LassoLassoDocs
Coding agent

Codex

Lasso can delegate the coding task to the Codex CLI. Codex runs inside a read-only sandbox, so it can read your project and propose a patch but cannot modify anything on its own.

Install the CLI

npm install -g @openai/codex
codex --version

Lasso detects the binary with which codex. Install it before starting lasso dev, or restart the dev server afterwards.

Sign in

Run codex once in a terminal and complete the login flow. Lasso inherits the credentials Codex stores for your user, so there is no separate key to configure.

Select it in Lasso

Open the model picker in the overlay toolbar. Codex appears as a group only when the binary is detected, offering GPT-5 and GPT-5-Codex.

How a request runs

codex exec \
  --json \
  --sandbox read-only \
  --skip-git-repo-check \
  --model gpt-5
  • --sandbox read-only keeps the agent from writing to your filesystem.
  • --skip-git-repo-check is required because Lasso already handles the repository trust decision for you.
  • --json streams structured events that Lasso turns into the task activity log.

Lasso passes the selected component context and expects a JSON patch proposal back, which becomes a reviewable diff. A request that has not finished within five minutes is stopped.

Permission requests

If the agent needs approval or input, Lasso pauses the task and shows the request in the overlay with Allow and Deny, then resumes the run with your answer.

Troubleshooting

  • missing field base_instructions: Codex is reading an older models cache format. Update Codex, then retry. Lasso already bypasses the repository trust check.
  • Expired MCP token: an error mentioning invalid_token for an MCP server such as mcp.canva.com means the OAuth token for that server has expired. Re-authenticate it in Codex, or remove the server from your Codex config.
  • Not listed in the picker: confirm which codex succeeds and restart lasso dev.

Next steps

Compare with Claude Code or OpenCode, or review the CLI reference.