Local Codex Bridge Example 1.0.0 - FindGoodAI

Use only with a disposable project first. This is a single-user teaching example,
not a production security boundary. Project registration sets the working
directory; it does not guarantee that Codex can only read that directory.
Use OS permissions and a dedicated account before connecting valuable projects.
Review inherited Codex configuration and external MCP integrations.

Requirements: Node.js 24 recommended; a supported Windows Codex login.
Pinned dependencies: Codex SDK 0.135.0, MCP TypeScript SDK 1.32.0, Zod 3.25.76.

Put the files directly in D:\CodexWebBridge (or another local directory).
Run npm ci --ignore-scripts.
Copy projects.example.json to projects.json.
Run node --check server.mjs, then node smoke-test.mjs (no model use).
Run node smoke-test.mjs --run-codex only when you intend to use Codex quota.
Keep writeEnabled=false until the read is verified in your local demo project.

The service uses stdio. Its stdout is reserved for MCP JSON-RPC.
Configure tunnel-client to launch node with the absolute server.mjs path.
Keep your tunnel runtime key out of source files and archives.
CODEX_HOME must match the local sign-in used by the worker.
Optional BRIDGE_CODEX_EXE points to a locally selected Codex executable.
Optional BRIDGE_MODEL selects a model supported by the local executor/account.
If an inherited model is rejected, inspect Codex's model selector or model/list
and set BRIDGE_MODEL locally. Do not assume browser model access is identical.
If a Windows workspace denies reads to CodexSandboxUsers, use an appropriate
test directory; do not remove existing protections to force a smoke test.

Six tools: list_projects, start_task, get_task_status, get_task_result,
continue_task, cancel_task. A returned job_id is acceptance, not completion.
A completed model turn is not proof that the requested file change or check
succeeded. Verify actual files, differences and check results.

Jobs are saved locally in data/jobs.json. Restart marks unfinished records
interrupted, without retrying. One active job per project per process; do not
start two service processes against the same project. Cancellation does not
undo edits. Runtime limit is ten minutes. Results are capped at 24,000 chars.
Common token masking is best effort, not comprehensive secret detection.

Editing requires writeEnabled=true in local projects.json and mode=edit.
The worker uses workspace-write for edits, read-only for analysis, disabled
web search and command network access, and approvalPolicy=never. Never means
no interactive permission escalation; it does not disable the sandbox.
For interactive approvals or live steering, implement an app-server adapter.

Full Chinese and English guide:
https://www.findgoodai.com/zh/ai-outpost/chatgpt-web-local-codex-mcp-windows-guide/
https://www.findgoodai.com/ai-outpost/chatgpt-web-local-codex-mcp-windows-guide/

Code example license: MIT. Copyright 2026 FindGoodAI.
Permission is granted, free of charge, to use, copy, modify, merge, publish,
distribute, sublicense and/or sell this example, provided this notice remains.
THE SOFTWARE IS PROVIDED AS IS, WITHOUT WARRANTY OF ANY KIND.
