73
/ 100
11 hours ago
glama

codex-app-mcp

Production-oriented MCP gateway for managing Codex through a persistent codex app-server process, supporting threads, autonomous goals, approvals, and HTTP/stdio transports.

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find. Or connect your repo for the top badge — read-only, revoke anytime. What we access →

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
No credential exfiltration, no sensitive file access, no obfuscation
Static analysis found nothing flowing your secrets to unexpected places.
🔐
You'll be asked for 1 credential: CODEX_APP_MCP_HTTP_TOKEN
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
configCODEX_APP_MCP_TRANSPORT
configCODEX_APP_MCP_HTTP_HOST
configCODEX_APP_MCP_HTTP_PORT
🔐 secretCODEX_APP_MCP_HTTP_TOKEN
configCODEX_APP_MCP_HTTP_TOKEN_FILE
configCODEX_APP_MCP_HTTP_MAX_INFLIGHT
configCODEX_APP_MCP_HTTP_ALLOWED_ORIGINS
configCODEX_APP_MCP_AUDIT
configCODEX_APP_MCP_PRINCIPAL
configCODEX_APP_MCP_AUDIT_PATH
configCODEX_APP_MCP_CONFIG_OVERRIDES
configCODEX_APP_MCP_BIN
configCODEX_APP_MCP_DEFAULT_SANDBOX
configCODEX_APP_MCP_LANES_PARENT
configCODEX_APP_MCP_ALLOWED_ROOTS
configCODEX_APP_MCP_ALLOWED_SERVERS
configCODEX_APP_MCP_ALLOWED_TOOLS
configCODEX_APP_MCP_ALLOWED_CONFIG_KEYS
configCODEX_APP_MCP_ALLOWED_RPC_METHODS
configCODEX_APP_MCP_SCHEDULER_POLL_SECONDS
configCODEX_APP_MCP_STATE_PATH
configCODEX_HOMEAuth = local codex login (). Never put OAuth in MCP config or HTTP bearer.
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 1 concrete improvement we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/zai-one-codex-mcp-9b7qac)](https://m8ven.ai/mcp/zai-one-codex-mcp-9b7qac)
commit: 384f710a36c9ef0e20dfc1448704f5dc5b290204
code hash: 3986449e4364222089093346b3bd1cd6b50761c505fa960cf99f829f8ce99d6c
verified: 8/10/2026, 4:19:31 AM
view raw JSON →
Check MCPs from inside your assistant
Tool Check · MCP

Vetting this one by hand? Tool Check is an MCP that scores other MCPs. Add it once and ask Claude, ChatGPT, or any MCP client to grade a server, surface CVEs, check the publisher, and suggest safer alternatives — before you install.

https://m8ven.ai/api/mcp/tool-check
check_toolsearch_toolscompare_toolsrecommend_alternativescheck_publisherreport_concern
How to add it →Free · no account needed · works in any MCP client