OpenAI Codex CLI AGENTS.md Official Docs, Explained

By Rogier Muller05.09.26
OpenAI Codex CLI AGENTS.md Official Docs, Explained

Updating to codex-cli 0.130.0 does not change how Codex CLI should run in a production repo. What carries a team through any release is the workflow contract: the rules in your own repo that say what the agent may touch, which connectors it may call, and what proof a reviewer needs before merge. A workflow contract is that small set of repo rules, written down once and checked into version control. Codex CLI is fast either way. The contract is what keeps that speed from turning into a mess at merge time.

The version number is the part that changes. The receipts your repo keeps are the part that should not. When a build ships and your PR bodies still have no owner, no connector list, and no command a reviewer can replay, the problem was never the CLI.

Write the four rules into AGENTS.md

Four habits hold steady across releases, and each one fixes a specific way reviews slip.

Verification gets skipped first. An exec shortcut runs codegen, tests never run, and a regression slides back in quietly. Require a transcript snippet that shows the tests ran after the change, and a green merge starts meaning something again.

Browser and CLI runs tell reviewers two different stories. A Chrome task and a terminal task drift apart, so write the staging URLs and credential boundaries down next to any browser work. Then the demo stops contradicting your CI.

Model swaps spike during update weeks. A version bump is a tempting moment to change the default model, and a different model means a different risk appetite. Document model-selection policy in AGENTS.md, but select the actual model in the client configuration. A written rule does not change the runtime model or grant tool access.

MCP connectors creep in without a sound. Each server you add widens what the agent can reach, and least privilege erodes one connector at a time. Keep a Markdown roster of connectors checked into the repo root, with the MCP specification as the shared vocabulary.

Paste this into AGENTS.md

Drop this snippet near the top of your AGENTS.md. It encodes the three habits a reviewer cannot guess on their own.

# AGENTS.md verification snippet

- Every Codex CLI run ends with the transcript snippet reviewers can replay.
- Pair browser evidence with the project's normal CLI checks before merge.
- If MCP servers are enabled, list allowed actions beside each connector name.

For the official side, the AGENTS.md guide and Codex CLI docs are the references. The instructions repository that decides your merges, though is your own.

Turn the rules into gates a reviewer can check

Rules only help if a reviewer can apply them without replaying a chat log. Here is the gate set we use, phrased as questions a reviewer asks the PR.

Gate Question
Reviewer path Can someone unfamiliar trace intent without chat replay?
Risk routing Were red folders touched, and who approved?
Replay proof Which commands prove regression guards?
Receipt match Does the PR body list scopes + verification transcript?

The scope receipt is what makes those gates concrete in a PR description:

  • Verification command output is pasted or linked.
  • Forked agent work lists parent + child responsibilities.
  • Red-folder paths received explicit human acknowledgement.
  • Scopes in the PR body match folders in the diff.

The features page, the slash commands reference, and OpenAI Plugins repository will keep moving between releases. None of that replaces your architecture judgement. Agents speed up execution; they do not take over ownership.

Start before the update lands

Record the expected verification evidence in AGENTS.md and check the next PR against its actual command output. A written rule alone does not block an unverified merge; required CI and review controls must enforce that gate. For a place to practice the whole contract, see Codex CLI workflows.

Where does your team stand?

Each team member completes the proficiency matrix individually. You receive a PDF with the team baseline and a recommended next step.

Assess your team