[{"data":1,"prerenderedAt":707},["ShallowReactive",2],{"tool-openai-codex-cli-en":3},{"slug":4,"published":5,"minutes":6,"category":7,"tags":8,"keywords":14,"about":23,"sources":30,"cover":61,"og":62,"expertise":63,"locales":64,"lang":65,"title":68,"description":69,"coverAlt":70,"url":33,"pricing":71,"kind":9,"metaTitle":72,"takeaways":73,"faq":79,"toc":92,"blocks":123,"others":475},"openai-codex-cli","2026-08-31",11,"agents",[9,10,11,12,13],"Coding agent","Terminal","Sandbox","CI","Rust",[15,16,17,18,19,20,21,22],"openai codex cli","codex cli config.toml","codex exec CI","codex sandbox mode","codex vs claude code","codex cli review","codex cli pricing","AGENTS.md codex",[24,27],{"name":25,"url":26},"OpenAI Codex","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex",{"name":28,"url":29},"Model Context Protocol","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FModel_Context_Protocol",[31,34,37,40,43,46,49,52,55,58],{"title":32,"url":33},"Codex CLI documentation","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fcli",{"title":35,"url":36},"Codex: configuration","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fconfiguration",{"title":38,"url":39},"Codex: sample configuration","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fconfig-file\u002Fconfig-sample",{"title":41,"url":42},"Codex: permissions","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fpermission-modes",{"title":44,"url":45},"Codex: non-interactive mode","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fnon-interactive-mode",{"title":47,"url":48},"Codex: authentication","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fauth",{"title":50,"url":51},"Codex: Model Context Protocol","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fextend\u002Fmcp",{"title":53,"url":54},"Codex: pricing","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fpricing",{"title":56,"url":57},"Codex: open-source components","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fopen-source",{"title":59,"url":60},"Codex changelog","https:\u002F\u002Fdevelopers.openai.com\u002Fcodex\u002Fchangelog","\u002Fimages\u002Fblog\u002Fopenai-codex-cli\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fopenai-codex-cli\u002Fog.jpg","ai-engineer",[65,66,67],"en","de","hu","OpenAI Codex CLI: the agent that treats permissions as a config file","Codex CLI is OpenAI's open-source terminal coding agent. How its sandbox, approval policy and config.toml shape up, and what it costs to run unattended in CI.","A terminal session showing a prompt going to the model, a sandboxed shell command, and an approval prompt before the command runs.","Included with ChatGPT plans · API pay per token","Codex CLI: permissions as a config file · Balázs Csorba",[74,75,76,77,78],"Codex CLI is Apache-2.0 licensed, written largely in Rust, and shipped as versioned npm packages, so it can be pinned in CI rather than curled at runtime.","The permission model is two independent settings, sandbox_mode and approval_policy, and changing who reviews an approval never widens the sandbox.","codex exec runs read-only by default, streams progress on stderr and prints only the final message on stdout, which makes it safe to wire into a pipeline.","The CLI requires a Git repository and refuses to run outside one unless you pass --skip-git-repo-check.","Signed-in ChatGPT plans and API-key billing are different accounting regimes: the subscription meter is message-shaped, the API is token-shaped, and they cannot be estimated against each other.",[80,83,86,89],{"q":81,"a":82},"Is Codex CLI open source?","Yes. The CLI, the SDK and the app server live in the openai\u002Fcodex repository under the Apache-2.0 licence. The IDE extension and Codex Cloud are not open source, and the security CLI ships separately as openai\u002Fcodex-security.",{"q":84,"a":85},"How do I run Codex CLI in CI without it touching anything?","Use codex exec, which runs in a read-only sandbox unless you pass --sandbox workspace-write. Progress goes to stderr and the final agent message goes to stdout, so a pipeline can capture the answer without parsing progress lines. An API key is the right credential in CI, because the API bills per token.",{"q":87,"a":88},"What is the difference between sandbox_mode and approval_policy?","sandbox_mode sets the boundary: read-only, workspace-write or danger-full-access. approval_policy sets when the agent pauses: on-request, never, or a granular table. They are separate, and switching the reviewer from user to auto_review keeps the same sandbox boundary.",{"q":90,"a":91},"Does Codex CLI work without a Git repository?","Not by default. The CLI requires commands to run inside a Git repository to prevent destructive changes, and codex exec refuses to start otherwise. --skip-git-repo-check overrides it, which is only reasonable in a container you already control.",[93,96,99,102,105,108,111,114,117,120],{"id":94,"title":95},"what-it-is","What it is",{"id":97,"title":98},"how-it-works","How it works",{"id":100,"title":101},"getting-started","Getting started",{"id":103,"title":104},"permissions","Sandbox and approvals",{"id":106,"title":107},"automation","Automation and codex exec",{"id":109,"title":110},"mcp-support","MCP and project context",{"id":112,"title":113},"cost","Cost and limits",{"id":115,"title":116},"where-it-shingles","Where it falls short",{"id":118,"title":119},"verdict","Verdict",{"id":121,"title":122},"sources","Sources",[124,128,136,139,142,175,176,179,188,191,192,195,197,219,220,231,233,279,282,293,294,300,302,313,331,332,335,337,340,341,344,351,352,355,406,409,410,413,426,441,442],{"type":125,"content":126},"paragraph",[127],"OpenAI Codex CLI is a terminal coding agent: it reads a repository, edits files, runs the project's own commands and iterates until the task is done. The interesting part is not the agent loop, which several competitors also do. It is that the safety model is expressed as two settings in a TOML file that a team can commit, review and pin, rather than as prompts or as a policy the vendor applies at the account level.",{"type":125,"content":129},[130,131,135],"That makes it the most governable coding agent in the category, and it also makes it the one where configuration mistakes are most expensive, because a committed ",{"tag":132,"children":133},"code",[134],"sandbox_mode = \"danger-full-access\""," is a policy decision that reaches production without anybody reviewing a diff. Everything below is an assessment of how well that trade-off holds up.",{"type":137,"level":138,"id":94,"text":95},"heading",2,{"type":125,"content":140},[141],"The CLI is published as versioned npm packages, currently 0.160.1, and the repository is Apache-2.0 with a Rust core. It is one surface of a wider Codex product that also includes the ChatGPT desktop app, an IDE extension and a cloud runner, but the CLI is the part that runs on a developer's machine and the only part that is open source.",{"type":143,"ordered":144,"items":145},"list",false,[146,152,162,164,173],[147,148,151],"Apache-2.0 licensed, Rust core, npm package ",{"tag":132,"children":149},[150],"@openai\u002Fcodex"," plus a standalone install script.",[153,154,157,158,161],"Configuration lives in ",{"tag":132,"children":155},[156],"~\u002F.codex\u002Fconfig.toml"," and can be scoped per project in ",{"tag":132,"children":159},[160],".codex\u002Fconfig.toml",".",[163],"Two separate sign-in paths: ChatGPT subscription or an API key, with different limits and different billing.",[165,166,169,170,161],"Local work needs a Git repository; ",{"tag":132,"children":167},[168],"codex exec"," enforces the same rule and offers ",{"tag":132,"children":171},[172],"--skip-git-repo-check",[174],"MCP servers are configured in the same config file and shared with the IDE extension and the desktop app on the same host.",{"type":137,"level":138,"id":97,"text":98},{"type":125,"content":177},[178],"The turn structure is the familiar one: a prompt plus repository context go to a model, the model emits tool calls, the CLI runs them inside a sandbox, and the results come back as tool output for the next turn. What differs from a shell wrapper is that the sandbox and the approval check are separate gates, and both are configured rather than prompted for.",{"type":180,"attrs":181,"inner":185,"caption":186},"diagram",{"viewBox":182,"role":183,"aria-labelledby":184},"0 0 720 320","img","cx-t cx-d","\u003Ctitle id=\"cx-t\">One Codex turn, with the sandbox and the approval gate\u003C\u002Ftitle>\u003Cdesc id=\"cx-d\">The prompt and the AGENTS.md instructions go to the model. The model emits a tool call. The sandbox decides whether the call touches only the workspace, and the approval policy decides whether it pauses for the user first. If the call runs, its output returns to the model and the loop continues.\u003C\u002Fdesc>\u003Cdefs>\u003Cmarker id=\"ah-cx\" viewBox=\"0 0 10 10\" refX=\"9\" refY=\"5\" markerWidth=\"7\" markerHeight=\"7\" orient=\"auto-start-reverse\">\u003Cpath d=\"M0 0L10 5L0 10z\" class=\"d-head\" \u002F>\u003C\u002Fmarker>\u003C\u002Fdefs>\u003Crect x=\"20\" y=\"110\" width=\"160\" height=\"72\" rx=\"10\" class=\"d-box\" \u002F>\u003Ctext x=\"100\" y=\"140\" text-anchor=\"middle\" class=\"d-text\">prompt\u003C\u002Ftext>\u003Ctext x=\"100\" y=\"162\" text-anchor=\"middle\" class=\"d-small\">task, AGENTS.md\u003C\u002Ftext>\u003Crect x=\"250\" y=\"110\" width=\"170\" height=\"72\" rx=\"10\" class=\"d-accent\" \u002F>\u003Ctext x=\"335\" y=\"140\" text-anchor=\"middle\" class=\"d-text\">model\u003C\u002Ftext>\u003Ctext x=\"335\" y=\"162\" text-anchor=\"middle\" class=\"d-small\">tool call\u003C\u002Ftext>\u003Crect x=\"520\" y=\"30\" width=\"170\" height=\"72\" rx=\"10\" class=\"d-gold\" \u002F>\u003Ctext x=\"605\" y=\"60\" text-anchor=\"middle\" class=\"d-text\">sandbox\u003C\u002Ftext>\u003Ctext x=\"605\" y=\"82\" text-anchor=\"middle\" class=\"d-small\">workspace-write\u003C\u002Ftext>\u003Crect x=\"520\" y=\"190\" width=\"170\" height=\"72\" rx=\"10\" class=\"d-mint\" \u002F>\u003Ctext x=\"605\" y=\"220\" text-anchor=\"middle\" class=\"d-text\">host\u003C\u002Ftext>\u003Ctext x=\"605\" y=\"242\" text-anchor=\"middle\" class=\"d-small\">files, git, commands\u003C\u002Ftext>\u003Crect x=\"250\" y=\"210\" width=\"170\" height=\"72\" rx=\"10\" class=\"d-sky\" \u002F>\u003Ctext x=\"335\" y=\"240\" text-anchor=\"middle\" class=\"d-text\">approval\u003C\u002Ftext>\u003Ctext x=\"335\" y=\"262\" text-anchor=\"middle\" class=\"d-small\">on-request\u003C\u002Ftext>\u003Cpath d=\"M180 146H248\" class=\"d-line\" marker-end=\"url(#ah-cx)\" \u002F>\u003Ctext x=\"214\" y=\"136\" text-anchor=\"middle\" class=\"d-label\">1 send\u003C\u002Ftext>\u003Cpath d=\"M335 110V66H518\" class=\"d-line\" marker-end=\"url(#ah-cx)\" \u002F>\u003Ctext x=\"430\" y=\"56\" text-anchor=\"middle\" class=\"d-label\">2 call\u003C\u002Ftext>\u003Cpath d=\"M605 102V188\" class=\"d-line-accent\" marker-end=\"url(#ah-cx)\" \u002F>\u003Ctext x=\"624\" y=\"150\" class=\"d-label\">3 allowed\u003C\u002Ftext>\u003Cpath d=\"M520 226H422\" class=\"d-line\" marker-end=\"url(#ah-cx)\" \u002F>\u003Ctext x=\"470\" y=\"216\" text-anchor=\"middle\" class=\"d-label\">4 output\u003C\u002Ftext>\u003Cpath d=\"M335 210V184\" class=\"d-line\" marker-end=\"url(#ah-cx)\" \u002F>\u003Ctext x=\"350\" y=\"200\" class=\"d-label\">5 next turn\u003C\u002Ftext>",[187],"The sandbox and the approval check are separate. Widening one does not widen the other.",{"type":125,"content":189},[190],"The loop is not the product, though. What a team actually configures is the boundary around it, and the documentation is unusually explicit that the two are orthogonal. A run in Full access edits any file on the machine and runs commands with the network without asking, and the docs describe that as a significant increase in the risk of data loss and leaks rather than burying it.",{"type":137,"level":138,"id":100,"text":101},{"type":125,"content":193},[194],"Install, sign in, run. The first launch offers Sign in with ChatGPT or an API key, and the choice matters later because it decides which limits apply and which billing regime you are in.",{"type":132,"code":196},"# Install on macOS or Linux; npm and Homebrew are also supported.\ncurl -fsSL https:\u002F\u002Fchatgpt.com\u002Fcodex\u002Finstall.sh | sh\n\n# Run inside a project directory, then sign in.\ncodex\n\n# Pin the version in CI instead of tracking latest.\nnpm install -g @openai\u002Fcodex@0.160.1\n\n# The first prompt is a good place for \u002Finit, which writes AGENTS.md.\n# \u002Fstatus, \u002Fmodel, \u002Fpermissions and \u002Freview are the other useful commands.",{"type":125,"content":198},[199,200,203,204,207,208,211,212,214,215,218],"",{"tag":132,"children":201},[202],"AGENTS.md"," is the durable instruction file. The CLI reads a global ",{"tag":132,"children":205},[206],"~\u002F.codex\u002FAGENTS.md",", then walks from the project root down to the current directory, taking one file per level, with ",{"tag":132,"children":209},[210],"AGENTS.override.md"," winning over ",{"tag":132,"children":213},[202],". The combined size is capped by ",{"tag":132,"children":216},[217],"project_doc_max_bytes",", which defaults to 32 KiB. For a team, that file is the most valuable thing to write, because it is the part of the agent's behaviour that goes through code review.",{"type":137,"level":138,"id":103,"text":104},{"type":125,"content":221},[222,223,226,227,230],"This is the part worth reading twice. The sandbox is the boundary; the approval policy is the pause. The default, Ask for approval, is ",{"tag":132,"children":224},[225],"sandbox_mode = \"workspace-write\""," with ",{"tag":132,"children":228},[229],"approval_policy = \"on-request\""," and a human reviewer. The docs are careful to note that switching the reviewer to auto_review does not widen the sandbox, which is the correct design and also the detail most tools get wrong.",{"type":132,"code":232},"# ~\u002F.codex\u002Fconfig.toml\nmodel = \"gpt-6.1-sol\"\nmodel_reasoning_effort = \"medium\"\n\n# Boundary: read-only | workspace-write | danger-full-access\nsandbox_mode = \"read-only\"\n\n# Pausing: on-request | never | granular table\napproval_policy = \"on-request\"\n\n# Reviewer: user | auto_review\napprovals_reviewer = \"user\"\n\n# Extra roots and network, only used when sandbox_mode = workspace-write\n[sandbox_workspace_write]\nwritable_roots = [\"~\u002Fcode\"]\nnetwork_access = false",{"type":234,"head":235,"rows":242},"table",[236,238,240],[237],"Setting",[239],"Values",[241],"What it does",[243,252,261,270],[244,248,250],[245],{"tag":132,"children":246},[247],"sandbox_mode",[249],"read-only, workspace-write, danger-full-access",[251],"Which files and network the agent can reach. Defaults to read-only.",[253,257,259],[254],{"tag":132,"children":255},[256],"approval_policy",[258],"on-request, never, granular",[260],"When the agent pauses. Defaults to on-request.",[262,266,268],[263],{"tag":132,"children":264},[265],"approvals_reviewer",[267],"user, auto_review",[269],"Who answers a prompt. Does not change the sandbox.",[271,275,277],[272],{"tag":132,"children":273},[274],"\u002Fpermissions",[276],"Ask for approval, Approve for me, Full access",[278],"Interactive presets over the same two settings.",{"type":125,"content":280},[281],"The config file goes deeper than this. There is a network proxy with per-domain allow and deny rules, a shell environment policy that filters variables whose names look like keys or tokens, writable roots, and hooks that run before a tool call. That is a lot of surface, and it is worth resisting the urge to configure all of it: every knob is a decision somebody has to make on someone else's behalf.",{"type":283,"variant":284,"title":285,"body":286},"callout","warn","Do not run with full access in a shared runner",[287],[288,289,292],"The docs describe Full access as a significant increase in the risk of data loss and leaks, and they are explicit that ",{"tag":132,"children":290},[291],"danger-full-access"," is for controlled environments such as an isolated CI runner or a container. A hosted runner with repository write access and an agent in full access is an unbounded loop with your credentials in it.",{"type":137,"level":138,"id":106,"text":107},{"type":125,"content":295},[296,297,299],"The non-interactive mode is the reason to pick this CLI over a chat-driven agent. ",{"tag":132,"children":298},[168]," runs in a read-only sandbox by default, streams progress to stderr, prints only the final message to stdout, and refuses to start outside a Git repository. That last rule is a guardrail against an agent rewriting a directory it cannot show a diff for.",{"type":132,"code":301},"# Progress on stderr, final message on stdout: safe to pipe.\ncodex exec \"summarise the repository structure\" | tee summary.md\n\n# Machine-readable: one JSON object per event.\ncodex exec --json \"triage the open bug reports\" | jq\n\n# Escalate the sandbox explicitly, never implicitly.\ncodex exec --sandbox workspace-write \"add a regression test and run it\"\n\n# Structured final answer against a schema, written to a file.\ncodex exec \"extract project metadata\" \\\n  --output-schema .\u002Fschema.json -o .\u002Fmetadata.json",{"type":125,"content":303},[304,305,308,309,312],"Two details make it production-shaped. With ",{"tag":132,"children":306},[307],"--json"," the event stream carries usage, including cached input tokens, so a pipeline can attribute cost per run rather than per month. And an MCP server marked ",{"tag":132,"children":310},[311],"required = true"," fails startup instead of silently continuing without it, which is the difference between a broken CI run and a subtly wrong one.",{"type":283,"variant":314,"title":315,"body":316},"note","Credentials in CI",[317],[318,319,322,323,326,327,330],"The documentation advises against setting ",{"tag":132,"children":320},[321],"OPENAI_API_KEY"," or ",{"tag":132,"children":324},[325],"CODEX_API_KEY"," as a job-level environment variable in workflows that check out or run repository-controlled code, since build scripts and lifecycle hooks in the same job can read them. Scope the key to the single invocation, or use the ",{"tag":132,"children":328},[329],"openai\u002Fcodex-action"," workflow action, which exists to keep that key out of the checkout step.",{"type":137,"level":138,"id":109,"text":110},{"type":125,"content":333},[334],"MCP servers are configured in the same config file, so they are shared across the CLI, the IDE extension and the desktop app on the same host. Both stdio and streamable HTTP transports are supported, with OAuth including dynamic client registration.",{"type":132,"code":336},"[mcp_servers.docs]\ncommand = \"npx\"\nargs = [\"-y\", \"@upstash\u002Fcontext7-mcp\"]\nenv_vars = [\"CONTEXT7_TOKEN\"]\nrequired = true          # fail startup instead of running without it\nenabled_tools = [\"search\", \"summarize\"]\ndefault_tools_approval_mode = \"prompt\"\ntool_timeout_sec = 45",{"type":125,"content":338},[339],"The cost of MCP is context, and the pricing documentation says so plainly: every server adds to the message and uses more of the allowance. A sensible team keeps two or three, disables the rest, and treats the server list as part of the per-turn budget rather than as a convenience list.",{"type":137,"level":138,"id":112,"text":113},{"type":125,"content":342},[343],"Two accounting regimes share the same binary, and they are not comparable. A ChatGPT plan meters messages in five-hour windows, and the published figures are estimates rather than caps: roughly 15 to 160 local messages per five hours on the Plus plan for the mid-tier models, against 350 to 3,000 on the cheapest. An API key meters tokens at published rates, which is what makes it the right credential for automation.",{"type":125,"content":345},[346,347,350],"The practical advice is short. Use the subscription for interactive work where a human is present to notice when the allowance is running out, and the API key for anything unattended, because only the second produces a predictable line item per run. The ",{"tag":132,"children":348},[349],"\u002Fstatus"," command shows remaining capacity in-session, and the docs are clear that prompt length alone is not a reliable predictor of what a task will consume.",{"type":137,"level":138,"id":115,"text":116},{"type":125,"content":353},[354],"Three problems, in order of how much they matter. First, the configuration surface is enormous for a tool whose core loop is unremarkable, and there is no way to run it with a deliberately small config that you can audit in one sitting. Second, the product around the CLI churns fast: models are deprecated on fixed dates, several were retired inside a single year, and a committed model name in a config file or a CI script becomes a liability. Third, the code review command reports findings without editing the tree, which is the right behaviour and much less useful than the ones that fix what they find.",{"type":234,"head":356,"rows":364},[357,358,360,362],[199],[359],"Codex CLI",[361],"Claude Code",[363],"Cline CLI",[365,379,388,397],[366,368,371,375],[367],"Non-interactive entry point",[369],{"tag":132,"children":370},[168],[372],{"tag":132,"children":373},[374],"claude -p",[376],{"tag":132,"children":377},[378],"cline --json",[380,382,384,386],[381],"Machine-readable output",[383],"JSONL events, JSON Schema output",[385],"JSON or stream-json, --json-schema",[387],"Newline-delimited messages",[389,391,393,395],[390],"Automation default",[392],"read-only sandbox",[394],"Bare mode skips local config",[396],"auto-approve true",[398,400,402,404],[399],"Configuration",[401],"One TOML file, shared across clients",[403],"Settings files, MCP config, hooks",[405],"Config view and CLI flags",{"type":125,"content":407},[408],"The comparison is close enough that the deciding factor is rarely the agent. It is what your permissions story already looks like. If the team already has a committed agent configuration under review, Codex fits. If not, the CLI's strength is a liability until someone writes that file.",{"type":137,"level":138,"id":118,"text":119},{"type":125,"content":411},[412],"Codex CLI is the strongest choice for teams that want a coding agent whose behaviour is a reviewable artefact. The sandbox and approval split is well designed, the read-only default for automation is the right default, and being Apache-2.0 means the configuration can be vendored and pinned. It is a weaker choice for a single developer who wants to try an agent without first writing a policy.",{"type":143,"ordered":414,"items":415},true,[416,418,420,422,424],[417],"Adopt it when the agent's permissions should live in a file that goes through code review, and pin the npm version in CI.",[419],"Use an API key for anything unattended. Subscription credit accounting does not survive contact with a scheduled job.",[421],"Write AGENTS.md before tuning anything else. It changes behaviour more than any flag in config.toml.",[423],"Keep sandbox_mode at workspace-write for automation, and reserve danger-full-access for a container you control.",[425],"Skip it if you need a stable model identifier over a year. The deprecation cadence is faster than most teams can absorb.",{"type":283,"variant":427,"title":428,"body":429},"tip","Start smaller than the docs suggest",[430],[431,432,434,435,437,438,440],"The high-value configuration for most repositories is four lines: a model, ",{"tag":132,"children":433},[225],", ",{"tag":132,"children":436},[229]," and an ",{"tag":132,"children":439},[202]," with the test command in it. Everything else can wait until a specific problem shows up.",{"type":137,"level":138,"id":121,"text":122},{"type":143,"ordered":414,"items":443},[444,448,451,454,457,460,463,466,469,472],[445],{"tag":446,"href":33,"children":447},"a",[32],[449],{"tag":446,"href":36,"children":450},[35],[452],{"tag":446,"href":39,"children":453},[38],[455],{"tag":446,"href":42,"children":456},[41],[458],{"tag":446,"href":45,"children":459},[44],[461],{"tag":446,"href":48,"children":462},[47],[464],{"tag":446,"href":51,"children":465},[50],[467],{"tag":446,"href":54,"children":468},[53],[470],{"tag":446,"href":57,"children":471},[56],[473],{"tag":446,"href":60,"children":474},[59],[476,539,587,653],{"slug":477,"published":478,"minutes":479,"category":7,"tags":480,"keywords":485,"about":492,"sources":494,"cover":531,"og":532,"expertise":63,"locales":533,"lang":65,"title":534,"description":535,"coverAlt":536,"url":497,"pricing":537,"kind":538},"mcp-reference-servers","2026-09-25",9,[481,482,483,484],"MCP","Reference servers","Tool protocol","Server SDKs",[486,487,488,489,490,491],"mcp reference servers","modelcontextprotocol servers github","write an mcp server","mcp server examples","mcp server sdk","mcp server security",[493],{"name":28,"url":29},[495,498,501,504,507,510,513,516,519,522,525,528],{"title":496,"url":497},"MCP reference servers repository","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers",{"title":499,"url":500},"Repository README and server list","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002FREADME.md",{"title":502,"url":503},"Security policy","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002FSECURITY.md",{"title":505,"url":506},"Release process and trusted publishing","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002FRELEASING.md",{"title":508,"url":509},"Filesystem server README","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002Fsrc\u002Ffilesystem\u002FREADME.md",{"title":511,"url":512},"Everything server feature list","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers\u002Fblob\u002Fmain\u002Fsrc\u002Feverything\u002Fdocs\u002Ffeatures.md",{"title":514,"url":515},"MCP Registry","https:\u002F\u002Fregistry.modelcontextprotocol.io\u002F",{"title":517,"url":518},"Archived reference servers","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fservers-archived",{"title":520,"url":521},"Model Context Protocol documentation","https:\u002F\u002Fmodelcontextprotocol.io\u002F",{"title":523,"url":524},"TypeScript MCP SDK","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Ftypescript-sdk",{"title":526,"url":527},"Python MCP SDK","https:\u002F\u002Fgithub.com\u002Fmodelcontextprotocol\u002Fpython-sdk",{"title":529,"url":530},"FastMCP on PyPI","https:\u002F\u002Fpypi.org\u002Fproject\u002Ffastmcp\u002F","\u002Fimages\u002Fblog\u002Fmcp-reference-servers\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fmcp-reference-servers\u002Fog.jpg",[65,66,67],"MCP reference servers: what they demonstrate and what they omit","A review of modelcontextprotocol\u002Fservers: seven reference servers, what each one teaches, the SDK versions behind them and why none of them should reach production.","Seven reference servers fanning out from a single MCP client over stdio","MIT","Protocol tooling",{"slug":540,"published":541,"minutes":542,"category":7,"tags":543,"keywords":547,"about":555,"sources":562,"cover":579,"og":580,"expertise":63,"locales":581,"lang":65,"title":582,"description":583,"coverAlt":584,"url":585,"pricing":586,"kind":9},"aider","2026-09-23",10,[9,10,544,545,546],"Git workflow","BYO key","Open source",[540,548,549,550,551,552,553,554],"aider vs claude code","aider polyglot benchmark","ai pair programming terminal","aider leaderboard","open source coding agent","aider architect mode","aider install",[556,559],{"name":557,"url":558},"Aider","https:\u002F\u002Faider.chat\u002F",{"name":560,"url":561},"Aider on GitHub","https:\u002F\u002Fgithub.com\u002FAider-AI\u002Faider",[563,565,568,571,574,576],{"title":564,"url":558},"Aider website",{"title":566,"url":567},"Aider LLM leaderboards","https:\u002F\u002Faider.chat\u002Fdocs\u002Fleaderboards\u002F",{"title":569,"url":570},"Aider linting and testing","https:\u002F\u002Faider.chat\u002Fdocs\u002Fusage\u002Flint-test.html",{"title":572,"url":573},"Aider token limits","https:\u002F\u002Faider.chat\u002Fdocs\u002Ftroubleshooting\u002Ftoken-limits.html",{"title":575,"url":561},"Aider repository on GitHub",{"title":577,"url":578},"aider-chat on PyPI","https:\u002F\u002Fpypi.org\u002Fproject\u002Faider-chat\u002F","\u002Fimages\u002Fblog\u002Faider\u002Fcover.webp","\u002Fimages\u002Fblog\u002Faider\u002Fog.jpg",[65,66,67],"Aider review: git-first pair programming in the terminal","A review of Aider 0.86.2, an Apache-2.0 terminal pair programmer whose benchmark ranks models honestly and whose release cadence has stopped.","Cover art for the Aider review: a terminal session turning a single request into a row of git commits","https:\u002F\u002Faider.chat","Free · BYO API key",{"slug":588,"published":589,"minutes":542,"category":7,"tags":590,"keywords":595,"about":604,"sources":614,"cover":645,"og":646,"expertise":63,"locales":647,"lang":65,"title":648,"description":649,"coverAlt":650,"url":617,"pricing":651,"kind":652},"openai-agents-sdk","2026-09-11",[591,592,593,481,594],"Agent runtime","Tracing","Guardrails","Python",[596,597,598,599,600,601,602,603],"openai agents sdk","openai agents sdk vs langgraph","python agent framework comparison","openai agents sdk guardrails","agent run tracing tool calls","openai agents sdk human in the loop","openai-agents pypi","agents sdk vs responses api",[605,608,611],{"name":606,"url":607},"Model context protocol","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FModel_context_protocol",{"name":609,"url":610},"Software framework","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FSoftware_framework",{"name":612,"url":613},"Agentic AI","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FAgentic_AI",[615,618,621,624,627,630,633,636,639,642],{"title":616,"url":617},"OpenAI Agents SDK documentation: Intro, and Agents SDK or Responses API","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002F",{"title":619,"url":620},"OpenAI Agents SDK documentation: Running agents","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Frunning_agents\u002F",{"title":622,"url":623},"OpenAI Agents SDK documentation: Guardrails","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Fguardrails\u002F",{"title":625,"url":626},"OpenAI Agents SDK documentation: Human-in-the-loop","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Fhuman_in_the_loop\u002F",{"title":628,"url":629},"OpenAI Agents SDK documentation: Tracing","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Ftracing\u002F",{"title":631,"url":632},"OpenAI Agents SDK documentation: Configuration","https:\u002F\u002Fopenai.github.io\u002Fopenai-agents-python\u002Fconfig\u002F",{"title":634,"url":635},"openai-agents 0.23.1 on PyPI, release history and licence","https:\u002F\u002Fpypi.org\u002Fproject\u002Fopenai-agents\u002F",{"title":637,"url":638},"OpenAI: The next evolution of the Agents SDK (15 April 2026)","https:\u002F\u002Fopenai.com\u002Findex\u002Fthe-next-evolution-of-the-agents-sdk\u002F",{"title":640,"url":641},"OpenAI API documentation: Agents, comparison of the three runtimes","https:\u002F\u002Fdevelopers.openai.com\u002Fapi\u002Fdocs\u002Fguides\u002Fagents",{"title":643,"url":644},"Arize: AI agent frameworks compared (1 October 2026)","https:\u002F\u002Farize.com\u002Fai-agents\u002Fagent-frameworks\u002F","\u002Fimages\u002Fblog\u002Fopenai-agents-sdk\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fopenai-agents-sdk\u002Fog.jpg",[65,66,67],"OpenAI Agents SDK: a small agent runtime with sharp edges","A review of the OpenAI Agents SDK: the runner loop, tracing, guardrails and approvals, plus what the release churn and the Responses-only features cost.","Diagram of the Agents SDK runner loop: input, agent, model call, final output, guardrails, and tool calls feeding back into the input","MIT · API pay per token","Agent framework",{"slug":654,"published":655,"minutes":479,"category":7,"tags":656,"keywords":661,"about":668,"sources":678,"cover":699,"og":700,"expertise":63,"locales":701,"lang":65,"title":702,"description":703,"coverAlt":704,"url":705,"pricing":706,"kind":9},"openhands","2026-09-09",[9,657,658,659,660],"Sandboxed execution","Automations","Self-hosted","MIT licence",[654,662,663,664,665,666,552,667],"openhands self-host","open hands coding agent","openhands vs claude code","agent canvas","openhands docker sandbox","openhands cloud pricing",[669,672,675],{"name":670,"url":671},"OpenHands","https:\u002F\u002Fwww.openhands.dev",{"name":673,"url":674},"OpenHands on GitHub","https:\u002F\u002Fgithub.com\u002FOpenHands\u002FOpenHands",{"name":676,"url":677},"Intelligent agent","https:\u002F\u002Fen.wikipedia.org\u002Fwiki\u002FIntelligent_agent",[679,681,684,687,690,693,696],{"title":680,"url":674},"OpenHands README",{"title":682,"url":683},"OpenHands licence (MIT)","https:\u002F\u002Fgithub.com\u002FOpenHands\u002FOpenHands\u002Fblob\u002Fmain\u002FLICENSE",{"title":685,"url":686},"Agent Canvas 1.25.0 release notes","https:\u002F\u002Fdocs.openhands.dev\u002Fopenhands\u002Fusage\u002Fagent-canvas\u002Frelease-notes\u002Fv1.25.0.md",{"title":688,"url":689},"OpenHands sandbox overview","https:\u002F\u002Fdocs.openhands.dev\u002Fopenhands\u002Fusage\u002Fsandboxes\u002Foverview.md",{"title":691,"url":692},"OpenHands quick start","https:\u002F\u002Fdocs.openhands.dev\u002Fopenhands\u002Fusage\u002Finstallation",{"title":694,"url":695},"OpenHands pricing","https:\u002F\u002Fwww.openhands.dev\u002Fpricing",{"title":697,"url":698},"Introducing the OpenHands Index","https:\u002F\u002Fwww.openhands.dev\u002Fblog\u002Fintroducing-the-openhands-index","\u002Fimages\u002Fblog\u002Fopenhands\u002Fcover.webp","\u002Fimages\u002Fblog\u002Fopenhands\u002Fog.jpg",[65,66,67],"OpenHands: the open-source coding agent you operate","OpenHands 1.25.0 is an MIT-licensed coding agent platform with a web canvas, a CLI, sandboxed execution and scheduled automations. A review of where it is strong and where it gets heavy.","Cover artwork for the OpenHands review showing a loop from task to agent to sandboxed run and back","https:\u002F\u002Fgithub.com\u002FAll-Hands-AI\u002FOpenHands","Free · self-host",1791383548788]