BakedBrie docs

Connect Codex

BakedBrie's MCP server is a streamable HTTP server. Codex connects to it with a bearer token that it reads from an environment variable, so the token never goes into the config file.

ItemValue
Server namebakedbrie
URLhttps://api.bakedbrie.com/mcp
Token env varBAKEDBRIE_TOKEN

Before you start

You need a BakedBrie API token (bbk_prd_...). If you do not have one, see Tokens and the runner.

Step 1: put the token in an environment variable

The user sets it in their own shell. Never paste it into chat.

export BAKEDBRIE_TOKEN='bbk_prd_...'

Codex reads the variable from the environment it starts in, so start codex from a shell where BAKEDBRIE_TOKEN is set. To keep it across sessions, add the line to the shell profile (for example ~/.zshrc) or load it from the keychain.

Step 2: add the server

Either run the command:

codex mcp add bakedbrie --url https://api.bakedbrie.com/mcp --bearer-token-env-var BAKEDBRIE_TOKEN

Or add this table to ~/.codex/config.toml yourself:

[mcp_servers.bakedbrie]
url = "https://api.bakedbrie.com/mcp"
bearer_token_env_var = "BAKEDBRIE_TOKEN"
default_tools_approval_mode = "approve"

Both give the same server (codex mcp add does not write the last line; add it by hand). Codex sends Authorization: Bearer <value of BAKEDBRIE_TOKEN> on every request. Do not put the token itself in config.toml.

For one project only, put the same table in .codex/config.toml in that project. Codex reads project config only for trusted projects.

Without --bearer-token-env-var (or bearer_token_env_var), Codex adds the server with no token and every call fails.

Tool approvals

Codex asks before every MCP tool that is not marked read only, and most BakedBrie tools change something (even the manage_* tools, whose list and get actions only read). default_tools_approval_mode decides what happens:

ValueWhat Codex does
approve (recommended) or autoRuns BakedBrie tools without asking. The agent still confirms with the user in plain words where these docs say so.
writesAsks before each tool not marked read only. Fine in the terminal UI.
promptAsks before every tool.

In codex exec nobody can answer a prompt, so without approve (or auto) every tool that would ask fails with MCP tool call requires approval, but approval policy is never. To allow only some tools, set approval_mode = "approve" in a [mcp_servers.bakedbrie.tools.<tool>] table instead.

Step 3: check the connection

codex mcp list

In the Codex terminal UI, type /mcp to see active servers. Then call the whoami tool. See whoami.

If it does not connect

What you seeLikely causeWhat to do
UNAUTHENTICATED, or Codex suggests codex mcp loginBAKEDBRIE_TOKEN was empty when Codex started, or the token was revoked or expiredExport the variable in the same shell, restart Codex. Mint a new token if it was revoked or is older than 90 days. BakedBrie does not use MCP OAuth, so codex mcp login does not help.
MCP_DISABLEDMCP is turned off on this BakedBrie serverTell the user.
API_TOKENS_DISABLEDAPI tokens are turned off on this serverTell the user.
TOKEN_RUNNER_ONLYYou used a runner keyMint a Full control or Read only token instead.
MCP tool call requires approval, but approval policy is neverCodex needs approval for this tool and cannot ask (codex exec)Add default_tools_approval_mode = "approve" to [mcp_servers.bakedbrie] and start Codex again.

More codes: Refusals.

Remove it

Delete the [mcp_servers.bakedbrie] table from ~/.codex/config.toml. To stop the token working everywhere, revoke it in Settings, Apps and API.

Next step

Read Concepts, then call whoami.

View as Markdown