Codex connects to Provely through the CLI, the REST API. The agent does the action. Provely verifies the outcome and signs a receipt. Codex never holds the verifier credentials.

A person verified the Codex capabilities on 2026-09-05. Agent products change monthly. Re-verify before you build.

Source: integration profile codex · retrieved 2026-09-05

Which surfaces does Codex use?

SurfaceSupportDetail
MCP serverVerify at implementationtransport stdio
CLISupportedRuns through the shell tool of the agent.
SDKNot supported
REST APISupportedAny HTTP call reaches the control plane.

Which guidance files does Codex read?

The renderer writes AGENTS.md fragment from one source. A new agent needs a profile, not core code.

FormatPathMode
AGENTS.md fragmentAGENTS.mdappend
CI gate workflow.provely/ci/github-actions.ymlfragment

How is a false completion claim blocked?

EnforcementSupportDetail
Advisory guidanceSupportedThe instruction files state the rules for every agent.
Lifecycle hooksVerify at implementationNo hook events stated.
CI gateSupportedprovely verify --wait fails the pipeline unless the verdict is VERIFIED.

How do I connect Codex?

Connect Codex to Provely

  1. Install the CLI.Run npx provely --version, or download the static binary.
  2. Check the MCP support of the host.The profile marks MCP as verify at implementation. When the host runs MCP, register provely mcp. If not, use the CLI through the shell tool.
  3. Write the guidance files.Run provely init --agent codex. It writes AGENTS.md (append), .provely/ci/github-actions.yml (fragment). The guidance carries one rule: a successful tool call is not completion.
  4. Add the CI gate.Run provely verify --wait <duration> in the pipeline. The step fails unless the verdict is VERIFIED. Exit codes: 0 VERIFIED, 2 PENDING, 3 FAILED, 4 CONTRADICTED, 5 UNVERIFIABLE.
  5. Report the verdict exactly as returned.VERIFIED: "The action is verified complete. Receipt: <id>." PENDING: "The action is accepted but not yet verified. Operation: <id>."

What else does the profile state?

  • Verified 2026-09-05: Codex reads AGENTS.md. Source: https://github.com/openai/codex (AGENTS.md at the repository root; docs/config.md).
  • Checked 2026-09-05: docs/config.md was fetched. The mcp_servers table was not readable. Team knowledge: Codex reads [mcp_servers.<name>] from ~/.codex/config.toml with command and args. Verify at implementation, then add [mcp_servers.provely] by hand. TOML, so no config_path.
  • Checked 2026-09-05: docs/config.md names lifecycle hooks and the setting allow_managed_hooks_only in requirements.toml. The event names were not readable. Keep hooks at verify_at_implementation.
  • Cloud Codex tasks read the same AGENTS.md. The CI gate verifies before merge.

Codex keeps its action credentials, and no surface returns the verifier credentials to it. Read the credential boundary. An operation outlives the session that opened it. Read the API reference.

Which host versions does the profile cover?

>=0.100.0. The integrations team last verified the profile with 0.153.4 on 2026-09-05 (npm @openai/codex, published 2026-09-04).