# Codex Features and Practical Usage
๐ค Stop babysitting the terminal โ non-interactive mode lets you treat Codex as just another stage in your pipe, ready to drop into CI and scripts.
๐ท๏ธ Title: `codex exec`
๐ URL:
๐ Overview
`codex exec` runs Codex once, without launching the interactive UI. You pass the prompt as a single argument, the agent does the work, and only the final message is written to stdout. It is built for CI pipelines, pre-commit hooks, and ordinary shell pipelines.
โ๏ธ How It Works
Progress logs stream to stderr while only the final agent answer goes to stdout, so it composes cleanly with pipes and redirects. Key flags:
ใป`--sandbox`: `read-only` (default) / `workspace-write` (allow edits) / `danger-full-access` (full access).
ใป`--ask-for-approval never`: suppresses approval prompts for fully unattended runs.
ใป`--json`: streams every event as JSON Lines (`thread.started`, `turn.started`, `item.completed`, `turn.completed`, etc.).
ใป`-o/--output-last-message
`: writes the final message to a file.
ใป`--output-schema `: enforces structured output matching a JSON Schema.
ใป`-C/--cd `: changes the working directory before running.
ใป`--skip-git-repo-check`: bypasses the Git-repo requirement (normally required to prevent destructive changes).
ใป`--ephemeral`: keeps session files off disk.
๐ ๏ธ Practical Usage
It pairs well with stdin. For example, pipe `npm test 2>&1` into `codex exec "summarize failing tests and propose minimal fix"` and tee the result to a summary file.
Structured output gives you stable, machine-readable fields: pass `--output-schema ./schema.json` with `-o ./project-metadata.json`.
You can chain sessions into multi-stage pipelines: run an initial `codex exec`, then continue with `codex exec resume --last` to fix what it found.
๐ก Use Cases
A common split is to trigger on CI failure, generate a patch read-only, then apply it and open a PR in a separate job that holds write permissions. It also works well for log triage โ pipe the tail of a log and save root-cause analysis to `analysis.md`.
โ ๏ธ Caveats
Never expose API keys as job-level env vars in workflows that check out untrusted code; on GitHub, prefer the official Codex GitHub Action. The `--full-auto` flag is deprecated โ use `--sandbox workspace-write` instead. If an MCP server marked `required = true` fails to start, `codex exec` exits with an error. Always pick the least-privilege sandbox for automation.
#Codex# #CI#