SERIESCodex Foundations

Reference

Codex MCP server directory: choose by task and permissions

Reference · 3 min read

Terms in this guide: MCP · Permission · Plugin

A criteria-led directory for deciding which kind of MCP connection your Codex workflow needs and what to inspect before enabling it.

Documentation and knowledge servers

Use this category when the task needs current product manuals, internal technical references, or a searchable knowledge base. Evaluate source freshness, retrieval scope, citations, rate limits, and whether confidential documents leave the organization.

A useful listing should identify transport, authentication, supported resources, the maintainer, and a reproducible read-only query.

Code hosting and issue trackers

These servers can expose repositories, pull requests, checks, issues, and project planning data. Separate read operations from comments, merges, issue edits, and workflow triggers. Confirm that server permissions match the repositories and organizations the user intends to access.

Design and browser tools

Design servers can expose files, components, or variables; browser tools can inspect and interact with pages. Record whether a tool reads the current signed-in session, runs in an isolated browser, or can perform account actions. Screenshot access and click access have different risk.

Collaboration and business systems

Email, chat, calendar, CRM, storage, and analytics tools can turn a coding workflow into an operational one. Check which people and records are visible, whether actions send messages or change external state, and which approval step remains before an irreversible action.

Local and remote transport

Codex supports local STDIO servers and remote Streamable HTTP servers in supported clients. Configuration can include environment variables, bearer tokens, or OAuth. Use a project-scoped configuration only for projects you trust, and avoid placing secrets directly in shareable files.

Server instructions can affect how Codex uses the full tool set. Maintainers should put important cross-tool constraints and rate limits early in those instructions.

Directory inclusion standard

AboutCodex should list a server only when it has an identifiable maintainer, primary documentation, a clear purpose, supported transport, authentication details, requested permissions, setup steps, limitations, and a current check date. Editorial inclusion should never imply a security guarantee or compatibility with every client.

Evaluate the capability before the catalog entry

Start with the reader task, then ask whether the server exposes the right data or action with a clear permission boundary. A long tool list does not prove usefulness. Record the service owner, authentication method, supported client, transport, required account, and whether the server reads data, writes data, or can trigger external side effects.

Prefer official documentation and repositories. Verify maintenance signals and installation steps on the review date. If a server is community maintained, say so clearly and avoid implying endorsement. Directory entries should make it easy to decide whether the capability fits before a reader connects an account.

Test the smallest safe interaction

After configuration, begin with discovery and a read-only request. Confirm that the expected tools appear, the server receives the intended scope, and errors do not reveal credentials. Test a write action only when it is part of the authorized use case, using a reversible target or draft state.

Record client version, server version, authentication path, tested operations, and limits. Availability in one Codex client does not prove the same integration works in every client. Keep those compatibility statements dated because plugin and MCP support can change.

Primary source

OpenAI MCP documentation. Source checked September 10, 2026.

My learningReport an issue with this pageGet the next practical briefing

Progress stays in this browser. No account needed.

View saved items
Updates and upgrade guidance
  1. Learning context added

    Added prerequisites, a suggested practice estimate, expected output, and connected definitions. The article procedure was not independently re-evaluated in this change.

    What to do: Use the opening checklist to prepare. No software update is required for this editorial change.

This log starts with the first recorded review; it is not a reconstruction of earlier revisions.

Keep the momentum

Your next useful read.

Explore the learning library