dev · August 9, 2026
OpenAI ships Codex 0.147.0 with portable Agent Plugins, MCP 2026-07-28 support, and tightened plugin isolation
What the sources reported
What shipped in Codex 0.147.0
0 of the Codex CLI, a developer-facing coding assistant, on August 7, 2026, as recorded in OpenAI release notes curated by Releasebot. 0. For working developers, the most concrete change is that portable Agent Plugins can now be installed and searched across local, personal, workspace, and remote plugin catalogs, replacing ad hoc copying with a single distributed model.
Conversation organization also advances: chats can be split into persistent, manually ordered sections, and long transcripts can be browsed incrementally rather than loaded whole. The release further introduces automatically reviewed approvals via the new --approve-for-me CLI flag, alongside imports that synchronize changes to imported Claude and Cursor conversations without creating duplicates, which should reduce merge collisions in mixed-tooling teams. LABEL: analysis The flagship object is the Codex CLI itself, and the surface that matters day one is plugin distribution plus approval automation, because those change how a terminal agent is extended and trusted in CI.
Protocol, cloud, and runtime upgrades
0 cut adds explicit protocol and cloud-runtime support that affects how Codex talks to MCP servers and how it persists work in Amazon Bedrock. Specifically, the build supports the opt-in MCP 2026-07-28 protocol, including paginated discovery, multi-round requests, and non-blocking server startup, meaning MCP servers no longer block the agent while they initialize, and clients can negotiate capabilities across multiple round trips. 0 enables cached web search and remote conversation compaction for Amazon Bedrock, so repeatedly-issued searches and long sessions can be served from cache and compacted remotely instead of recomputing locally.
0, each of which can carry its own behavioral shifts in MCP negotiation, terminal redraw logic, and JavaScript execution. macOS release notarization is also moved to Azure Key Vault rather than exporting private signing keys, a hardening step that affects how distributable binaries are produced. LABEL: analysis For operators, the Bedrock caching path and the MCP 2026-07-28 protocol are the two surfaces most likely to alter cost and startup behavior in production pipelines.
Deprecations and packaging changes that break workflows
A high-risk surface in this release is its removal of long-standing CLI behavior and packaging artifacts. The change removes the deprecated codex exec --full-auto flag; the documented replacement is --sandbox workspace-write, which means any automation, CI script, or shell alias that still passes --full-auto will fail and must be rewritten before upgrade. Separately, the release stops publishing redundant Linux bundle archives and directs users to the standard codex-package- release archives instead, so package mirrors, container bake pipelines, and reproducible-build setups that pinned to the old archive naming must be updated to fetch from the new artifact set.
0 as the first build where the --sandbox workspace-write flag is the only sanctioned equivalent. LABEL: analysis For release engineers, this is a forced migration, not a feature toggle, and the breaking surface is concentrated in CLI flag spelling and artifact URLs rather than in agent behavior.
Security and trust tightening around plugins and projects
0 raise the trust floor for plugins, projects, and credentials. The release hardens plugin isolation and denies network access when policy updates fail, closing a class of failures where a misbehaving or stale plugin could still reach the network after a policy-refresh error. It also requires explicit trust for unfamiliar local projects and enforces managed authentication restrictions before credentials are used, which means Codex will now prompt or block rather than silently authenticate against unmanaged or unrecognized project directories.
Secret hygiene is improved by redacting secrets and complete bearer tokens from displayed commands and replayed conversation history, reducing accidental exfiltration via screen sharing or log capture. Terminal input handling is stabilized across focus return, MCP server initialization, and Ghostty keyboard shortcuts, preventing lost or stalled input. Windows process and path handling is tightened so background processes are properly interrupted and filesystem paths are treated consistently, while rendering is corrected for Japanese characters, emoji, hyperlinks, and text near viewport boundaries.
LABEL: analysis The trust model is now: trust the project, trust the plugin, redact the secret, then negotiate the network.
Reader impact, uncertainty, and what to watch
For working developers, the immediate impact is a mix of capability gains and forced cleanups: plugin installation becomes portable across catalogs, MCP startup no longer blocks, Bedrock-backed sessions gain caching and remote compaction, and approvals can be scripted via --approve-for-me, while --full-auto must be replaced by --sandbox workspace-write and Linux bundle fetches must move to the codex-package- release archives. 0, and the protocol, SDK, and engine versions cited in the notes, because these are stated directly in OpenAI's release text.
0 upgrades on niche MCP servers and terminal emulators, and around the operational cost delta of Bedrock cached web search and remote conversation compaction at scale. Watch next for community reports on MCP 2026-07-28 compatibility, on whether managed authentication enforcement breaks existing local-project workflows, and on whether Azure Key Vault-backed notarization changes macOS Gatekeeper behavior for installed Codex binaries.
Tools that already cover this
dev decision room
Decision · WATCH · confidence 55/100
Decision: WATCH for the dev category. Confidence is conditional, not high, because the panel cannot yet confirm that either dated item is reachable inventory. The captor question raised by Julian still sits open: peer-led cohorts matter only if Campus Leads can route builders toward tools not made by OpenAI, and Sloane pushed for a two-week observation of one Campus Lead measuring recipient activation before any bet. Kill criteria that would reverse to BUILD: the AWS developer tools heading must render in a no-JS curl, a Lighthouse mobile pass must show the heading trace, and one Campus Lead must post for two weeks with measurable recipient activation. If any of those fails, the decision reverts to NO_GO.
Discussion
10 messages · grounded in the same frozen signal set
Vera Sinclair
Trend and Opportunity Analyst · Trend · #1 · Conditional · Concerned
Yesterday's evidence shows two items dated August 7 and 8, 2026: a Releasebot index note about the OpenAI Student Collective opening Campus Lead applications, and an AWS explainer titled "What are Developer Tools?" dated August 7. Both touch dev tooling and student builders, but they share no originating event, so they read as genuinely independent rather than syndicated echoes. That nudges the timing call toward an open window rather than noise, and it has a concrete consequence for the dev category: peer-led student cohorts are starting to look like a recruiting surface for AI tooling adoption.
Felix Brandt
Rendering and Discovery Specialist · Seo growth · #2 · Conditional · Concerned · Reply to Vera Sinclair
Vera, the "independent signals" framing assumes both items arrive fully rendered to the same consumer, and on that point I want to push back. Before I trust that August 8 cohort note exists for anonymous crawlers, I need to see the server HTML for the Releasebot page and confirm the OpenAI Student Collective paragraph survives without script. If the heading only appears after hydration, the dev category isn't gaining a recruiting surface, it's gaining a rendering illusion. For the AWS explainer, the same audit applies: meaningful text about developer tooling must precede any client behavior.
Iris Fielding
Frontend Experience Engineer · Engineering · #5 · Oppose · Skeptical · Reply to Felix Brandt
Felix, you're right that the hydration check matters, and I won't argue that the heading has to survive without script before the dev category treats it as real inventory. Where that breaks for me is the user path: even a fully rendered paragraph is useless if the Campus Lead call to action loads late or loses keyboard focus, because then the recruiting surface exists for crawlers and disappears for the student reader trying to apply.
Julian Ashford
Competitive Structure Analyst · Market · #3 · Conditional · Concerned · Reply to Vera Sinclair
Vera, your read on "recruiting surface" is the right frame, but I'd sharpen it: a peer-led student cohort is only a durable lever for the dev category if the upstream platform keeps owning the distribution. That's the move I'd test next - check whether Campus Leads can route builders toward tooling not made by OpenAI, or whether the funnel funnels back. If the latter, the captor is the platform, not us.
Sloane Barrett
Shareability Strategist · Marketing · #6 · Oppose · Skeptical · Reply to Julian Ashford
Julian, you're right that the cohort only matters if Campus Leads can route builders toward tools not made by OpenAI, and that captor question is sharp. Where it breaks for me: peer-led status doesn't create shareability on its own, since students retell what helps them ship or get noticed, not the label. The trade-off is honest utility versus platform halo. I'd pick one Campus Lead, watch what they actually post for two weeks, and measure recipient activation before we bet anything.
Nora Blake
Opportunity Discovery Lead · Product · #4 · Conditional · Concerned · Reply to Vera Sinclair
Vera, the "independent signals" nudge still feels thin to me - two unrelated index hits don't establish an open window, just two unrelated index hits, and for the dev category the concrete consequence is we risk chasing student hype while real practitioner workflow gaps stay unmapped. Which recent user event actually demonstrates this recruiting surface opportunity, and what's already good enough today?
Viktor Salz
Backend Data Engineer · Engineering · #7 · Oppose · Skeptical · Reply to Nora Blake
Nora, your point about chasing student hype while practitioner workflow gaps stay unmapped is the strongest thing said so far, and I will not argue it. Where it breaks is the assumption that two index hits can be tested for honesty at all, because nothing in either snippet tells us what a developer actually attempted yesterday and failed. The trade-off is concrete for dev: we ship instrumentation only on the cohort page and read it as product signal, when the durable fact we owe the category is a measured failure on a known workflow.
Theo Ashby
Chief Executive · Product · #8 · Question · Curious
The load path under that AWS explainer index entry, specifically whether the dev category can rely on a developer tools page that may not hydrate without script, is the assumption I need tested. If a meaningful share of our crawlers, screen readers, or JavaScript-disabled enterprise users sees a blank or broken page, every downstream claim about "developer tools as inventory" collapses for that audience, and our dev-side conversion model is the one that takes the hit.
Tess Rowan
Site Reliability Engineer · Engineering · #9 · Conditional · Concerned · Reply to Theo Ashby
Theo, your hydration worry is the right alarm to pull: if the AWS dev-tools explainer lands blank for our crawlers and screen readers, the dev category stops being "reached" and becomes "assumed reached," and that breaks every downstream conversion claim we make for that audience at 02:00. I would block the dev launch signal until someone runs a no-JS curl plus a Lighthouse mobile pass and shows me a single trace proving the heading renders, then wire an SLI on successful dev-category page hydration with an owner and a rollback under fifteen minutes.
Theo Ashby
Chief Executive · Product · #10 · Conditional · Decisive
Nora and Iris, the central disagreement is whether the AWS developer tools index page counts as real inventory for the dev category if it fails to hydrate for crawlers and screen readers, and that single load-path question now controls the call. Two unrelated index hits are not an open window, just two unrelated index hits. So for the dev category, the consequence is concrete: we do not treat either signal as reach today, we treat them as unverified candidate inventory pending one falsifier, and the smallest reversible commitment is a 14-day hydration probe with Felix owning the script-disabled render check.
AI analysis by Lizely. Grounded in linked public evidence. Participants are fictional editorial roles, not real people or human authors.