Codex
Codex CLI: approval and sandbox modes (and what --yolo does)
How do I make Codex run commands without asking?
Codex combines an approval policy (--ask-for-approval: on-request or never) with a sandbox (--sandbox: read-only, workspace-write or danger-full-access). --dangerously-bypass-approvals-and-sandbox, alias --yolo, removes both. Use /permissions in a session to change them.
Sandbox modes
- workspace-write (default): read files, edit the workspace and run commands; edits outside it and network access need approval.
- read-only: read files and run commands within sandbox limits.
- danger-full-access: no sandbox. Not recommended.
Approval policy
- on-request: you approve actions that go outside the sandbox.
- never: no approval prompts.
~/.codex/config.toml
approval_policy = "on-request" sandbox_mode = "workspace-write"
Hands-off without --yolo
--full-auto is deprecated. For unattended runs, Codex recommends codex exec with --sandbox workspace-write, which keeps the sandbox while skipping prompts for work inside the workspace.
Sources
More on Codex
Other guides
Get the weekly agent stack update
New official MCP servers, spec changes and harness releases, checked against the source. One email a week, no fluff.
Reviewed Oct 6, 2026. Settings change often; the linked vendor docs are the source of truth.