Codex

Codex CLI: approval and sandbox modes (and what --yolo does)

How do I make Codex run commands without asking?

Codex combines an approval policy (--ask-for-approval: on-request or never) with a sandbox (--sandbox: read-only, workspace-write or danger-full-access). --dangerously-bypass-approvals-and-sandbox, alias --yolo, removes both. Use /permissions in a session to change them.

Sandbox modes

  • workspace-write (default): read files, edit the workspace and run commands; edits outside it and network access need approval.
  • read-only: read files and run commands within sandbox limits.
  • danger-full-access: no sandbox. Not recommended.

Approval policy

  • on-request: you approve actions that go outside the sandbox.
  • never: no approval prompts.

~/.codex/config.toml

approval_policy = "on-request"
sandbox_mode = "workspace-write"

Hands-off without --yolo

--full-auto is deprecated. For unattended runs, Codex recommends codex exec with --sandbox workspace-write, which keeps the sandbox while skipping prompts for work inside the workspace.

Sources

More on Codex

Other guides

Get the weekly agent stack update

New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.

Reviewed Oct 6, 2026. Settings change often; the linked vendor docs are the source of truth.