OpenAI Codex CLI rust-v0.161.0
OpenAI Codex CLI rust-v0.161.0 was released on .
Summary
OpenAI Codex CLI rust-v0.161.0 now defaults to the faster GPT-6.1 Sol model and lets you customize your microphone and speaker settings for voice conversations. You can also log into MCP servers directly from your terminal and get more control over how the CLI accesses your sy...
Release Context
- This was the 105th OpenAI Codex CLI release of 2026 tracked by Havoptic.
- It shipped 2 days after OpenAI Codex CLI rust-v0.160.1 (October 5, 2026).
- OpenAI Codex CLI: ships every 1.4 days — 15 releases in the last month.
Why it matters: GPT-6.1 Sol powers faster code generation by default.
Shipped around the same time
Within 3 days of this release, other AI coding tools also shipped:
- Claude Code v2.1.294 (October 8, 2026)
- Claude Code v2.1.293 (October 7, 2026)
- GitHub Copilot CLI v1.0.93 (October 7, 2026)
- Antigravity CLI v1.3.1 (October 7, 2026)
- Gemini CLI v0.63.0 (October 6, 2026)
Compare OpenAI Codex CLI
Release Notes
New Features - GPT-6.1 Sol is now the default model in the bundled and Amazon Bedrock catalogs. (49318, 49339) - Amazon Bedrock supports multi-agent V2 and Ultra reasoning on compatible models; Bedrock Mantle also accepts AWS GovCloud regions. (49345, 49813) - Sign in to MCP servers from an active terminal session with /mcp login <name>. (49290) - Choose your microphone, speaker, and microphone input channels for voice conversations, with preferences saved locally. (49437, 49836) - Daybreak is opt-in through --enable clidaybreak or features.clidaybreak=true; daybreak=true alone is insufficient. By default, controls and indicators are hidden, /daybreak is unavailable, and automatic Cyber routing is omitted—even for saved Daybreak threads. Saved preferences remain intact. Opt-in routing requires eligible ChatGPT sign-in, the OpenAI provider, and advertised model/program support. (49856, 49858, 49859, 49861, 51207) - Select a Cyber access program per turn with codex exec --cyber-access-program or the TypeScript SDK’s cyberAccessProgram option. The explicit exec override remains available with clidaybreak disabled and leaves the saved choice unchanged. (49939, 51207) Bug Fixes - Approved filesystem escalation can now grant broader write access while preserving denied reads and network restrictions. Background tasks retain their originating turn’s permissions. (49353, 49880) - Explicit launch permissions survive terminal reconnects and new sessions, while implicit client settings no longer overwrite server or saved-thread web-search settings. (49809, 49799) - Elevated Windows terminal sessions can start using an embedded server, and sandboxed PowerShell preserves relative paths beneath protected user profiles. (49855, 49690) - Enter correctly submits buffered input after paste detection expires, including in Vim insert mode. (49810) - Thread resume includes the latest committed history. Startup detects recoverable SQLite corruption earlier and preserves damaged databases as backups. (49599, 49701) - Responses retries and WebSocket-to-HTTP fallback honor server retry guidance, reducing premature failures during overload. (49441) Documentation - Authentication guidance now accounts for keyring storage instead of implying credentials always reside in auth.json. (49361) Chores - Publishing an older alpha or hotfix no longer moves npm alpha tags backward. (49704) Changelog Full Changelog: https://github.com/openai/codex/compare/rust-v0.160.0...rust-v0.161.0 - 49246 Use executable fixture copying in the bundled bwrap test @felixxia-oai - 49257 Allow Guardian cached approvals with incomplete root context @felixxia-oai - 49260 Restrict enterprise MCP auth and fail closed on config refresh @nicksteele-oai - 49261 Preserve Windows sandbox runner launch errors @zm-oai - 49262 Trace turn phases and correlate accepted input with turns @jif-oai - 49266 Remove the remote agent message board client README @jif-oai - 49267 Support remote agent message boards in multi-agent sessions @jif-oai - 49269 Preserve thread overrides and cloud policy validity during config reloads @nicksteele-oai - 49275 Isolate realtime conversation tests from Responses prewarm connections @felixxia-oai - 49276 Enable enterprise MCP sign-in and account-scoped grant cleanup @nicksteele-oai - 49277 Avoid a turn teardown race in the Guardian agent message test @felixxia-oai - 49280 Restrict capability roots to captured turn environments @miz-openai - 49286 Model exec-server session attachment state as an enum @jif-oai - 49290 Add /mcp login <name> to the TUI @nicksteele-oai - 49294 Record Guardian context mode in review and classification telemetry @felixxia-oai - 49295 Simplify configuration fingerprint canonicalization @jif-oai - 49297 Scan the session index backwards for batch thread name lookups @jif-oai - 49300 Compact the inline hidden tag buffer once per chunk @jif-oai - 49305 Batch metadata reads when resolving thread names @jif-oai - 49308 Run piped legacy Windows sandbox processes without a console @etraut-openai - 49312 Notify parent agents when Guardian stops a subagent @jif-oai - 49316 Bump taiki-e/install-action to v2.87.21 in CI setup @jgershen-oai - 49318 Add GPT-6.1 Sol as the default catalog model @andrewgu-oai - 49325 Retry Windows sandbox runner logon once on error 1056 @zm-oai - 49330 Keep remote control reconnect backoff capped during sustained failures @yansenzhou-oai - 49332 Clean up canceled exec-server RPC requests immediately @jif-oai - 49339 Add GPT-6.1 Sol to Bedrock catalogs and make it the default @celia-oai - 49345 Enable multi-agent V2 and Ultra reasoning on Amazon Bedrock @celia-oai - 49353 Allow approved filesystem escalation while preserving denied reads @viyatb-oai - 49357 Continue Markdown blockquotes when pasting multiline text @bc-openai - 49360 Carry shell invocation metadata and report executor PATH directories @anp-oai - 49361 Clarify credential storage wording across authentication UI and docs @celia-oai - 49369 Update Bedrock GPT-6 Sol catalog tests to expect multi-agent V2 @celia-oai - 49379 Compile hook matchers during discovery @jif-oai - 49384 Track credential storage outcomes and redact sensitive errors @celia-oai - 49388 Fix Windows path inference for opaque URIs with slash prefixes @dkovalenko-oai - 49389 Serialize tests that share Windows sandbox accounts @jgershen-oai - 49392 Add attributed MCP OAuth credential storage telemetry @celia-oai - 49395 Remove randomized greetings from TUI session headers @etraut-openai - 49401 Preserve live tool-call metadata across request windows @ningyi-oai - 49403 Add an experimental flag for bundled tools in login shells @anp-oai - 49406 Support explicit cyber access programs with OpenAI API keys @julee-oai - 49407 Recover exec-server sessions after environment info timeouts @vivi - 49408 Compare tool call metadata in the recorder refresh test @euroelessar - 49411 Bind the app-server time provider to a local variable @euroelessar - 49414 Filter graceful shutdown guard and trigger traces from SQLite logs @dkovalenko-oai - 49415 Truncate input text in protocol debug output @dkovalenko-oai - 49416 Omit payloads from multiline ANSI warnings @dkovalenko-oai - 49424 Infer Windows UNC paths with forward and mixed slashes @dkovalenko-oai - 49425 Prune diagnostic logs periodically by age and database size @dkovalenko-oai - 49426 Enable analytics by default for daemon-launched app servers @bc-openai - 49432 Preserve bootstrap discovery across authentication changes @cooper-oai - 49437 Add local audio device selection to TUI voice settings @bc-openai - 49441 Honor server retry advice across Responses retries and fallback @anp-oai - 49444 Use memrchr to find newlines in reverse JSONL scans @btraut-openai - 49467 Restore executor tool paths after login shell startup @anp-oai - 49472 Use server-authoritative permissions in the TUI @etraut-openai - 49473 Use the rmcp SDK for enterprise-managed token exchanges @nicksteele-oai - 49475 Complete turn abort callbacks before emitting terminal events @euroelessar - 49478 Discover and validate MCP authorization servers before ID-JAG exchange @nicksteele-oai - 49480 Add experimental thread prediction protocol types @keyz - 49489 Add regression coverage for account switches between analytics batches @anp-oai - 49517 Add a fork shortcut to the TUI command center @etraut-openai - 49560 Add an opt-in model catalog to multi-agent context @jif-oai - 49564 Copy selected file paths as plain text in the TUI @fcoury-oai - 49584 Skip host skill discovery for Guardian reviews @jif-oai - 49595 Make the strict network approval test independent of request order @jif-oai - 49598 Persist explicit user goal edits in model history @felixxia-oai - 49599 Return authoritative replay history when resuming a thread @felixxia-oai - 49600 Reuse unchanged history snapshots when resuming threads @felixxia-oai - 49624 Use server authentication for explicit remote session commands @cooper-oai - 49642 Allow managed requirements to disable the Windows MXC sandbox @iceweasel-oai - 49675 Serialize Responses routing fields before large inputs @jbeckwith-oai - 49678 Escape command drafts when recovering question answers @imac-oai - 49683 Add a managed feature gate for in-app voice @vishnu-oai - 49686 Deliver remote message board notifications to active turns @jif-oai - 49689 Export skill invocation events through OpenTelemetry @jif-oai - 49690 Preserve PowerShell relative paths in the elevated Windows sandbox @johnl-oai - 49692 Keep compressed rollout snippet searches on one blocking worker @npancha-openai - 49693 Move thread history projection into one blocking task @charliemarsh-oai - 49694 Batch rollout listing scans on cancellable blocking workers @charliemarsh-oai - 49696 Make exec-server file reads cancellable between chunks @charliemarsh-oai - 49701 Detect SQLite corruption during startup and preserve recovery backups @dkovalenko-oai - 49702 Rename exec-server file handle management identifiers @anp-oai - 49704 Prevent npm alpha dist-tags from moving backward @imac-oai - 49706 Upgrade the argument comment lint toolchain and Dylint @tamird - 49708 Move session index I/O off async runtime threads @charliemarsh-oai - 49710 Classify SQLite corruption using typed error codes @dkovalenko-oai - 49712 Avoid full-string scans in token-budget truncation @jif-oai - 49713 Remove repository-local Codex guidance, skills, and environment config @anp-oai - 49714 Decouple API-key cyber access programs from model discovery @julee-oai - 49715 Add account security setup reminders to the TUI @dennyku - 49778 Define exec-server protocol types for streamed file writes @anp-oai - 49781 Include the environment's MXC backend in MCP sandbox metadata @zm-oai - 49782 Clean up process groups for failed shell snapshot captures @jif-oai - 49783 Preserve background thread requests when forking in the TUI @etraut-openai - 49784 Add a requirements feature gate for the browser annotation API @tepman-oai - 49785 Persist empty paginated threads when naming them @rd-oai - 49786 Clarify V2 spawn model override guidance for context catalogs @jif-oai - 49787 Remove AGENTS.md from Bazel core test data @andrewgu-oai - 49792 Add retained conversation support to Guardian async sampling @felixxia-oai - 49793 Add conversation mode to Guardian v2 async classification @felixxia-oai - 49795 Avoid duplicate sync reviews in Guardian classifier continuations @felixxia-oai - 49796 Deduplicate Guardian retained-context omission notices @felixxia-oai - 49798 Share cached exec-server environment info with Arc @anp-oai - 49799 Preserve server web-search settings in the TUI @etraut-openai - 49800 Allow cleanup of replay-only side conversations with missing threads @bc-openai - 49801 Update the Rust toolchain action for argument-comment linting @andrewgu-oai - 49804 Use platform-specific modifier labels in TUI shortcut hints @bc-openai - 49805 Add capability-gated writable file streams to the exec-server client @anp-oai - 49806 Accept unknown Codex error variants in the app-server protocol @anp-oai - 49807 Enable API-key model discovery by default @andrewgu-oai - 49809 Preserve local launch permissions across TUI sessions and reconnects @etraut-openai - 49810 Flush expired paste bursts before handling Enter @bc-openai - 49811 Handle unsupported fs/writeBlock requests in exec-server @anp-oai - 49812 Move shadow skill ranking off the turn preparation path @vkg-oai - 49813 Support AWS GovCloud regions for Amazon Bedrock Mantle @alexsong-oai - 49814 Add coordinated shutdown for local agent trees @owenlin0 - 49816 Remove browser-open success messages from the TUI @bc-openai - 49817 Add an advisory Bedrock GovCloud requirements check @alexsong-oai - 49818 Use dedicated parameters for sandboxed file opens @anp-oai - 49819 Recover daemon startup and updater re-exec after cwd deletion @etraut-openai - 49822 Box the resume future in the agents overview permissions test @sayan-oai - 49835 Clarify service tier default save errors in the TUI @etraut-openai - 49836 Allow microphone channel selection for voice conversations @bc-openai - 49843 Preserve daemon diagnostics and include updater logs in reports @etraut-openai - 49846 Capture host-supplied extension data for each turn @sayan-oai - 49847 Persist world-state snapshots alongside rendered context @pakrym-oai - 49850 Launch Windows daemon children in a dedicated working directory @etraut-openai - 49852 Improve diagnostics for report attachment failures @dkovalenko-oai - 49855 Use embedded mode for elevated Windows TUI sessions @etraut-openai - 49856 Support Daybreak selection in codex exec @etraut-openai - 49857 Use the model catalog to select TUI cyber refusal guidance @etraut-openai - 49858 Add a persistent /daybreak toggle to the TUI @etraut-openai - 49859 Honor Daybreak settings in TUI continuations and background tasks @etraut-openai - 49861 Add Daybreak state to the status line and terminal title @etraut-openai - 49867 Update elevated-launch warning snapshot to use ⌃o for copy @etraut-openai - 49874 Point usage and credit links to ChatGPT settings @etraut-openai - 49875 Decouple TUI startup presentation from execution configuration @etraut-openai - 49876 Remove personality plumbing from the TUI @etraut-openai - 49880 Bind permission grants to the originating turn @anp-oai - 49894 Return world-state snapshots and context updates together @pakrym-oai - 49898 Scope extension filesystem access to callback permissions @anp-oai - 49910 Preserve validation errors for invalid TUI keybindings @etraut-openai - 49912 Respect approval policies in temporary structured threads @etraut-openai - 49939 Add per-turn Cyber access program selection to exec and the SDK @mldangelo-oai - 49946 Prevent stale file search results from being labeled with a new query @jif-oai - 49951 Include preceding assistant context in Guardian sender reviews @jif-oai - 49956 Cache the placeholder regex for MCP hook argument expansion @jif-oai - 49959 Test session index thread-name append and removal @jif-oai - 49972 Share byte buffers across exec-server output chunks @jif-oai - 49987 Add renewable EMA HTTP authentication and credential versioning @nicksteele-oai - 49993 Preserve the async Guardian history prefix as retained context changes @felixxia-oai
Other Recent OpenAI Codex CLI Releases
- rust-v0.160.0 (October 1, 2026)
- rust-v0.159.3 (September 30, 2026)
- rust-v0.159.2 (September 29, 2026)
- rust-v0.159.1 (September 29, 2026)
- rust-v0.159.0 (September 29, 2026)
All OpenAI Codex CLI releases · All AI coding tool releases on Havoptic