1
00:00:00,000 --> 00:00:04,880
If you have ever tried hooking up an
enterprise tool to an autonomous coding agent,

2
00:00:04,920 --> 00:00:08,560
you probably ran face first into a wall
about five minutes in.

3
00:00:09,103 --> 00:00:12,143
Oh, the classic OAuth redirect loop of
doom.

4
00:00:12,663 --> 00:00:16,622
Where it tries to open a browser window on
a headless remote server and just sits

5
00:00:16,683 --> 00:00:17,783
there forever.

6
00:00:18,125 --> 00:00:19,245
Every single time.

7
00:00:19,373 --> 00:00:23,965
Well, Jellypod helps make tracking these
daily changelogs possible,

8
00:00:24,005 --> 00:00:31,005
and in Codex rust version 0.158.0, OpenAI
quietly dropped a fix for

9
00:00:31,037 --> 00:00:32,125
this exact problem.

10
00:00:32,338 --> 00:00:38,285
In the release notes, they added support
for pre registered OAuth client secrets via

11
00:00:38,365 --> 00:00:44,845
a new flag on the command line: codex mcp
add with oauth client secret.

12
00:00:45,175 --> 00:00:49,655
Wait, so Model Context Protocol servers
can finally do confidential client

13
00:00:49,695 --> 00:00:51,675
authentication directly in the tool?

14
00:00:52,125 --> 00:00:52,925
Exactly.

15
00:00:53,015 --> 00:00:59,005
Because up until now, MCP setups mostly
assumed, you know, a desktop user sitting

16
00:00:59,032 --> 00:01:02,765
there clicking allow, or a simple public
client setup.

17
00:01:03,072 --> 00:01:06,372
Right, like PKCE, Proof Key for Code
Exchange.

18
00:01:06,792 --> 00:01:10,592
Which, if you think about it, makes total
sense for a person in a browser.

19
00:01:11,032 --> 00:01:15,112
You generate a secret on the fly, you
bounce through Okta or Azure AD,

20
00:01:15,612 --> 00:01:18,851
the browser handles your cookie, and you
get back a short lived token.

21
00:01:19,332 --> 00:01:24,152
But, an autonomous agent running in a
terminal doesn't have a human eyes session

22
00:01:24,212 --> 00:01:24,932
attached to it.

23
00:01:25,250 --> 00:01:29,970
And enterprise security teams hate public
client flows for backend services anyway.

24
00:01:30,210 --> 00:01:34,930
If you go to corporate IT and say, hey, I
need an automated script to talk to our

25
00:01:34,974 --> 00:01:40,850
internal database API via MCP, they will
flatly refuse to allow a public client

26
00:01:40,900 --> 00:01:42,450
without a pre shared secret.

27
00:01:42,818 --> 00:01:44,698
They want a confidential client.

28
00:01:45,058 --> 00:01:50,238
A real, pre registered application
identity with a stored secret that can issue

29
00:01:50,318 --> 00:01:51,938
tokens non interactively.

30
00:01:52,250 --> 00:01:52,970
Precisely.

31
00:01:53,130 --> 00:01:58,730
So the new syntax lets you run codex mcp
add, give it the server name,

32
00:01:58,810 --> 00:02:05,130
specify the url endpoint, and then pass
oauth client id and oauth client secret

33
00:02:05,183 --> 00:02:05,690
directly.

34
00:02:06,088 --> 00:02:10,508
Though, please tell me people aren't
literally pasting their production corporate

35
00:02:10,568 --> 00:02:12,948
client secrets into raw bash commands.

36
00:02:14,153 --> 00:02:15,093
You know someone will!

37
00:02:15,673 --> 00:02:18,073
But yes, huge operational warning here.

38
00:02:18,713 --> 00:02:23,913
If you paste oauth client secret right
into the shell, that secret lives in your dot

39
00:02:23,953 --> 00:02:27,333
bash history or your zsh history forever.

40
00:02:28,133 --> 00:02:32,873
Anyone with read access to your dotfiles
or your terminal session has your service

41
00:02:32,933 --> 00:02:33,353
account.

42
00:02:34,053 --> 00:02:38,213
Codex does offer interactive prompt
capture, or environment variables,

43
00:02:38,713 --> 00:02:43,153
which is what you really ought to be using
if you share your machine or log shell

44
00:02:43,273 --> 00:02:43,693
sessions.

45
00:02:44,090 --> 00:02:47,410
Treat your command history like a public
document, folks.

46
00:02:47,930 --> 00:02:52,110
But architecturally, this unblocks a lot
of real corporate internal tool

47
00:02:52,170 --> 00:02:54,770
integrations that were just stalled out
before.

48
00:02:55,042 --> 00:02:58,482
Now, the auth change wasn't the only big
fix under the hood.

49
00:02:58,589 --> 00:03:05,202
There was this infuriating edge case in
pull request 47819 around

50
00:03:05,246 --> 00:03:06,242
Guardian reviews.

51
00:03:07,010 --> 00:03:08,970
Oh, I read that pull request description!

52
00:03:09,530 --> 00:03:12,230
It was so funny and so painful.

53
00:03:12,930 --> 00:03:15,370
You know how when Codex is about to do
something dangerous,

54
00:03:15,490 --> 00:03:19,270
it pauses and waits for Guardian
authorization or user approval?

55
00:03:19,667 --> 00:03:20,387
Right.

56
00:03:20,467 --> 00:03:23,667
It is sitting there waiting for you to
review a proposed action.

57
00:03:24,007 --> 00:03:27,987
And naturally, because you are human, you
might type something like,

58
00:03:28,507 --> 00:03:30,647
wait, what is the current test status?

59
00:03:30,787 --> 00:03:32,667
Or, did the lint pass?

60
00:03:33,167 --> 00:03:38,427
And in 0.157, the system would look at
your new text, treat it as a state

61
00:03:38,487 --> 00:03:42,507
invalidation, and completely abort the
pending task execution!

62
00:03:43,327 --> 00:03:44,447
It just wiped the board.

63
00:03:45,067 --> 00:03:48,807
You asked a status question, and Codex
threw out the entire run.

64
00:03:49,547 --> 00:03:56,367
With pull request 47819, the approval
reviews now retry when new user input arrives.

65
00:03:57,087 --> 00:04:01,587
So the pending action stays alive in the
queue while the agent absorbs the new

66
00:04:01,627 --> 00:04:02,207
context.

67
00:04:02,692 --> 00:04:07,072
That is such a relief for anyone who talks
to their agent while it is working.

68
00:04:07,832 --> 00:04:11,472
Speaking of approvals though, they also
tightened up terminal permissions,

69
00:04:11,532 --> 00:04:11,952
didn't they?

70
00:04:12,292 --> 00:04:15,252
Yeah, pull request 47799.

71
00:04:15,341 --> 00:04:20,452
Terminal input approval is now enabled by
default whenever commands run with

72
00:04:20,496 --> 00:04:21,652
elevated permissions.

73
00:04:21,792 --> 00:04:28,212
And tied right into that, pull requests
47601 and 47648

74
00:04:28,319 --> 00:04:33,252
added bearer token authentication for exec
server WebSocket connections.

75
00:04:34,232 --> 00:04:39,312
That is actually huge for remote dev
containers and shared compute boxes.

76
00:04:40,012 --> 00:04:43,372
If your background execution server is
listening on a WebSocket socket,

77
00:04:43,812 --> 00:04:47,432
you cannot just leave it wide open to any
local process on the machine.

78
00:04:47,750 --> 00:04:48,670
Exactly.

79
00:04:48,740 --> 00:04:51,510
You need a bearer token isolating that
socket.

80
00:04:51,650 --> 00:04:56,470
And on the surface side, for anyone living
in the fullscreen terminal UI,

81
00:04:56,518 --> 00:05:01,510
pull request 47639 finally fixed the
clipboard formatting.

82
00:05:01,902 --> 00:05:03,942
Wait, did they fix the Markdown stripping?

83
00:05:04,250 --> 00:05:05,130
They did!

84
00:05:05,210 --> 00:05:10,490
You now have configurable copy on select
and right click paste in the fullscreen

85
00:05:10,650 --> 00:05:15,530
TUI, and when you copy text out of the
transcript, it actually preserves the

86
00:05:15,583 --> 00:05:20,170
Markdown blocks instead of flattening
everything into unformatted mush.

87
00:05:20,588 --> 00:05:24,828
As a tester who copies code snippets out
of agent runs twenty times a day,

88
00:05:25,188 --> 00:05:26,448
thank goodness.

89
00:05:27,008 --> 00:05:31,388
Oh, and Mermaid flowcharts stop crashing
on quoted labels and ampersands now too.

90
00:05:31,988 --> 00:05:36,168
Little quality of life wins that make the
terminal feel like a finished product.

91
00:05:36,500 --> 00:05:40,500
Small details, but they add up to a much
more stable daily driver.

