codex

The Codex CLI, installed globally with npm.

Installs the Codex CLI (codex) as a global npm package.

devtools:
  - name: nodejs
  - name: codex

That is the whole install; Codex runs with its own defaults. To set a model or add MCP servers, add a codex toolconfig.

Logging in

Run codex inside the workstation (rl shell <workstation>) and sign in when it asks, or give it an API key from a Secret through the workstation’s environment:

environment:
  OPENAI_API_KEY: "${secret:openai-api-key}"

Version behavior

versionResult
omittedthe latest published release
0.5.0that exact npm version

Node.js

The recipe needs npm. If nodejs is declared first, that Node is used; otherwise the recipe installs the distribution’s Node.js and npm.

Example

Node 24, both CLIs, and Codex told which model to use:

devtools:
  - name: nodejs
    version: "24"
  - name: claude-code
  - name: codex
toolconfigs:
  - id: codex
    name: codex
    config:
      configToml: |
        model = "o4-mini"

The configToml text is written as-is to ~/.codex/config.toml in the login user’s home. Ringleader does not check or change it, so anything Codex accepts in that file works here. The codex toolconfig page covers the alternatives: the same settings as YAML, MCP servers, and trusted folders.

Notes

  • Unlike claude-code, installing codex does not set any permission default, because Codex ships with its own. A toolconfig is created for you only to pre-trust the workstation’s working folders, and only when the workstation declares any.
  • The binary lands on the system PATH.
  • Works on Debian, Ubuntu, and Alpine.