PTENES
Skip to content
MODULE 2.1

🤝 Claude uses Codex

The mods videos connected Claude to Codex with an improvised wire. Here you do the same through the official route: the command codex exec, wrapped in a bridge just a few lines long. It’s recipe R1 from the kit.

6
Topics
~35
Minutes
R1
Recipe
Practical
Type
0 of 60%
1

Understand the codex-exec bridge

Codex has a headless mode: codex exec. You send a request, it works on it, and returns the final answer. That's a CLI, step 3 on the route ladder.

The kit wraps that command in a short script: runtime/pontes/codex-exec.sh. É a bridge. It already chooses the model, applies the policy, and returns only the relevant text.

Claude remains the decision-maker. Codex becomes a colleague Claude consults, like asking for another team member’s opinion.

🆕 New here? Four words from this module

  • Script — a text file with commands in sequence. You run the file, and it executes everything in order.
  • stdin (standard input) — the “pipe” through which a program receives text. The bridge sends your request to Codex through this pipe.
  • Sandbox — a sandbox: the enclosed space where Codex works. It determines whether it can only read or can also write files.
  • Output — what the program prints in the terminal. When there’s an error, it also returns a number (for example, “exit code 2”).
Claude Code decides and asks codex-exec.sh check the sandbox (POLITICA) request via stdin · timeout codex exec through the subscription returns only the final answer (the rest of the log is discarded)

How to read the diagram: the blue box in the middle is the bridge. All the rules live in it: which sandbox applies, how long to wait, and what to return. The dashed arrow below is the response going back to Claude.

⌨️
codex exec

the official method (CLI)

🌉
Bridge

codex-exec.sh

📦
Sandbox

only reads, or reads and writes

💳
Subscription

uses quota, not API

2

Test the bridge by itself

Before putting Claude in the middle, test the bridge directly in the terminal. If it fails here, it’ll fail inside the agent too, and then it’s hard to tell who’s at fault.

The test is as simple as possible: ask Codex to respond with a single word. If the word comes back, the bridge, login, and quota are working.

1

Check your Codex login

The doctor in module 1.2 has to show codex ok and "Logged in using ChatGPT". If it doesn't show up, run codex login.

2

Give the script execution permission

O chmod +x marks the file as "ready to run". You only need to do this once.

3

Ask for the PONG

One sentence, one word back. It's proof that recipe R1 works.

🎯 Objective: prove that the bridge communicates with Codex

In the terminal, from inside the kit folder:

chmod +x runtime/pontes/codex-exec.sh
runtime/pontes/codex-exec.sh "Responda apenas PONG"

Result confirmed in CHANGELOG 0.1.0:

PONG
How to verify: the only line printed is PONG. If you see codex falhou; log:, read the following lines and go to topic 6.

💡 Why such a silly test

A one-word request uses almost no quota and gets a quick response. It helps distinguish a bridge problem (login, installation) from a request problem. Only after that should you ask for anything serious.

🔑
codex login

through the subscription

✅
chmod +x

can run

🏓
PONG

the proof of R1

🧪
Alone

before the agent

3

Ask for a second opinion from inside Claude

Now for real-world use. Open Claude and ask it to consult Codex. Claude runs the bridge, reads the response, and compares it with its own.

Why is this worth it? Rule 3 of the ROTEAMENTO.md responds: review by another one model catches errors the same model doesn’t see. Two different perspectives make mistakes in different places.

🎯 Objective: Claude consults Codex and combines both opinions

Open claude in the kit folder and paste:

Use runtime/pontes/codex-exec.sh to ask Codex to review the README.md file: what might confuse a beginner? Then compare its feedback with your opinion.
How to verify: Claude asks to run runtime/pontes/codex-exec.sh and, in its response, separates what Codex said from what it thinks.
📄 README.md Claude's reading first opinion Codex's reading via codex-exec.sh comparison what both saw and what only one saw

How to read the diagram: the same file follows two independent paths. The value is in the box on the right: what only one of the two pointed out is exactly what you wouldn't have seen by asking just one model.

Clara can use the same idea with her data. She asks Claude: “Use runtime/pontes/codex-exec.sh to ask Codex to check whether runtime/exemplos/agenda.csv there are two appointments at the same time with the same provider. Then check it yourself too.”

✓ It’s okay to ask for a second opinion

  • ✓ Review text intended for a client or team
  • ✓ Check an account or an important spreadsheet
  • ✓ Before a decision that's hard to undo
  • ✓ When Claude seems too confident

✗ Not worth it

  • ✗ Trivial task that a model can handle on its own
  • ✗ Every question, out of habit: uses quota on both sides
  • ✗ When you won’t read the comparison
  • ✗ To “break a tie” without looking at the evidence
👀
Another model

routing rule 3

🧭
Claude decides

Codex gives its opinion

📖
Read-only

bridge pattern (N4)

⚖️
Compare

what only one saw

4

Let Codex modify files

By default, the bridge uses the sandbox read-only: Codex reads, but doesn't write anything. That's the "read" ceiling of the POLITICA.md, level N4.

When you want it to create or modify files, pass two more arguments: the folder and the sandbox workspace-write. This raises the action to "modify," level N3: it does it and notifies you.

SandboxCodex canAction in POLITICALevel
read-only (default)read files in the folderRead a file, page, or spreadsheetN4
workspace-writeread and write inside the specified folderCreate/modify project fileN3

What to look for in the table: there are only two lines. Any other sandbox doesn’t cross the bridge, as you’ll see in the next topic.

🎯 Objective: Codex creates a file in the current folder

In the terminal, from inside the kit folder:

runtime/pontes/codex-exec.sh "Crie notas.txt com a palavra OK" "$PWD" workspace-write
cat notas.txt

Result confirmed in CHANGELOG 0.1.0 (the cat notas.txt):

OK
How to verify: o cat notas.txt shows OK. O "$PWD" it’s the folder you’re in: Codex only writes inside it.

⚠️ Recording it is your decision, not the agent’s

The recipe is clear: modify files (N3) only if you ask. Don’t let Claude change the read-only by workspace-write "to speed things up". And point to the right folder: the "$PWD" from the project, never your entire personal folder.

📖
read-only

default, N4

✏️
workspace-write

record, N3

📁
"$PWD"

the current folder

📝
notas.txt

the proof

5

See the policy reject the dangerous action

Codex has a third sandbox, danger-full-access: full access to the machine. The bridge won't allow it. Before calling Codex, it checks the sandbox and stops immediately if it isn't one of the two allowed options.

This is the policy written in code, not in a polite request to the agent. Even if someone asks, the command never reaches Codex.

read-only workspace-write danger-full-access gatekeeper check the sandbox continue to Codex sandbox denied via POLITICA · exit 2

How to read the diagram: the gatekeeper comes before Codex. The blue arrows pass through; the red one returns with the message and exit code 2, without Codex ever being called.

🎯 Objective: see the bridge refuse full access

In the terminal, from inside the kit folder:

runtime/pontes/codex-exec.sh "x" . danger-full-access

Result confirmed in CHANGELOG 0.1.0 (the message, with exit code 2):

sandbox recusado pela POLITICA
How to verify: the message appears immediately, without waiting for Codex, and no files change in the folder.

✓ The bridge accepts

  • ✓ read-only, when you don’t say anything
  • ✓ workspace-write, when you ask
  • ✓ Any folder you specify in the 2nd argument

✗ The bridge refuses

  • ✗ danger-full-access
  • ✗ Any sandbox name outside the list
  • ✗ Call without any request (it shows the “usage”)

💡 Rule that applies to every bridge

Put the limit inside the bridge, not just in the request text. The agent can forget an instruction; a line of code that refuses won’t. The “did it refuse?” test matters just as much as the “did it work?” test.

6

Adjust the model, timing, and common errors

The bridge has two settings, made by environment variable: a named value that you define in the terminal before the command, and that the script reads.

The model’s default is gpt-6-luna, the "lower" level of the ROTEAMENTO.md. Starting with the smallest saves quota. Only move up if the response isn't good enough.

VariableDefaultWhat for
CODEX_MODELOgpt-6-lunaanother level of the ROTEAMENTO.md (in Codex: gpt-6-sol executor, gpt-6-astra top and super)
CODEX_TIMEOUT600seconds before giving up

What to look for in the table: model names change over time. The ROTEAMENTO.md asks you to check with codex --help and update the table.

Common errors ("If you get an error" section of R1)

1

It gets stuck without responding

The request needs to go through stdin with - at the end, otherwise Codex keeps waiting for more text. The bridge already does this; the problem comes up when someone calls codex exec directly, without the bridge.

2

sandbox recusado pela POLITICA

Only read-only e workspace-write are accepted. Check the 3rd argument.

3

The test needs network access

The Codex sandbox blocks the network, including the local network. If the test needs to start a server, add -c sandbox_workspace_write.network_access=true in the bridge and note it in LIMITES.md.

💡 Take notes before you continue

The bridge already has a line in the CAPACIDADES.md: "Codex CLI · CLI · 3 · runtime/pontes/codex-exec.sh · read (N4)". If you changed the network sandbox, the record goes in the LIMITES.md, with a date. That way, no one finds out about the change only when something breaks.

Quick test (optional): Clara wants Codex to only read the calendar and give an opinion. Which bridge call should she use?

🎚️
CODEX_MODELO

start with the smallest

⏱️
CODEX_TIMEOUT

600 seconds

➖
stdin with -

otherwise it freezes

📒
LIMITES.md

adjustment noted

🎓 Module summary

✓
codex exec is the official method — the codex-exec.sh bridge wraps it and applies the policy.
✓
Test it by itself first — "Reply with only PONG" returns PONG.
✓
Second opinion from another model — catches what a single model misses.
✓
Reading is the default; writing requires a request — read-only (N4) and workspace-write (N3).
✓
The dangerous part never reaches Codex — danger-full-access exits with a refusal and exit code 2.

Next module:

2.2 — Your first MCP bridge