.typescriptlang.org/)
[](https://modelcontextprotocol.io/)
MCP server that wraps [Codex CLI](https://github.com/openai/codex) as a subprocess, exposing code execution, web search, and structured output as [Model Context Protocol](https://modelcontextprotocol.io/) tools.
Works with any MCP client: Claude Code, Gemini CLI, Cursor, Windsurf, VS Code, or any tool that speaks MCP.
## Do you need this?
If you're in a terminal agent (Claude Code, Codex CLI, Gemini CLI) with shell access, call Codex CLI directly. It's faster, cheaper, and zero overhead:
```bash
# Review current branch vs main
codex review --base main
# Review uncommitted changes
codex review --uncommitted
# Review with custom focus
codex review --base main "Focus on security and error handling"
# From a worktree (run inside the worktree; `-C` is broken for `review`)
cd /path/to/worktree && codex review --base main
# General analysis
codex exec "Analyze src/utils/parse.ts for edge cases"
```
**Use this MCP bridge instead when:**
- Your client has no shell access (Cursor, Windsurf, Claude Desktop, VS Code)
- You need structured output with JSON Schema validation (Codex CLI's `--json` has [known bugs](https://github.com/openai/codex/issues/16552))
- You need partial response capture on timeout and automatic model fallback on
quota exhaustion
- You want subprocess isolation: explicit env allowlist, no shell escape,
secret redaction on output, FIFO-queued concurrency (max 3 parallel spawns,
configurable via `CODEX_MAX_CONCURRENT`)
- You need multi-turn conversations via session resume (`sessionId` /
`resetSession`, inspected via `listSessions`)
Worktree note: Codex CLI issue [#9084](https://github.com/openai/codex/issues/9084)
breaks `codex -C /path review ...`. Run `codex review` from inside the worktree to avoid it.
## Quick Start
```bash
npx codex-mcp-bridge
```
### Prerequisites
- [Codex CLI](https://github.com/openai/codex) installed (`npm i -g @openai/codex`)
- `OPENAI_API_KEY` environment variable set, or `codex auth login` completed
### Claude Code
```bash
claude mcp add codex-bridge -- npx -y codex-mcp-bridge
```
### Gemini CLI
Add to `~/.gemini/settings.json`:
```json
{
"mcpServers": {
"codex-bridge": {
"command": "npx",
"args": ["-y", "codex-mcp-bridge"]
}
}
}
```
### Cursor / Windsurf / VS Code
Add to your MCP settings:
```json
{
"codex-bridge": {
"command": "npx",
"args": ["-y", "codex-mcp-bridge"],
"env": {
"OPENAI_API_KEY": "sk-..."
}
}
}
```
## Tools
| Tool | Description |
|------|-------------|
| **codex** | Execute prompts with file context, session resume, and sandbox control. Multi-turn conversations via session IDs. Use for free-form review prompts; see [Code review with this CLI](#code-review-with-this-cli). |
| **review** | Native diff-aware Codex review via `codex exec review --json`. No caller prompt; supports uncommitted, base branch, and commit review modes. |
| **search** | Web search via `codex --search`. Returns synthesized answers with source URLs. |
| **query** | Lightweight text analysis. No repo context, no sessions. Runs in an isolated temp directory. |
| **structured** | JSON Schema validated output via [Ajv](https://ajv.js.org/). Data extraction, classification, or any task needing machine-parseable output. |
| **ping** | Health check with CLI version, capabilities, and concurrency diagnostics (`activeCount`, `queueDepth`). |
| **mcpStatus** | Report what Codex says about each MCP server it knows about: auth type, tool inventory, and whether it initialized. Optional diagnostic mode adds explicit failure states and error text. |
| **listSessions** | List active conversation sessions with metadata (turn count, model, timestamps). |
### codex
General-purpose execution. Supports multi-turn conversations via `sessionId`, sandbox levels (`read-only`, `workspace-write`, `full-auto`), and reasoning effort control. Pass `resetSession: true` to discard and start fresh. Use `listSessions` to inspect active sessions before resuming.
Key parameters: `prompt` (required), `files`, `model`, `sessionId`, `sandbox`, `reasoningEffort`, `workingDirectory`, `timeout` (default 60s).
### search
Web search powered by OpenAI's native search infrastructure via Codex CLI's `--search` flag. Returns synthesized answers with source URLs.
Key parameters: `query` (required), `model`, `workingDirectory`, `timeout` (default 120s).
### query
Lightweight, non-agentic text analysis. Spawns in an isolated temp directory so the bridge's repo context doesn't leak. Pass text to analyze in the `context` parameter. Supports `reasoningEffort` and `maxResponseLength`.
Key parameters: `prompt` (required), `context`, `model`, `reasoningEffort`, `timeout` (default 60s).
### review
Thin wrapper around Codex CLI's native diff-aware review. The bridge passes the diff selector to `codex exec review --json`; upstream Codex owns the review prompt. Requires a real git repository via `workingDirectory`.
Key parameters: `mode` (required: `uncommitted`, `base`, or `commit`), `workingDirectory` (required), `base` (required for `base` mode), `commit` (required for `commit` mode), `title`, `model`, `timeout` (default 180s).
### structured
Embeds a JSON Schema in the prompt and validates the response with Ajv. Returns clean JSON on success, validation errors on failure.
Key parameters: `prompt` (required), `schema` (required, JSON string), `files`, `model`, `workingDirectory`, `timeout` (default 60s).
### ping
No parameters. Returns CLI version, auth status, model configuration, and concurrency diagnostics (`activeCount`, `queueDepth`).
### mcpStatus
Reports per-server MCP state as Codex's own `app-server` protocol sees it. Unlike every other tool, it deliberately does **not** suppress Codex's MCP servers or harden the subprocess environment, because both would disable the thing being measured. It therefore boots the servers in `~/.codex/config.toml` and is slower than a normal call.
Key parameters: `diagnostics` (default `false`), `workingDirectory`, `timeout` (per-request, default 90s).
| Mode | Cost | What you get |
|------|------|--------------|
| default | ~6-9s | Inventory: auth type, tool names and counts, and `initialized` / `unknown` per server. Creates no thread and writes no session record. |
| `diagnostics: true` | ~10-20s | Adds an explicit `failed` state and the error text naming the cause (expired OAuth grant, missing binary, remote refusal). Starts an ephemeral thread, which is never materialised on disk. |
Reading the output:
- **`unknown` is not a failure.** It means the inventory carried no server info and no explicit verdict was available. Only `diagnostics: true` can report `failed`.
- **A `degraded` warning means don't trust `unknown`.** Slow calls have been observed reporting healthy servers as uninitialized, so the tool reports how long the underlying call took and flags the result when it was slow enough to be suspect.
- **`builtIn`** marks a server Codex injects that is not in your config; **`configuredButUnreported`** marks one in your config that Codex never mentioned.
Example:
```text
atlassian failed auth=oAuth tools=0
error: MCP client for `atlassian` failed to start: MCP startup failed: failed to
refresh OAuth tokens for server atlassian: ... invalid_grant: Grant not found
codex_apps initialized auth=bearerToken tools=117 (builtIn)
linear initialized auth=oAuth tools=57
serena initialized auth=unsupported tools=22
```
All tools attach execution metadata (`_meta`) with `durationMs`, `model`, `fallbackUsed`, and session info where applicable. See [DESIGN.md](DESIGN.md) for details.
## Code review with this CLI
This bridge does not bundle reviewer prompts. There are three paths for code review:
### Native upstream `codex review`
```bash
codex review --base main
codex review --uncommitted
codex review --base main "Focus on security and error handling"
```
Diff-aware review built into Codex CLI. No bridge involvement. Use this when your client has shell access.
### Bridge `review` tool for native diff-aware review
```jsonc
{
"tool": "review",
"arguments": {
"mode": "base",
"base": "main",
"workingDirectory": "/path/to/worktree"
}
}
```
The bridge runs `codex exec review --json` from `workingDirectory`, captures the final review text, and returns review metadata such as `threadId`, event counts, and redacted command output. It does not accept a prompt.
### Bridge `codex` tool with caller-supplied prompt
```jsonc
{
"tool": "codex",
"arguments": {
"prompt": "<your review prompt + diff or file references>",
"sandbox": "read-only"
}
}
```
The bridge runs `codex exec --sandbox read-only` with the supplied prompt and returns stdout. Use this for free-form review prompts or review inputs that are not expressible as `uncommitted`, `base`, or `commit` diff selectors.
### Representative review prompt
A starting point; adapt freely:
```text
Review the following diff:
<diff content>
Look for:
- Bugs that would surface in production
- Missing error handling on user-supplied input
- Tests modifiWhat people ask about codex-mcp-bridge
What is hampsterx/codex-mcp-bridge?
+
hampsterx/codex-mcp-bridge is mcp servers for the Claude AI ecosystem. MCP server bridging Codex CLI to Claude Code, Cursor - (native) review, queries, and search with hardened subprocess management It has 3 GitHub stars and was last updated today.
How do I install codex-mcp-bridge?
+
You can install codex-mcp-bridge by cloning the repository (https://github.com/hampsterx/codex-mcp-bridge) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is hampsterx/codex-mcp-bridge safe to use?
+
Our security agent has analyzed hampsterx/codex-mcp-bridge and assigned a Trust Score of 74/100 (tier: OK). See the full breakdown of passed checks and flags on this page.
Who maintains hampsterx/codex-mcp-bridge?
+
hampsterx/codex-mcp-bridge is maintained by hampsterx. The last recorded GitHub activity is from today, with 0 open issues.
Are there alternatives to codex-mcp-bridge?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy codex-mcp-bridge to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/hampsterx-codex-mcp-bridge)<a href="https://claudewave.com/repo/hampsterx-codex-mcp-bridge"><img src="https://claudewave.com/api/badge/hampsterx-codex-mcp-bridge" alt="Featured on ClaudeWave: hampsterx/codex-mcp-bridge" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
The fastest path to AI-powered full stack observability, even for lean teams.
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!