openclaw/extensions/codex/openclaw.plugin.json
RoboClaw 1caaef4b6f
feat(ui): select Ultrafast for supported accounts (#160352)
* feat(ui): select Ultrafast for supported accounts

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(gateway): preserve Ultrafast compatibility and account authority

Negotiate speed decoding per connection and keep canonical session state intact. Fence personal-account catalog requests at final guarded HTTP dispatch. Refresh the measured UI boot manifest without changing performance limits.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* refactor(openai): keep account catalog outcomes together

Move the existing account-scoped result projection into the already imported catalog helper without changing its behavior. Keep the provider owner below its existing line-count ratchet.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test: refresh Ultrafast tool prompt fixtures

Regenerate the canonical Codex dynamic-tool fixtures for the authorized Ultrafast speed value. Update only that enum value and its derived size/hash metadata; keep snapshot checks enabled.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix: stop account catalog requests after default unlink

Bind automatic account selections to the canonical profile writer's committed link authority and carry the real request scope through final guarded dispatch. Keep explicit retained account selections usable after unlink and evict failed discovery custody. Preserve the existing active Auto Ultrafast opt-in while explicit Fast stays priority.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* refactor(codex): use narrowed Auto activation flag

Keep the reviewed Auto tier predicate while satisfying the typed boolean lint contract.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ui): share speed applicability for optional Ultrafast

Respect the selected request mapping before offering an optional entitled tier. Preserve all three choices on eligible routes and clearable stored preferences on unsupported routes. Reproduced the contradictory catalog regression and passed 59 unit/Chromium cases; scoped independent review found no actionable P0/P1.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ci): export manifest in same-revision preflight harness

Restore the trusted file omitted when the inline manifest moved out of ci.yml in 9d75a8fe87. Actual preflight job109720001696 failed before tests with MODULE_NOT_FOUND; real Git push and PR materialization fixtures reproduce the same omission. Keep the canonical index export owner, regenerate its workflow projection, and preserve all source/credential guards. Fifteen materialization variants, five import/size checks, root test types, and focused independent review pass.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ci): satisfy extracted manifest static contracts

Repair inherited check-lint failures from the manifest extraction without changing CI routing: avoid namespace shadowing, retain error cause and the diagnostic callback string contract, preserve nonmutating shard copies, and apply required branch syntax. All1259 scripts lint clean;45 planner/import/size cases, formatting, UI i18n, styles, ratchet and independent review pass.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(ci): centralize dependency-free workflow flag parsing

Remove the extracted manifest local coercion helper and preserve its exact narrow Boolean grammar under the existing script argument owner. Register the canonical declaration rather than weakening the guard, and carry its runtime through trusted preflight materialization and fixtures.77 argument cases,11 declaration-guard cases,71 scoped integration cases, types, lint, export scans and remaining guard commands pass; independent review has no actionable P0/P1.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(gateway): separate model publication authority from selection scope

Keep the actual request lifetime in selected-account HTTP assertions without treating every anonymous unscoped catalog read as a personal account projection. Restore the established models.list response shape; no assertions weakened.177 model/catalog/session cases and10physical HTTP authority cases pass, together with types, lint, ratchet and independent review.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix: preserve session response argument tuples

Forward the original response tuple while projecting successful legacy payloads, without appending optional undefined arguments.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix(codex): preserve existing Ultrafast opt-ins

Keep the v2026.9.7 Fast and active Auto opt-in semantics while adding explicit per-session Ultrafast. Standard still clears the tier. Cover cold and warm native turn requests without requiring a migration.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(ui): distinguish speed labels from model names

Match the complete Effort and Speed section labels rather than the Speed only fixture model. Retain the independent absence assertions for reasoning and speed controls. All four failures reproduced before the repair; the complete 13-case bundled browser file passes afterward.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(openai): intercept the shared transcription socket

Update the two stale socket mock registrations after the upstream transport consolidation. Keep the actual provider/session code, fake peers, assertions, timeouts, and Bun transport guard unchanged. All 86 OpenAI shard files pass: 1263 passed and one existing skip.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* test(gateway): construct complete session reset callers

Replace partial caller objects cast as never with the existing typed session mutation client fixture. Preserve provenance and required-sandbox assertions and the production client capability contract. Both CI failures reproduce before the repair; all 15 reset-model cases pass afterward.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

* fix: confirm the selected Ultrafast command mode

Share the direct command, directive reply, and system-event confirmation formatter so the saved Ultrafast tier is named accurately. Include the accepted manual value in help and docs without advertising an unverified optional native-menu choice. Preserve boolean Fast, Auto, reset, authorization and persistence behavior. Three regressions fail before repair; 274 focused cases pass afterward.

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>

---------

Co-authored-by: steipete <58493+steipete@users.noreply.github.com>
2026-09-30 07:45:41 +00:00

846 lines
29 KiB
JSON

{
"id": "codex",
"categories": ["agent-runtimes"],
"providers": ["codex"],
"syntheticAuthRefs": ["codex"],
"providerCatalogEntry": "./provider-discovery.ts",
"backupResources": [
{
"disposition": "regenerable",
"scope": "agent",
"relativePath": "codex-home/tmp/arg0"
},
{
"disposition": "regenerable",
"scope": "agent",
"relativePath": "codex-home/.tmp/plugins"
},
{
"disposition": "regenerable",
"scope": "agent",
"relativePath": "codex-home/.tmp/bundled-marketplaces"
}
],
"doctorContract": {
"configRepair": true,
"stateMigrations": [
{ "id": "codex-app-server-sidecars-to-plugin-state" },
{ "id": "codex-native-task-assignments" },
{
"id": "codex-app-server-orphaned-session-bindings",
"doctorOnly": true,
"phase": "after-session-repair"
}
]
},
"doctorHealthChecks": true,
"sessionRouteStateOwners": [
{
"id": "codex",
"label": "Codex",
"providerIds": ["codex", "codex-cli", "openai-codex"],
"runtimeIds": ["codex", "codex-cli"],
"cliSessionKeys": ["codex-cli"],
"authProfilePrefixes": ["codex:", "codex-cli:", "openai-codex:"]
}
],
"name": "Codex",
"description": "Codex app-server harness and native session catalog.",
"cliCommands": [
{
"name": "codex",
"description": "Inspect and branch from Codex sessions through the Gateway",
"hasSubcommands": true
}
],
"contracts": {
"mediaUnderstandingProviders": ["codex"],
"migrationProviders": ["codex"],
"tools": [
"codex_threads",
"codex_plugins",
"codex_endpoint_probe",
"codex_sessions_list",
"codex_session_read",
"codex_session_send",
"codex_session_interrupt"
],
"webSearchProviders": ["codex"]
},
"mediaUnderstandingProviderMetadata": {
"codex": {
"capabilities": ["image"],
"defaultModels": {
"image": "gpt-6-astra"
}
}
},
"activation": {
"onStartup": false,
"onAgentHarnesses": ["codex"],
"onCommands": ["codex"],
"onConfigPaths": [
"plugins.entries.codex.config.appServer.transport",
"plugins.entries.codex.config.sessionCatalog.enabled",
"plugins.entries.codex.config.sessionCatalog.homes",
"plugins.entries.codex.config.supervision.enabled"
]
},
"commandAliases": [
{
"name": "codex",
"kind": "runtime-slash",
"cliCommand": "plugins"
}
],
"setup": {
"nativeSessionCatalog": {
"label": "Codex",
"legacyDefaultEnabled": true,
"description": "Existing native Codex conversations on this Gateway and eligible paired nodes.",
"nodeCommands": [
"codex.appServer.threads.list.v1",
"codex.appServer.thread.turns.list.v1",
"codex.sessionCatalog.transcript.read.v1",
"codex.terminal.resume.v1",
"codex.cli.sessions.list"
]
}
},
"configGroups": [
{
"id": "dynamic-tools",
"title": "Dynamic tools",
"order": 10,
"properties": ["codexDynamicToolsLoading", "codexDynamicToolsExclude"]
},
{
"id": "native-sessions",
"title": "Native sessions",
"order": 20,
"properties": ["sessionCatalog", "supervision"]
},
{
"id": "model-discovery",
"title": "Model discovery",
"order": 30,
"properties": ["discovery"]
},
{
"id": "computer-use",
"title": "Computer use",
"order": 40,
"properties": ["computerUse"]
},
{
"id": "native-plugins",
"title": "Native plugins",
"order": 50,
"properties": ["codexPlugins"]
},
{
"id": "app-server-connection",
"title": "App Server connection",
"order": 60,
"properties": ["appServer"]
}
],
"configSchema": {
"type": "object",
"additionalProperties": false,
"properties": {
"codexDynamicToolsLoading": {
"type": "string",
"enum": ["searchable", "direct"],
"default": "searchable"
},
"codexDynamicToolsExclude": {
"type": "array",
"items": { "type": "string" },
"default": []
},
"sessionCatalog": {
"type": "object",
"additionalProperties": false,
"properties": {
"enabled": { "type": "boolean", "default": true },
"homes": {
"type": "array",
"items": {
"anyOf": [
{ "type": "string", "minLength": 1, "pattern": "\\S" },
{
"type": "object",
"additionalProperties": false,
"required": ["path"],
"properties": {
"path": { "type": "string", "minLength": 1, "pattern": "\\S" },
"label": { "type": "string", "minLength": 1, "pattern": "\\S" }
}
}
]
}
}
}
},
"discovery": {
"type": "object",
"additionalProperties": false,
"properties": {
"enabled": { "type": "boolean" },
"timeoutMs": {
"type": "number",
"minimum": 1,
"default": 10000
}
}
},
"computerUse": {
"type": "object",
"additionalProperties": false,
"properties": {
"enabled": {
"type": "boolean",
"default": false
},
"autoInstall": {
"type": "boolean",
"default": false
},
"marketplaceDiscoveryTimeoutMs": {
"type": "number",
"minimum": 1,
"default": 60000
},
"liveTestTimeoutMs": {
"type": "number",
"minimum": 1,
"default": 60000
},
"toolCallTimeoutMs": {
"type": "number",
"minimum": 1,
"default": 60000
},
"healthCheckEnabled": {
"type": "boolean",
"default": false
},
"healthCheckIntervalMinutes": {
"type": "number",
"enum": [30, 60, 120, 240],
"default": 60
},
"pluginCacheMode": {
"type": "string",
"enum": ["shared", "independent"],
"default": "independent"
},
"strictReadiness": {
"type": "boolean",
"default": false
},
"autoRepair": {
"type": "boolean",
"default": false
},
"marketplaceSource": {
"type": "string"
},
"marketplacePath": {
"type": "string"
},
"marketplaceName": {
"type": "string"
},
"pluginName": {
"type": "string",
"default": "computer-use"
},
"mcpServerName": {
"type": "string",
"default": "computer-use"
}
}
},
"codexPlugins": {
"type": "object",
"additionalProperties": false,
"properties": {
"enabled": {
"type": "boolean",
"default": false
},
"allow_all_plugins": {
"type": "boolean",
"default": false
},
"allow_destructive_actions": {
"oneOf": [{ "type": "boolean" }, { "const": "auto" }, { "const": "ask" }],
"default": true
},
"plugins": {
"type": "object",
"additionalProperties": {
"type": "object",
"additionalProperties": false,
"properties": {
"enabled": {
"type": "boolean"
},
"marketplaceName": {
"type": "string",
"pattern": "^[A-Za-z0-9_-]+$"
},
"pluginName": {
"type": "string"
},
"allow_destructive_actions": {
"oneOf": [{ "type": "boolean" }, { "const": "auto" }, { "const": "ask" }]
}
}
}
}
}
},
"supervision": {
"type": "object",
"additionalProperties": false,
"properties": {
"enabled": { "type": "boolean", "default": false },
"endpoints": {
"type": "array",
"items": {
"oneOf": [
{
"type": "object",
"additionalProperties": false,
"properties": {
"id": { "type": "string" },
"label": { "type": "string" },
"transport": { "const": "stdio-proxy" },
"command": { "type": "string" },
"args": { "type": "array", "items": { "type": "string" } },
"cwd": { "type": "string" }
}
},
{
"type": "object",
"additionalProperties": false,
"required": ["transport", "url"],
"properties": {
"id": { "type": "string" },
"label": { "type": "string" },
"transport": { "const": "websocket" },
"url": { "type": "string" },
"authTokenEnv": { "type": "string" }
}
}
]
}
},
"allowRawTranscripts": { "type": "boolean", "default": false },
"allowWriteControls": { "type": "boolean", "default": false }
}
},
"appServer": {
"type": "object",
"additionalProperties": false,
"properties": {
"mode": {
"type": "string",
"enum": ["yolo", "guardian"]
},
"transport": {
"type": "string",
"enum": ["stdio", "websocket", "unix"],
"default": "stdio"
},
"homeScope": {
"type": "string",
"enum": ["agent", "user"]
},
"command": { "type": "string" },
"args": {
"oneOf": [
{
"type": "array",
"items": { "type": "string" }
},
{ "type": "string" }
]
},
"url": { "type": "string" },
"authToken": { "type": ["string", "object"] },
"headers": {
"type": "object",
"additionalProperties": { "type": ["string", "object"] }
},
"clearEnv": {
"type": "array",
"items": { "type": "string" }
},
"remoteWorkspaceRoot": {
"type": "string"
},
"codeModeOnly": {
"type": "boolean",
"default": false
},
"loopDetectionPreToolUseRelay": {
"type": "boolean",
"default": true
},
"requestTimeoutMs": {
"type": "number",
"minimum": 1,
"default": 60000
},
"approvalPolicy": {
"type": "string",
"enum": ["never", "on-request", "on-failure", "untrusted"]
},
"sandbox": {
"type": "string",
"enum": ["read-only", "workspace-write", "danger-full-access"]
},
"approvalsReviewer": {
"type": "string",
"enum": ["user", "auto_review", "guardian_subagent"]
},
"serviceTier": { "type": ["string", "null"] },
"enableUltrafast": { "type": "boolean", "default": false },
"cyberFailover": {
"type": "object",
"additionalProperties": false,
"properties": {
"mode": { "type": "string", "enum": ["auto", "off"], "default": "auto" },
"model": {
"type": "string",
"minLength": 1,
"default": "gpt-daybreak-blue-latest"
},
"cooloffMs": { "type": "number", "minimum": 1, "default": 600000 }
}
},
"networkProxy": {
"type": "object",
"additionalProperties": false,
"properties": {
"enabled": {
"type": "boolean",
"default": false
},
"profileName": { "type": "string" },
"baseProfile": {
"type": "string",
"enum": ["read-only", "workspace"]
},
"mode": {
"type": "string",
"enum": ["limited", "full"]
},
"domains": {
"type": "object",
"additionalProperties": {
"type": "string",
"enum": ["allow", "deny"]
}
},
"unixSockets": {
"type": "object",
"additionalProperties": {
"type": "string",
"enum": ["allow", "none"]
}
},
"proxyUrl": { "type": "string" },
"socksUrl": { "type": "string" },
"enableSocks5": { "type": "boolean" },
"enableSocks5Udp": { "type": "boolean" },
"allowUpstreamProxy": { "type": "boolean" },
"allowLocalBinding": { "type": "boolean" },
"dangerouslyAllowNonLoopbackProxy": { "type": "boolean" },
"dangerouslyAllowAllUnixSockets": { "type": "boolean" }
}
},
"defaultWorkspaceDir": {
"type": "string"
},
"experimental": {
"type": "object",
"additionalProperties": false,
"properties": {
"sandboxExecServer": {
"type": "boolean",
"default": false
}
}
}
}
}
}
},
"configContracts": {
"secretInputs": {
"paths": [
{ "path": "appServer.authToken", "expected": "string" },
{ "path": "appServer.headers.*", "expected": "string" }
]
}
},
"uiHints": {
"sessionCatalog": {
"label": "Native Session Discovery",
"help": "Controls whether Codex sessions from this Gateway and paired nodes appear in the sidebar. Disabling also removes this host's paired-node catalog commands without disabling the Codex provider or harness. Node-list failures usually indicate a Gateway pairing-store or node-registry problem; verify Settings > Devices or run openclaw nodes list. Changes require a Gateway restart."
},
"sessionCatalog.enabled": {
"label": "Discover Codex Sessions",
"help": "List native Codex sessions in the sidebar from this Gateway and eligible paired nodes."
},
"sessionCatalog.homes": {
"label": "Additional Codex Homes",
"help": "Existing local Codex home directories to include in native session discovery. String paths use the canonical directory basename as their label; object entries can override it with label. Paths are canonicalized and deduplicated. Requires appServer.transport=stdio and a Gateway restart.",
"advanced": true
},
"codexDynamicToolsLoading": {
"label": "Dynamic Tools Loading",
"help": "Use searchable to defer OpenClaw dynamic tools behind Codex tool search, or direct to expose them in the initial context.",
"advanced": true
},
"codexDynamicToolsExclude": {
"label": "Dynamic Tool Excludes",
"help": "Additional OpenClaw dynamic tool names to omit from Codex app-server turns.",
"advanced": true
},
"discovery": {
"label": "Model Discovery",
"help": "Plugin-owned controls for discovering Codex app-server models."
},
"discovery.enabled": {
"label": "Enable Discovery",
"help": "When false, OpenClaw keeps the Codex harness available but uses the bundled fallback model list."
},
"discovery.timeoutMs": {
"label": "Discovery Timeout",
"help": "Maximum time to wait for Codex app-server model discovery. The default allows Codex to finish its remote catalog refresh or native fallback; a timeout leaves native models unavailable until discovery succeeds.",
"advanced": true
},
"computerUse": {
"label": "Computer Use",
"help": "Controls Codex app-server setup for the Computer Use plugin.",
"advanced": true
},
"computerUse.enabled": {
"label": "Enable Computer Use",
"help": "When true, Codex-mode turns require the configured Computer Use MCP server to be available.",
"advanced": true
},
"computerUse.autoInstall": {
"label": "Auto Install",
"help": "Install the configured Computer Use plugin when Codex-mode turns start.",
"advanced": true
},
"computerUse.marketplaceDiscoveryTimeoutMs": {
"label": "Marketplace Discovery Timeout",
"help": "Maximum time to wait for Codex app-server to finish loading marketplaces during Computer Use install.",
"advanced": true
},
"computerUse.liveTestTimeoutMs": {
"label": "Live Test Timeout",
"help": "Maximum time for the Computer Use list_apps readiness probe before status and startup treat the live test as failed.",
"advanced": true
},
"computerUse.toolCallTimeoutMs": {
"label": "Tool Call Timeout",
"help": "Maximum expected time for real Computer Use tool calls such as list_apps before OpenClaw treats the child runtime as stale.",
"advanced": true
},
"computerUse.healthCheckEnabled": {
"label": "Periodic Health Checks",
"help": "When true, run periodic Computer Use live probes on the configured cadence.",
"advanced": true
},
"computerUse.healthCheckIntervalMinutes": {
"label": "Health Check Interval",
"help": "Cadence for periodic Computer Use health checks when health checks are enabled.",
"advanced": true
},
"computerUse.pluginCacheMode": {
"label": "Plugin Cache Mode",
"help": "The default independent mode leaves each Codex home unmanaged. Choose shared to opt in to a refreshed Codex-discoverable cache copy.",
"advanced": true
},
"computerUse.strictReadiness": {
"label": "Strict Readiness",
"help": "When true, a failed Computer Use live probe stops Codex-mode startup. The default false value preserves existing enabled setups by continuing with a warning.",
"advanced": true
},
"computerUse.autoRepair": {
"label": "Auto Repair",
"help": "When true, failed Computer Use live tests reload the Codex-owned MCP runtime before retrying once.",
"advanced": true
},
"computerUse.marketplaceSource": {
"label": "Marketplace Source",
"help": "Optional Codex marketplace source to add before installing Computer Use.",
"advanced": true
},
"computerUse.marketplacePath": {
"label": "Marketplace Path",
"help": "Optional local Codex marketplace file path containing the Computer Use plugin.",
"advanced": true
},
"computerUse.marketplaceName": {
"label": "Marketplace Name",
"help": "Optional registered Codex marketplace name containing the Computer Use plugin.",
"advanced": true
},
"computerUse.pluginName": {
"label": "Plugin Name",
"help": "Codex marketplace plugin name for Computer Use.",
"advanced": true
},
"computerUse.mcpServerName": {
"label": "MCP Server Name",
"help": "MCP server name exposed by the Computer Use plugin.",
"advanced": true
},
"codexPlugins": {
"label": "Native Codex Plugins",
"help": "Controls native Codex plugin availability for Codex harness turns.",
"advanced": true
},
"codexPlugins.enabled": {
"label": "Enable Native Plugins",
"help": "Expose explicit Codex plugin entries to Codex harness turns.",
"advanced": true
},
"codexPlugins.allow_all_plugins": {
"label": "Allow All Connected Apps",
"help": "Expose every currently accessible app connected to the authenticated Codex account when a new Codex thread starts.",
"advanced": true
},
"codexPlugins.allow_destructive_actions": {
"label": "Allow Destructive Plugin Actions",
"help": "Default policy for plugin app write or destructive action elicitations. Use true to accept safe schemas without prompting, false to decline, auto to ask through plugin approvals when Codex requires approval, or ask to prompt for every write/destructive action without durable approval.",
"advanced": true
},
"codexPlugins.plugins": {
"label": "Plugin Entries",
"help": "Explicit plugin entries. The wildcard key * is not supported.",
"advanced": true
},
"supervision": {
"label": "Codex Supervision",
"help": "Configure the separate user-home App Server connection used by the native session catalog and optional supervision tools.",
"advanced": true
},
"supervision.enabled": {
"label": "Enable Codex Supervision",
"help": "Enable agent-facing Codex supervision tools. The operator session catalog remains available whenever the plugin is active."
},
"supervision.endpoints": {
"label": "Legacy Supervisor Endpoints",
"help": "Advanced compatibility endpoints for migrated Codex Supervisor agent tools.",
"advanced": true
},
"supervision.allowRawTranscripts": {
"label": "Allow Raw Transcript Tools",
"help": "Allow supervision agent tools, including turn-inclusive codex_threads reads, to expose full transcripts and transcript previews.",
"advanced": true
},
"supervision.allowWriteControls": {
"label": "Allow Write Control Tools",
"help": "Allow supervision agent tools to control turns and let codex_threads fork, rename, archive, or unarchive native threads.",
"advanced": true
},
"appServer": {
"label": "App Server",
"help": "Runtime controls for connecting to Codex app-server.",
"advanced": true
},
"appServer.mode": {
"label": "Execution Mode",
"help": "Legacy Codex app-server preset. Prefer tools.exec.mode=auto for normalized Guardian-reviewed approvals.",
"advanced": true
},
"appServer.transport": {
"label": "Transport",
"help": "Use stdio to spawn Codex locally or unix for the shared local control socket. Remote websocket transport is experimental and unsupported by Codex.",
"advanced": true
},
"appServer.homeScope": {
"label": "Codex Home Scope",
"help": "Use agent for isolated Codex state, or user to share native Codex threads, config, and authentication with Codex Desktop and the CLI.",
"advanced": true
},
"appServer.command": {
"label": "Command",
"help": "Executable used for stdio transport. Leave unset to use OpenClaw's managed Codex binary.",
"advanced": true
},
"appServer.args": {
"label": "Arguments",
"help": "Arguments used for stdio transport. Defaults to app-server --listen stdio://.",
"advanced": true
},
"appServer.url": {
"label": "WebSocket URL",
"help": "Codex app-server WebSocket URL when transport is websocket.",
"advanced": true
},
"appServer.authToken": {
"label": "Auth Token",
"help": "Bearer token sent to the WebSocket app-server.",
"sensitive": true,
"advanced": true
},
"appServer.headers": {
"label": "Headers",
"help": "Additional headers sent to the WebSocket app-server.",
"sensitive": true,
"advanced": true
},
"appServer.clearEnv": {
"label": "Clear Environment",
"help": "Environment variable names removed from the spawned stdio app-server process after overrides are applied.",
"advanced": true
},
"appServer.remoteWorkspaceRoot": {
"label": "Remote Workspace Root",
"help": "Remote Codex app-server workspace root used to project OpenClaw cwd suffixes before starting Codex threads.",
"advanced": true
},
"appServer.codeModeOnly": {
"label": "Code Mode Only",
"help": "Expose Codex's code-mode-only tool surface. OpenClaw dynamic tools remain available through Codex nested tool calls.",
"advanced": true
},
"appServer.loopDetectionPreToolUseRelay": {
"label": "Loop Detection Pre-tool Relay",
"help": "Install the Codex PreToolUse subprocess used only for OpenClaw loop detection and its no-policy marker. Disable to reduce per-tool process fan-out; before-tool and trusted policy relays remain enforced.",
"advanced": true
},
"appServer.requestTimeoutMs": {
"label": "Request Timeout",
"help": "Maximum time to wait for Codex app-server control-plane requests.",
"advanced": true
},
"appServer.approvalPolicy": {
"label": "Approval Policy",
"help": "Codex native approval policy sent to thread start, resume, and turns.",
"advanced": true
},
"appServer.sandbox": {
"label": "Sandbox",
"help": "Codex native sandbox mode sent to thread start and resume.",
"advanced": true
},
"appServer.approvalsReviewer": {
"label": "Approvals Reviewer",
"help": "Use user approvals or Codex auto_review for native app-server approvals. guardian_subagent remains accepted for compatibility.",
"advanced": true
},
"appServer.serviceTier": {
"label": "Service Tier",
"help": "Optional Codex app-server service tier. Use priority, flex, or null. Legacy fast is accepted as priority.",
"advanced": true
},
"appServer.enableUltrafast": {
"label": "Enable Ultrafast (for supported models)",
"help": "Prefer Ultrafast when the shared Fast-mode control is on, active Auto, or unspecified, and the selected model advertises access. Existing opted-in Fast sessions retain this behavior; Standard remains off.",
"advanced": true
},
"appServer.networkProxy": {
"label": "Network Proxy",
"help": "Enable Codex permissions-profile networking for app-server commands.",
"advanced": true
},
"appServer.networkProxy.enabled": {
"label": "Network Proxy Enabled",
"help": "When enabled, OpenClaw defines a Codex permissions profile and selects it with default_permissions instead of sandbox fields.",
"advanced": true
},
"appServer.networkProxy.profileName": {
"label": "Network Proxy Profile",
"help": "Optional stable Codex permissions profile name. Leave unset to use a generated openclaw-network fingerprint name.",
"advanced": true
},
"appServer.networkProxy.baseProfile": {
"label": "Network Proxy Base",
"help": "Filesystem access used by the generated profile. Defaults to read-only for read-only sandboxes and workspace otherwise.",
"advanced": true
},
"appServer.networkProxy.domains": {
"label": "Network Domains",
"help": "Domain allow and deny rules for Codex sandboxed networking.",
"advanced": true
},
"appServer.networkProxy.unixSockets": {
"label": "Unix Sockets",
"help": "Unix socket allow and none rules for Codex sandboxed networking.",
"advanced": true
},
"appServer.networkProxy.proxyUrl": {
"label": "HTTP Proxy URL",
"help": "HTTP listener URL used by Codex sandboxed networking.",
"advanced": true
},
"appServer.networkProxy.socksUrl": {
"label": "SOCKS Proxy URL",
"help": "SOCKS listener URL used by Codex sandboxed networking.",
"advanced": true
},
"appServer.networkProxy.enableSocks5": {
"label": "Enable SOCKS5",
"help": "Expose SOCKS5 support for the generated Codex permissions profile.",
"advanced": true
},
"appServer.networkProxy.enableSocks5Udp": {
"label": "Enable SOCKS5 UDP",
"help": "Allow UDP over the SOCKS5 listener when SOCKS5 is enabled.",
"advanced": true
},
"appServer.networkProxy.allowUpstreamProxy": {
"label": "Allow Upstream Proxy",
"help": "Allow Codex sandboxed networking to chain through inherited HTTP(S)_PROXY or ALL_PROXY settings.",
"advanced": true
},
"appServer.networkProxy.allowLocalBinding": {
"label": "Allow Local Binding",
"help": "Permit broader local and private-network access through Codex sandboxed networking.",
"advanced": true
},
"appServer.networkProxy.mode": {
"label": "Network Mode",
"help": "Codex sandboxed networking mode for subprocess traffic.",
"advanced": true
},
"appServer.networkProxy.dangerouslyAllowNonLoopbackProxy": {
"label": "Allow Non-Loopback Proxy",
"help": "Permit non-loopback bind addresses for Codex sandboxed networking listeners.",
"advanced": true
},
"appServer.networkProxy.dangerouslyAllowAllUnixSockets": {
"label": "Allow All Unix Sockets",
"help": "Bypass Codex's Unix socket allowlist for tightly controlled environments.",
"advanced": true
},
"appServer.defaultWorkspaceDir": {
"label": "Default Workspace",
"help": "Workspace used by /codex bind when --cwd is omitted.",
"advanced": true
},
"appServer.experimental": {
"label": "Experimental",
"help": "Experimental Codex app-server integrations.",
"advanced": true
},
"appServer.experimental.sandboxExecServer": {
"label": "Sandbox Exec Server",
"help": "Route native Codex execution through an OpenClaw sandbox-backed exec-server when OpenClaw sandboxing is active.",
"advanced": true
}
}
}