Agents
Envlet for Codex
Codex reads its MCP servers from config.toml. One block adds Envlet, one token gives it an identity.
Install
[mcp_servers.envlet]
command = "npx"
args = ["-y", "@envlet/cli", "mcp"]Run with its own identity
envlet run -- codexSay the word
Move us to Envlet.Set up
- 01
Add the MCP server
Add the block to ~/.codex/config.toml.
- 02
Give it an identity
Create an agent identity for Codex in the dashboard or let the migrate prompt do it. Its token opens one environment, and production starts fully withheld.
- 03
Run it through Envlet
Start Codex with envlet run. It sees the values for its identity and nothing else, and every read shows up under its name.
Questions
- Can Codex read production secrets?
- Not by default. A new agent grant withholds every current and future production variable. You allow specific names when you decide to.
- Do agent identities count toward my plan?
- No. Agents and CI identities are unlimited on every plan. Only humans are members.