approvalPolicy
Controls when user approval is required
How to use it
approvalPolicy is exposed by the Codex MCP Server MCP server. Add the server to your MCP client (Claude Desktop, Cursor, Windsurf and others), and the approvalPolicy tool becomes available to the model automatically. See the full listing for setup details and every tool this server provides.
Install Codex MCP Server
claude mcp add codex-cli -- npx -y @cexll/codex-mcp-serverOther tools in Codex MCP Server (18)
(o3-based for software engineering)
(low-latency code Q&A)
Full system access including network
Shorthand for sandboxMode: "workspace-write" + approvalPolicy: "on-failure"
(also available)
(general purpose, fast reasoning)
(default, optimized for coding)
~/Library/Application Support/Claude/claudedesktopconfig.json
No approvals required
(smartest, deep reasoning)
(fast & efficient)
Only ask when operations fail
Ask before every action
Analysis only, no file modifications
Controls file system access level
Maximum paranoia mode
Can modify files in workspace
⚠️ Bypasses all safety checks (dangerous, not recommended)