Repository navigation
[Feature]: Support Codex Computer Use approval flow in T3 Code #2156
Description
Activity
I hit the same wall on Windows and ended up implementing both halves of this. Sharing what I found and offering the smaller half as a PR if there's interest.
Root cause (why no approval ever appears)
Two independent gaps in the
codex app-serverpath:- T3's Codex session runtime has no handlers for the approval methods Codex raises for Computer Use —
item/permissions/requestApprovalandmcpServer/elicitation/request(withcodex_approval_kind: "mcp_tool_call") — and doesn't advertisemcpServerOpenaiFormElicitationat initialize. The request goes nowhere, so the turn stalls with no UI. This is platform-neutral and affects any MCP tool approval, not just Computer Use. - Separately (Windows, transport-level): the
node_replconfig inherited from Codex pointsSKY_CUA_NATIVE_PIPE_DIRECTORYat a Codex-Desktop-owned pipe that doesn't exist when T3 owns the app-server, so the Computer Use transport can't connect at all. (The macOS analog appears to be the entitlement/TCC layer — see fix(desktop): allow Codex Computer Use automation on macOS #2796.)
What I have working
On a branch (Windows 11, GPT-5.6 Codex, Supervised mode): the approval popup renders in T3's pending-approval panel ("Allow Codex to use ?", per-app, with approve-once / approve-for-session), approving resumes the tool call, and screenshots + window text come back correctly. Reference branch: https://github.com/Nelglor/t3code/tree/codex/computer-use (single commit on top of v0.0.33:
0b29564de)It splits cleanly:
- Approval plumbing (small, cross-platform) — two new request kinds (
tool,permissions) through contracts → CodexAdapter → ingestion → the existing pending-approval panel, plus the initialize capability flag. Tests at each layer. This is the "smallest useful scope" in the issue body: approvals surface instead of silently stalling. - Windows transport bridge (larger, opinionated) — a per-session local pipe to Codex's own
codex-computer-use.exehelper, with a SHA-256-pinned facade module so sandboxed model code only reaches the desktop through a vetted surface. I'm treating this as reference code only, not proposing it for merge.
Screenshots
<screenshot: approval lifecycle in the work log>

<screenshot: confirmed end-to-end result>

Known rough edge visible above: approval identity comes from the target executable, so unpackaged Electron apps share a grant and the display name can resolve to a different Electron app — here the prompt says "Iris" for a dev-mode T3 Code window, because both run as
electron.exeand the display name comes from Codex's helper. Packaged apps with their own executable names are unaffected.Offer
Per CONTRIBUTING: happy to open a small, focused PR for the approval-plumbing half (with before/after screenshots of the approval panel), or you're welcome to take any of the branch as reference and reimplement — or neither. Just flagging that the confusing state described in this issue is reproducible, diagnosable, and fixable in two separable steps.
Relation to #5533: complementary — that adds an external computer-use engine as an opt-in MCP server with no per-action approvals; this makes Codex's native Computer Use approvals reach T3's UI, and the same
toolapproval kind would give #5533-style tools a per-action approval surface too.- T3's Codex session runtime has no handlers for the approval methods Codex raises for Computer Use —
- added 6 commits that reference this issue
on Aug 13, 2026 - locked and limited conversation to collaborators
on Aug 15, 2026

Problem or use case
I can use Codex with the bundled
computer-useplugin in the Codex ecosystem, but in T3 Code there is no visible approval flow for enabling or authorizing Computer Use.From the user perspective, this makes Computer Use feel unsupported or broken:
codex app-servercomputer-useplugin can be enabledRight now it is hard to tell whether:
Proposed solution
When a Codex session requests Computer Use, T3 Code should surface a first-class approval flow in the UI.
At minimum:
Ideally, T3 Code would support the same practical workflow users expect from Codex Desktop:
Why this matters
This would make T3 Code much more trustworthy and understandable for users trying advanced Codex capabilities.
Without this, users get stuck in a confusing state where:
A clear approval flow, or even a clear unsupported-state message, would remove a lot of confusion.
Smallest useful scope
The smallest useful version would be:
Even that would be much better than failing silently.
Alternatives considered
Those can help debug, but they do not solve the missing T3 Code UX.
Risks or tradeoffs
codex app-serverapp-serverpath, so the UI should avoid implying support if the backend cannot actually provide itExamples or references
Related issues:
.codex/config.toml. #297 The app does not load a local MCP server defined in.codex/config.toml.This request is specifically about surfacing the Codex Computer Use approval or support flow inside T3 Code.