Skip to content

[Feature]: Support Codex Computer Use approval flow in T3 Code #2156

Description

@leonardoxr

Problem or use case

I can use Codex with the bundled computer-use plugin in the Codex ecosystem, but in T3 Code there is no visible approval flow for enabling or authorizing Computer Use.

From the user perspective, this makes Computer Use feel unsupported or broken:

  • T3 Code wraps codex app-server
  • the Codex-side computer-use plugin can be enabled
  • but when a prompt asks to use Computer Use, T3 Code does not surface an allow prompt or clear unsupported-state message

Right now it is hard to tell whether:

  • T3 Code does not support this capability yet
  • the capability is available but the approval UX is missing
  • or macOS permissions need to be granted somewhere else

Proposed solution

When a Codex session requests Computer Use, T3 Code should surface a first-class approval flow in the UI.

At minimum:

  • detect that the session is attempting to use Codex Computer Use
  • show a clear prompt explaining what access is needed
  • route the user through any required desktop permission flow
  • show a clear error or unsupported message if this capability is not yet supported in T3 Code

Ideally, T3 Code would support the same practical workflow users expect from Codex Desktop:

  • request or approve Computer Use from the UI
  • explain required macOS permissions like Accessibility and Screen Recording
  • make the capability state visible per session

Why this matters

This would make T3 Code much more trustworthy and understandable for users trying advanced Codex capabilities.

Without this, users get stuck in a confusing state where:

  • Computer Use appears enabled on the Codex side
  • prompts to use it do not work in T3 Code
  • and there is no clear indication whether the blocker is product support, app permissions, or missing UI

A clear approval flow, or even a clear unsupported-state message, would remove a lot of confusion.

Smallest useful scope

The smallest useful version would be:

  • detect when a session tries to use Codex Computer Use
  • show a clear message that this is unsupported in T3 Code today, or
  • if supported, show the approval prompt and required permission guidance

Even that would be much better than failing silently.

Alternatives considered

  • Using Codex Desktop directly for Computer Use
  • Checking local Codex MCP or plugin config outside T3 Code
  • Manually inspecting macOS permissions

Those can help debug, but they do not solve the missing T3 Code UX.

Risks or tradeoffs

  • This may require extra plumbing between T3 Code and codex app-server
  • Desktop permission handling on macOS may need app-specific UX and documentation
  • The capability may differ between the desktop app and the app-server path, so the UI should avoid implying support if the backend cannot actually provide it

Examples or references

Related issues:

This request is specifically about surfacing the Codex Computer Use approval or support flow inside T3 Code.

Activity

  1. Nelglor commented on Aug 10, 2026

    @Nelglor
    Contributor

    I hit the same wall on Windows and ended up implementing both halves of this. Sharing what I found and offering the smaller half as a PR if there's interest.

    Root cause (why no approval ever appears)

    Two independent gaps in the codex app-server path:

    1. T3's Codex session runtime has no handlers for the approval methods Codex raises for Computer Use — item/permissions/requestApproval and mcpServer/elicitation/request (with codex_approval_kind: "mcp_tool_call") — and doesn't advertise mcpServerOpenaiFormElicitation at initialize. The request goes nowhere, so the turn stalls with no UI. This is platform-neutral and affects any MCP tool approval, not just Computer Use.
    2. Separately (Windows, transport-level): the node_repl config inherited from Codex points SKY_CUA_NATIVE_PIPE_DIRECTORY at a Codex-Desktop-owned pipe that doesn't exist when T3 owns the app-server, so the Computer Use transport can't connect at all. (The macOS analog appears to be the entitlement/TCC layer — see fix(desktop): allow Codex Computer Use automation on macOS #2796.)

    What I have working

    On a branch (Windows 11, GPT-5.6 Codex, Supervised mode): the approval popup renders in T3's pending-approval panel ("Allow Codex to use ?", per-app, with approve-once / approve-for-session), approving resumes the tool call, and screenshots + window text come back correctly. Reference branch: https://github.com/Nelglor/t3code/tree/codex/computer-use (single commit on top of v0.0.33: 0b29564de)

    It splits cleanly:

    • Approval plumbing (small, cross-platform) — two new request kinds (tool, permissions) through contracts → CodexAdapter → ingestion → the existing pending-approval panel, plus the initialize capability flag. Tests at each layer. This is the "smallest useful scope" in the issue body: approvals surface instead of silently stalling.
    • Windows transport bridge (larger, opinionated) — a per-session local pipe to Codex's own codex-computer-use.exe helper, with a SHA-256-pinned facade module so sandboxed model code only reaches the desktop through a vetted surface. I'm treating this as reference code only, not proposing it for merge.

    Screenshots

    <screenshot: approval prompt>
    Image

    <screenshot: approval lifecycle in the work log>
    Image

    <screenshot: confirmed end-to-end result>
    Image

    Known rough edge visible above: approval identity comes from the target executable, so unpackaged Electron apps share a grant and the display name can resolve to a different Electron app — here the prompt says "Iris" for a dev-mode T3 Code window, because both run as electron.exe and the display name comes from Codex's helper. Packaged apps with their own executable names are unaffected.

    Offer

    Per CONTRIBUTING: happy to open a small, focused PR for the approval-plumbing half (with before/after screenshots of the approval panel), or you're welcome to take any of the branch as reference and reimplement — or neither. Just flagging that the confusing state described in this issue is reproducible, diagnosable, and fixable in two separable steps.

    Relation to #5533: complementary — that adds an external computer-use engine as an opt-in MCP server with no per-action approvals; this makes Codex's native Computer Use approvals reach T3's UI, and the same tool approval kind would give #5533-style tools a per-action approval surface too.

  2. locked and limited conversation to collaborators on Aug 15, 2026
  3. converted this issue into a discussion #6726 on Aug 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions