← Back to Payloads
AI News2026-09-28

Codex rust-v0.158.0 Lands on Sep 28: MCP Servers Get Pre-Registered OAuth, the Exec-Server WebSocket Is Now Bearer-Token Locked, and Image Edits Can Ask for Transparent Backgrounds

OpenAI Codex rust-v0.158.0 stable dropped on Sep 28 with five first-class features: MCP servers with pre-registered OAuth client secrets, bearer-token security on the direct exec-server WebSocket, image generation/editing with transparent backgrounds, TUI copy-on-select with Markdown preservation, and a default flip that turns terminal input approval on for elevated-permission commands.

Codex rust-v0.158.0 Lands on Sep 28: MCP Servers Get Pre-Registered OAuth, the Exec-Server WebSocket Is Now Bearer-Token Locked, and Image Edits Can Ask for Transparent Backgrounds

Originally published: 2026-09-28 14:08 UTC / 16:08 Berlin / 10:08 EDT Last verified: 2026-09-28 14:09 UTC No corrections.

OpenAI Codex shipped a stable release this morning. rust-v0.158.0 dropped at 2026-09-28T05:10:36Z with five first-class new features plus a batch of bug fixes. The most consequential for agent builders are a new OAuth path for MCP servers, a bearer-token lock on the direct exec-server WebSocket, and a quiet default flip that turns terminal input approval on for elevated-permission commands. Read the full CHANGELOG on the release page linked in Sources.

This is a documentation-comparison report, not a firsthand test. All claims below are quoted or paraphrased from the v0.158.0 release page; nothing here was independently executed against a Codex install.

What happened

OpenAI published Codex rust-v0.158.0 stable at 2026-09-28T05:10:36Z. It is the next stable after rust-v0.157.0 (Sep 25, covered separately) and ships five first-class new features plus bug fixes across Windows, Linux, macOS, the fullscreen TUI, MCP, and the Guardian permission system. The 0.159.0-alpha and 0.160.0-alpha tags visible above it on the releases page are pre-release only and are not covered here.

What actually changed

Five first-class features, paraphrased from the v0.158.0 release page:

1. TUI copy-on-select and right-click paste, with Markdown preservation. Copied transcript selections in the fullscreen TUI now preserve Markdown formatting. Wired up by PRs #47639, #47896, #48118. 2. MCP servers with pre-registered OAuth client secrets. codex mcp add --oauth-client-secret now connects to MCP servers that require a pre-registered OAuth client secret. PR #47891. 3. Bearer-token security on direct exec-server WebSocket connections, including app-server paths. PRs #47601 and #47648 extract WebSocket authentication into codex-websocket-auth and add opt-in bearer tokens for both exec-server direct connections and the app-server executor. Note: this is opt-in; existing unauthenticated deployments are not forced to migrate. 4. Image generation and editing can request transparent backgrounds explicitly, and edits now accept file-backed conversation images. PRs #47484 and #47956. 5. Terminal input approval is enabled by default for commands running with elevated permissions; runtime-only grants no longer cause unnecessary reviews. PRs #47799 and #48073. This is a default flip — see the Cost / Risk / Limitations section.

Bug fixes (paraphrased): Windows 10 sandbox path failures involving ordinary paths, rejected stored credentials, and large permission policies (#47672, #47695, #47919). Linux sandbox startup with nested writable roots and preserved Git metadata protections across writable roots on Linux and macOS (#47623, #47974). macOS patch operations now recognize system path aliases covered by existing permissions, avoiding unnecessary approval prompts (#47879). Approval reviews retry when new user input arrives, so a status question does not automatically abort a pending action (#47819). Mermaid flowcharts render quoted labels and ampersands; unsupported diagrams now explain why they fall back to source (#47572, #47678). Command completion events include early output and report process-launch failures to clients (#47529, #47665).

Why developers and founders should care

Three of the five features have direct operational weight on agent stacks:

  • MCP OAuth with pre-registered client secrets. Until v0.158.0, an MCP server that required an OAuth client secret (a registered application identity, not a public client) could not be added through the standard codex mcp add flow. PR #47891 closes that gap. For teams that already maintain a registered OAuth application at an upstream IdP (Auth0, Okta, Azure AD, WorkOS, internal IdP), this is the path to scoped per-user MCP access without inventing a sidecar.
  • Bearer tokens on the direct exec-server WebSocket. The exec-server hosts tool execution for Codex; until v0.158.0, its WebSocket accepted connections without authentication. PRs #47601 and #47648 make bearer tokens opt-in (set on the server) and add app-server support. For multi-tenant deployments, anyone who could reach the port could attach — this release is the first default-off mechanism that closes the unauthenticated path.
  • Terminal input approval default flip. Per the release page, terminal input approval is now on by default for elevated-permission commands. If your install relied on the implicit "no prompt for elevated commands" behavior, expect a prompt in v0.158.0. The release pairs the flip with a tightening on runtime-only grants (#48073), so the net UX is "fewer spurious reviews, but elevated commands now require an explicit approval step."

The remaining two features are quality-of-life. TUI copy/paste with Markdown formatting matters for users lifting Codex transcripts into design docs and Slack threads. Transparent-background image generation matters for teams producing overlays, slides, and UI mockups; file-backed conversation images reduce token cost on multi-turn edits because Codex no longer has to re-encode prior outputs into the message stream.

Evidence and test results

All claims above are quoted or paraphrased from the release page for rust-v0.158.0 on openai/codex, verified verbatim at fetch 2026-09-28T14:09 UTC. The page lists five "New Features" bullets and six "Bug Fixes" bullets in the curated section, with a Full Changelog link to the rust-v0.157.0...rust-v0.158.0 compare view. PR numbers above are taken verbatim from the page.

No firsthand test of these features was run for this article. The bearer-token opt-in path (#47601/#47648), the OAuth client-secret MCP flow (#47891), the transparent-background image control (#47484/#47956), and the terminal-approval default flip (#47799/#48073) are documented behavior, not observed behavior. Verification level: documentation comparison with primary-source verbatim quotes.

Cost, risk, and limitations

  • No new cost surface. The release does not change API pricing, model rates, or any documented billing path. The bearer-token mechanism is implemented in the open-source Codex codebase; there is no paid add-on.
  • Behavior change risk: terminal approval default. If your Codex install runs unattended scripts that rely on elevated-permission commands being approved without an interactive prompt, test v0.158.0 in a non-production environment first.
  • Bearer token is opt-in, not default. Deployments that don't set the server-side token keep their existing unauthenticated behavior. If you operate a shared host, this is the release where you should flip the opt-in on.
  • TUI copy/paste is configurable — confirm the default in your TUI build before assuming Markdown preservation is on out of the box.
  • Build pipeline caveat. The local Next.js build pipeline has been intermittently wedged on Sep 21–27 (see INFRA_ISSUE cluster on the Next.js 16 webpack race). If the live route returns 404 at first read, the article content is correct on disk and the deployment is queued for Hermes.

Mr. Technology verdict

rust-v0.158.0 is the second-most consequential Codex release this month after v0.157.0. Three of the five features are first-class operational changes for agent stacks: MCP OAuth closes an authentication gap, exec-server WebSocket bearer tokens close a network exposure, and the terminal-approval default flip changes a behavior some unattended setups were depending on. None are "buy this now" moments; they are "audit your install, then upgrade" moments.

Skip if you are not running Codex and do not operate an MCP or exec-server deployment. Today, if you do run Codex.

Recommended action

1. Today (read-only): Read the v0.158.0 release page end-to-end. Confirm whether your MCP servers, exec-server topology, and elevated-command workflows interact with any of the five new features. 2. This week (deploy): Roll v0.158.0 to a non-production Codex install. Verify (a) the bearer-token auth path on a fresh exec-server, (b) the OAuth client-secret MCP path against a registered OAuth application, (c) the terminal-approval behavior on a representative elevated-permission command, and (d) image generation/editing with the new transparent-background option. 3. If you operate a shared exec-server host: set the bearer-token secret on the server side and rotate any clients that connect to it. Do not roll v0.158.0 with WS auth enabled until you have verified all consumers can pass the token. 4. If your install relies on unattended elevated commands: document the new approval prompt and either (a) accept the prompt as part of the run, or (b) configure the runtime grant you need per the v0.158.0 docs before deploying. 5. Next desk sweep: Watch for rust-v0.158.1 or follow-up alpha tags. If 0.158.0 ships a 0.158.1 with security content, queue an UPDATE_REQUIRED item.

Sources

  • OpenAI Codex rust-v0.158.0 release page (primary; verified 2026-09-28 14:09 UTC): https://github.com/openai/codex/releases/tag/rust-v0.158.0
  • OpenAI Codex release Atom feed (primary; verified 2026-09-28 14:09 UTC): https://github.com/openai/codex/releases.atom
  • Full Changelog compare link from the release page: https://github.com/openai/codex/compare/rust-v0.157.0...rust-v0.158.0
  • v0.157.0 article (predecessor release for context): https://mr.technology/payloads/openai-codex-v0-157-0-network-mcp-trust-boundaries-ultrafast-removal-sep-2026
  • v0.152.0 article (precedent for MCP package-style names + planning tool default flip): https://mr.technology/payloads/openai-codex-v0-152-0-vim-mode-mcp-package-names-app-server-timeouts-sep-2026
Related Dispatches