PluginBench
MCP Server
Active
ISC

io.github.xiaolai/codex-octopus MCP Server

io.github.xiaolai/codex-octopus

Spawn multiple specialized Codex agents as MCP servers, each with custom models, sandboxes, and personalities.

What is the io.github.xiaolai/codex-octopus MCP server?

Codex Octopus is an MCP server that wraps the OpenAI Codex SDK, allowing you to run multiple specialized Codex agents—each independently configured with different models, sandbox modes, effort levels, and instructions—from a single MCP client. Each agent appears as a separate tool, enabling use cases like strict code review, test writing, and quick Q&A simultaneously.

Codex Octopus lets you configure and deploy multiple Codex agents with different personalities and constraints. Instead of one generic Codex instance, you can spin up a read-only code reviewer, a test-writing specialist, a cheap quick helper, and a deep-thinking expert—all at once. Each runs in its own sandbox with its own model and approval policy, giving you fine-grained control over what each agent can do.

How to install io.github.xiaolai/codex-octopus

Copy-paste configuration for popular MCP clients.

transport: stdio
Config generated by PluginBench — verify against the source before use.
Environment / auth
  • CODEX_API_KEY
    secret

    OpenAI API key (leave unset to inherit from parent process)

  • CODEX_TOOL_NAME

    Tool name prefix (default: codex)

  • CODEX_MODEL

    Model: gpt-5-codex, o3, codex-1, or full ID

  • CODEX_SANDBOX_MODE

    Sandbox: read-only, workspace-write, danger-full-access

  • CODEX_APPROVAL_POLICY

    Approval: never, on-failure, on-request, untrusted

  • CODEX_APPEND_INSTRUCTIONS

    Additional instructions appended to the default

  • CODEX_FACTORY_ONLY

    Set to true to expose only the factory wizard tool

~/Library/Application Support/Claude/claude_desktop_config.json
{
  "mcpServers": {
    "codex-octopus": {
      "command": "npx",
      "args": [
        "-y",
        "codex-octopus"
      ],
      "env": {
        "CODEX_API_KEY": "<YOUR_CODEX_API_KEY>",
        "CODEX_TOOL_NAME": "<YOUR_CODEX_TOOL_NAME>",
        "CODEX_MODEL": "<YOUR_CODEX_MODEL>",
        "CODEX_SANDBOX_MODE": "<YOUR_CODEX_SANDBOX_MODE>",
        "CODEX_APPROVAL_POLICY": "<YOUR_CODEX_APPROVAL_POLICY>",
        "CODEX_APPEND_INSTRUCTIONS": "<YOUR_CODEX_APPEND_INSTRUCTIONS>",
        "CODEX_FACTORY_ONLY": "<YOUR_CODEX_FACTORY_ONLY>"
      }
    }
  }
}

Tools & capabilities

Tools this server exposes to the agent.

  • <name> (customizable) — Send a task to the agent and receive a response with a thread_id for conversation continuity.
  • <name>_reply (customizable) — Continue a previous conversation with the agent by referencing its thread_id.
  • create_codex_mcp (factory mode only) — Interactive wizard that generates .mcp.json configuration entries for new specialized agents.

Use cases

  • Deploy a strict code reviewer with read-only sandbox to audit pull requests without risk of modification.
  • Create a dedicated test-writing agent with workspace-write access and TDD-focused instructions.
  • Run a minimal-effort quick-answer helper for fast coding questions at lower cost.
  • Set up multiple agents with different reasoning effort levels (minimal to xhigh) for different complexity tiers.
  • Use the factory wizard to interactively generate new agent configurations without manual .mcp.json editing.

io.github.xiaolai/codex-octopus MCP server FAQ

What is Codex Octopus?

Codex Octopus is an MCP server that lets you run multiple specialized Codex agents simultaneously, each with its own model, sandbox mode, effort level, and custom instructions. Instead of one generic agent, you get purpose-built tools like a code reviewer, test writer, and quick helper.

Is it free?

Codex Octopus itself is free and open-source (ISC license), but it requires an OpenAI API key and will incur charges based on your Codex API usage.

How do I install it in Cursor or Claude Desktop?

Add an entry to your `.mcp.json` file with `command: npx` and `args: ["codex-octopus@latest"]`, optionally setting environment variables for model, sandbox mode, and instructions. You can run multiple instances with different configurations.

What authentication is required?

You need an OpenAI API key set as the `CODEX_API_KEY` environment variable. If not provided, it inherits from the parent process.

Can I customize each agent's behavior?

Yes. Each instance is configured via environment variables in `.mcp.json`: model selection, sandbox mode (read-only, workspace-write, danger-full-access), reasoning effort, approval policy, and custom instructions.

What is the factory mode?

Set `CODEX_FACTORY_ONLY=true` to expose a single `create_codex_mcp` tool—an interactive wizard that generates `.mcp.json` entries for new agents based on your description.

README (reference)

Source of truth, from the repository.

<p align="center"> <img src="https://raw.githubusercontent.com/xiaolai/codex-octopus/main/assets/codex-octopus.svg" alt="Codex Octopus" width="200" /> </p>

Codex Octopus

One brain, many arms.

An MCP server that wraps the OpenAI Codex SDK, letting you run multiple specialized Codex agents — each with its own model, sandbox, effort, and personality — from any MCP client.

Why

Codex is powerful. But one instance does everything the same way. Sometimes you want a strict code reviewer in read-only sandbox. A test writer with workspace-write access. A cheap quick helper on minimal effort. A deep thinker on xhigh.

Codex Octopus lets you spin up as many of these as you need. Same binary, different configurations. Each one shows up as a separate tool in your MCP client.

Prerequisites

  • Node.js >= 18
  • Codex CLI — the Codex SDK spawns the Codex CLI under the hood, so you need it installed (@openai/codex)
  • OpenAI API key (CODEX_API_KEY env var) or inherited from parent process

Install

npm install codex-octopus

Or use npx directly in your .mcp.json (see Quick Start below).

Quick Start

Add to your .mcp.json:

{
  "mcpServers": {
    "codex": {
      "command": "npx",
      "args": ["codex-octopus@latest"],
      "env": {
        "CODEX_SANDBOX_MODE": "workspace-write",
        "CODEX_APPROVAL_POLICY": "never"
      }
    }
  }
}

This gives you two tools: codex and codex_reply. That's it — you have Codex as a tool.

Multiple Agents

The real power is running several instances with different configurations:

{
  "mcpServers": {
    "code-reviewer": {
      "command": "npx",
      "args": ["codex-octopus@latest"],
      "env": {
        "CODEX_TOOL_NAME": "code_reviewer",
        "CODEX_SERVER_NAME": "code-reviewer",
        "CODEX_DESCRIPTION": "Strict code reviewer. Read-only sandbox.",
        "CODEX_MODEL": "o3",
        "CODEX_SANDBOX_MODE": "read-only",
        "CODEX_APPEND_INSTRUCTIONS": "You are a strict code reviewer. Report real bugs, not style preferences.",
        "CODEX_EFFORT": "high"
      }
    },
    "test-writer": {
      "command": "npx",
      "args": ["codex-octopus@latest"],
      "env": {
        "CODEX_TOOL_NAME": "test_writer",
        "CODEX_SERVER_NAME": "test-writer",
        "CODEX_DESCRIPTION": "Writes thorough tests with edge case coverage.",
        "CODEX_MODEL": "gpt-5-codex",
        "CODEX_SANDBOX_MODE": "workspace-write",
        "CODEX_APPEND_INSTRUCTIONS": "Write tests first. Cover edge cases. TDD."
      }
    },
    "quick-qa": {
      "command": "npx",
      "args": ["codex-octopus@latest"],
      "env": {
        "CODEX_TOOL_NAME": "quick_qa",
        "CODEX_SERVER_NAME": "quick-qa",
        "CODEX_DESCRIPTION": "Fast answers to quick coding questions.",
        "CODEX_EFFORT": "minimal"
      }
    }
  }
}

Your MCP client now sees three distinct tools — code_reviewer, test_writer, quick_qa — each purpose-built.

Agent Factory

Don't want to write configs by hand? Add a factory instance:

{
  "mcpServers": {
    "agent-factory": {
      "command": "npx",
      "args": ["codex-octopus@latest"],
      "env": {
        "CODEX_FACTORY_ONLY": "true",
        "CODEX_SERVER_NAME": "agent-factory"
      }
    }
  }
}

This exposes a single create_codex_mcp tool — an interactive wizard. Tell it what you want ("a strict code reviewer with read-only sandbox") and it generates the .mcp.json entry for you.

Tools

Each non-factory instance exposes:

ToolPurpose
<name>Send a task to the agent, get a response + thread_id
<name>_replyContinue a previous conversation by thread_id

Per-invocation parameters (override server defaults):

ParameterDescription
promptThe task or question (required)
cwdWorking directory override
modelModel override
additionalDirsExtra directories the agent can access
effortReasoning effort (minimal to xhigh)
sandboxModeSandbox override (can only tighten, never loosen)
approvalPolicyApproval override (can only tighten, never loosen)
networkAccessEnable network access from sandbox
webSearchModeWeb search: disabled, cached, live
instructionsAdditional instructions (prepended to prompt)

Configuration

All configuration is via environment variables in .mcp.json. Every env var is optional.

Identity

Env VarDescriptionDefault
CODEX_TOOL_NAMETool name prefix (<name> and <name>_reply)codex
CODEX_DESCRIPTIONTool description shown to the host AIgeneric
CODEX_SERVER_NAMEMCP server name in protocol handshakecodex-octopus
CODEX_FACTORY_ONLYOnly expose the factory wizard toolfalse

Agent

Env VarDescriptionDefault
CODEX_MODELModel (gpt-5-codex, o3, codex-1, etc.)SDK default
CODEX_CWDWorking directoryprocess.cwd()
CODEX_SANDBOX_MODEread-only, workspace-write, danger-full-accessread-only
CODEX_APPROVAL_POLICYnever, on-failure, on-request, untrustedon-failure
CODEX_EFFORTminimal, low, medium, high, xhighSDK default
CODEX_ADDITIONAL_DIRSExtra directories (comma-separated)none
CODEX_NETWORK_ACCESSAllow network from sandboxfalse
CODEX_WEB_SEARCHdisabled, cached, livedisabled

Instructions

Env VarDescription
CODEX_INSTRUCTIONSReplaces the default instructions
CODEX_APPEND_INSTRUCTIONSAppended to the default (usually what you want)

Advanced

Env VarDescription
CODEX_PERSIST_SESSIONtrue/false — enable session resume (default: true)

Authentication

Env VarDescriptionDefault
CODEX_API_KEYOpenAI API key for this agentinherited from parent

Security

  • Sandbox defaults to read-only — the agent can't write files unless you explicitly set workspace-write or danger-full-access.
  • cwd overrides preserve agent knowledge — when the host overrides cwd, the agent's configured base directory is automatically added to additionalDirectories.
  • Security overrides narrow, never widen — per-invocation sandboxMode and approvalPolicy can only tighten (e.g., workspace-write → read-only), never loosen.
  • _reply tool respects persistence — not registered when CODEX_PERSIST_SESSION=false.
  • API keys are redacted — the factory wizard never exposes CODEX_API_KEY in generated configs.

Architecture

┌─────────────────────────────────┐
│  MCP Client                     │
│  (Claude Desktop, Cursor, etc.) │
│                                 │
│  Sees: code_reviewer,           │
│        test_writer, quick_qa    │
└──────────┬──────────────────────┘
           │ JSON-RPC / stdio
┌──────────▼──────────────────────┐
│  Codex Octopus (per instance)   │
│                                 │
│  Env: CODEX_MODEL=o3            │
│       CODEX_SANDBOX_MODE=...    │
│       CODEX_APPEND_INSTRUCTIONS │
│                                 │
│  Calls: Codex SDK thread.run()  │
└──────────┬──────────────────────┘
           │ in-process
┌──────────▼──────────────────────┐
│  Codex SDK → Codex CLI          │
│  Runs autonomously: reads files,│
│  writes code, runs commands     │
│  Returns result + thread_id     │
└─────────────────────────────────┘

Known Limitations

  • minimal effort + web_search: OpenAI does not allow web_search tools with minimal reasoning effort. Use low or higher if web search is needed.

Development

pnpm install
pnpm build       # compile TypeScript
pnpm test        # run tests (vitest)
pnpm test:coverage  # coverage report

License

ISC - Xiaolai Li

Related MCP servers

Spawn multiple specialized Claude Code agents as MCP servers, each with custom models, tools, and personalities.

16
TypeScript
ISC
View repository →

Field-verified China travel facts for foreign visitors: booking walls, hotel registration, transit.

APIs and MCP for structured public data, web research, CAPTCHA, and source-bound data cleanup.

AI copilot for WeChat Mini Program - compile-fix, size analysis, compliance. 20 tools.

View repository →

Falsification-first citation auditor: existence, metadata, and claim-support checks via MCP.

1
Python
MIT
View repository →

AI-powered native browser with 12 MCP tools. ~30 tokens per page.

5
TypeScript
MIT
View repository →