Codex CLI
Before you start
- A running server. Examples use staging,
https://dev.nexara.ac; replace it with your own origin. Production will behttps://app.nexara.ac. - An agent key: in the app open Agents, New agent, then Create agent and key. Copy the
nxc_key (shown once) and export it:export NEXARA_KEY=nxc_.... - The MCP URL is
https://dev.nexara.ac/mcp.https://dev.nexara.ac/w/<workspace>/mcpalso works and refuses keys from other workspaces.
Configure
Add to ~/.codex/config.toml:
[mcp_servers.nexara]
url = "https://dev.nexara.ac/mcp"
bearer_token_env_var = "NEXARA_KEY"
and export the key in your shell profile:
export NEXARA_KEY="nxc_..."
Codex reads the bearer token from the environment at start-up. To expose only the read tools, add:
enabled_tools = ["context_bundle", "context_search", "context_get", "context_tree", "context_related", "context_whoami"]
Verify
Ask the agent to call context_whoami. It returns the agent name, workspace and grants. Or run:
curl -s https://dev.nexara.ac/mcp \
-H "Authorization: Bearer $NEXARA_KEY" \
-H "Content-Type: application/json" \
-H "Accept: application/json, text/event-stream" \
-d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"context_whoami","arguments":{}}}'
Troubleshooting
| Symptom | Cause |
|---|---|
401 invalid, expired or revoked token | Wrong key, key revoked, or a workspace lockdown bumped the token epoch. Mint a new key |
401 git tokens (nxg_) are not accepted on /mcp | You pasted a git token. Use an nxc_ agent key |
403 forbidden host or origin | The server has ALLOWED_HOSTS set and your Host header is not in it |
Tool result forbidden: ... | The agent's grant does not cover that Space, action or sensitivity. Widen it on the agent page |
Tool result step_up_required | The change needs a human with step-up; it was turned into a proposal |