# Connect Codex

BakedBrie's MCP server is a streamable HTTP server. Codex connects to it with a bearer token that it reads from an environment variable, so the token never goes into the config file.

| Item | Value |
|---|---|
| Server name | `bakedbrie` |
| URL | `https://api.bakedbrie.com/mcp` |
| Token env var | `BAKEDBRIE_TOKEN` |

## Before you start

You need a BakedBrie API token (`bbk_prd_...`). If you do not have one, see [Tokens and the runner](/docs/tokens-and-runner).

## Step 1: put the token in an environment variable

The user sets it in their own shell. Never paste it into chat.

```bash
export BAKEDBRIE_TOKEN='bbk_prd_...'
```

Codex reads the variable from the environment it starts in, so start `codex` from a shell where `BAKEDBRIE_TOKEN` is set. To keep it across sessions, add the line to the shell profile (for example `~/.zshrc`) or load it from the keychain.

## Step 2: add the server

Either run the command:

```bash
codex mcp add bakedbrie --url https://api.bakedbrie.com/mcp --bearer-token-env-var BAKEDBRIE_TOKEN
```

Or add this table to `~/.codex/config.toml` yourself:

```toml
[mcp_servers.bakedbrie]
url = "https://api.bakedbrie.com/mcp"
bearer_token_env_var = "BAKEDBRIE_TOKEN"
default_tools_approval_mode = "approve"
```

Both give the same server (`codex mcp add` does not write the last line; add it by hand). Codex sends `Authorization: Bearer <value of BAKEDBRIE_TOKEN>` on every request. Do not put the token itself in `config.toml`.

For one project only, put the same table in `.codex/config.toml` in that project. Codex reads project config only for trusted projects.

Without `--bearer-token-env-var` (or `bearer_token_env_var`), Codex adds the server with no token and every call fails.

### Tool approvals

Codex asks before every MCP tool that is not marked read only, and most BakedBrie tools change something (even the `manage_*` tools, whose `list` and `get` actions only read). `default_tools_approval_mode` decides what happens:

| Value | What Codex does |
|---|---|
| `approve` (recommended) or `auto` | Runs BakedBrie tools without asking. The agent still confirms with the user in plain words where these docs say so. |
| `writes` | Asks before each tool not marked read only. Fine in the terminal UI. |
| `prompt` | Asks before every tool. |

In `codex exec` nobody can answer a prompt, so without `approve` (or `auto`) every tool that would ask fails with `MCP tool call requires approval, but approval policy is never`. To allow only some tools, set `approval_mode = "approve"` in a `[mcp_servers.bakedbrie.tools.<tool>]` table instead.

## Step 3: check the connection

```bash
codex mcp list
```

In the Codex terminal UI, type `/mcp` to see active servers. Then call the `whoami` tool. See [whoami](/docs/reference/tools/whoami).

## If it does not connect

| What you see | Likely cause | What to do |
|---|---|---|
| `UNAUTHENTICATED`, or Codex suggests `codex mcp login` | `BAKEDBRIE_TOKEN` was empty when Codex started, or the token was revoked or expired | Export the variable in the same shell, restart Codex. Mint a new token if it was revoked or is older than 90 days. BakedBrie does not use MCP OAuth, so `codex mcp login` does not help. |
| `MCP_DISABLED` | MCP is turned off on this BakedBrie server | Tell the user. |
| `API_TOKENS_DISABLED` | API tokens are turned off on this server | Tell the user. |
| `TOKEN_RUNNER_ONLY` | You used a runner key | Mint a Full control or Read only token instead. |
| `MCP tool call requires approval, but approval policy is never` | Codex needs approval for this tool and cannot ask (`codex exec`) | Add `default_tools_approval_mode = "approve"` to `[mcp_servers.bakedbrie]` and start Codex again. |

More codes: [Refusals](/docs/refusals).

## Remove it

Delete the `[mcp_servers.bakedbrie]` table from `~/.codex/config.toml`. To stop the token working everywhere, revoke it in Settings, Apps and API.

## Next step

Read [Concepts](/docs/concepts), then call `whoami`.

<!--
Sources checked 2026-09-23:
https://developers.openai.com/codex/mcp (redirects to https://learn.chatgpt.com/docs/extend/mcp?surface=cli): ~/.codex/config.toml, project .codex/config.toml for trusted projects, [mcp_servers.<name>] url + bearer_token_env_var, codex mcp add <name> --url, codex mcp list, /mcp
https://developers.openai.com/codex/config-reference (redirects to https://learn.chatgpt.com/docs/config-file/config-reference): mcp_servers.<id>.url, mcp_servers.<id>.bearer_token_env_var, mcp_servers.<id>.default_tools_approval_mode (auto | prompt | writes | approve), mcp_servers.<id>.tools.<tool>.approval_mode
https://learn.chatgpt.com/docs/extend/mcp?surface=cli: "The writes mode prompts for tools that aren't marked read-only." codex exec refusal text seen in the D4 acceptance run (codex-cli 0.155.1)
https://github.com/github/github-mcp-server/blob/main/docs/installation-guides/install-codex.md (codex mcp add --bearer-token-env-var; without it the config has no token)
Confirmed against local `codex mcp add --help` (codex-cli 0.155.1): --url, --bearer-token-env-var
Server side: apps/api/src/mcp/server.ts (POST /mcp, Bearer bbk_ token), infra/topology.json (api origin)
-->
