termal.in

← Blog

Connect OpenAI Codex to your servers over SSH — safely

· Termalin team codexmcpai-agentssshtutorial

Codex is happy inside a repo. The task that sends you looking for server access is the one that leaves it — the deploy failed, the migration hung, the service won’t come back up on the actual box. The tempting fix is to let Codex run ssh itself: it already executes shell commands on your machine, so if a key sits unlocked in ~/.ssh or a running ssh-agent, ssh prod works for it without you deciding anything. That’s not “giving Codex access” — that’s discovering you gave it away by default.

There’s a cleaner arrangement, and Codex is built for it. OpenAI’s Codex CLI speaks MCP, and Termalin is an SSH client with a built-in MCP server. Point Codex at that server and it works your hosts for real — runs commands, reads and writes files — while the agent never holds a key. This is the same shape as the Claude Code and Cursor setups; here’s the Codex-specific version, in about twenty minutes.

What you need

  • Termalin — the desktop app; the Free tier is fine. Its built-in MCP server is what Codex will talk to.
  • The Codex CLI, on the same machine.
  • One host saved in Termalin. Pick something you don’t mind an agent poking at for the first run — staging, a throwaway VPS.

Step 1 — turn agent access on and set a policy

Agent access is off by default. In Termalin, open Settings → MCP, enable it, and tick the hosts Codex may reach. Nothing outside that list exists as far as the agent is concerned; adding a host is a decision you make in the app, not something Codex can talk its way into.

Two things happen underneath. Termalin writes a host inventory for the MCP server with agent-only auth entries — no passwords or keys land in that file. And authentication stays with the app’s key custodian: you unlock once, and Termalin signs on the agent’s behalf. There’s no key file for Codex to read, so there’s nothing to leak — which also closes the ~/.ssh back door above.

While you’re there, set each host’s agent policy: full access, an allowlist of commands, or blocked. For anything you care about, start with an allowlist — the shortest list that lets Codex do the job you have in mind.

Step 2 — register the server in config.toml

Codex reads MCP servers from the mcp_servers section of ~/.codex/config.toml. Add one entry pointing at the bundled termalin-mcp binary:

[mcp_servers.termalin]
command = "<path>/termalin-mcp"

Recent Codex builds can add it from the command line instead — the same result:

codex mcp add termalin -- <path>/termalin-mcp

That’s the whole integration, and the same config drives Codex in the IDE. Restart Codex, confirm the server shows as connected, and the tools appear to the agent: hosts_list, ssh_exec, persistent sessions (session_open / session_exec), SFTP reads and writes, and port forwards.

One Codex habit worth keeping for the first sessions: leave its command approvals on. Codex asks before it acts unless you tell it not to — don’t tell it not to yet. Widen that the same way you widen the host list: one boring thing at a time, after you’ve watched how it behaves.

Step 3 — give it a real chore

Skip the demo command. Hand it something you’d actually do:

The deploy to staging-1 finished but the health check is flapping. Find out why and fix it.

Codex calls hosts_list, sees staging-1, opens a session, and starts pulling threads — service status, the last hundred log lines, the config diff against what’s running. It proposes a fix, applies it within the policy you set, and confirms the check goes green.

The reason this is comfortable rather than nerve-wracking is that none of it is invisible. Every session Codex opens shows up in Termalin as a live terminal tab, and the watch grid puts all open sessions side by side with the agent-driven tiles glowing. You’re watching commands land as they run, not reading a summary afterward — and you can step in mid-session at any point.

Where the boundaries are

The defaults worth knowing before you point Codex at anything that matters:

  • Your keys never enter Codex’s environment. The custodian signs; the agent requests. Revoking access is a toggle in Settings, not a key rotation across your fleet.
  • Its reach is the host list you ticked in Step 1, and each host’s command policy bounds what it can run there. “Full” on production is still a full shell — set it deliberately.
  • Typing into your session is separate. By default Codex opens its own sessions; joining one you already have open is its own consent toggle, and on Pro. It never rides along silently.
  • Every command is on the record. Session recordings capture output only — never keystrokes — and each agent command is tagged as the agent’s in the audit log, with the device and IP it came from. “The agent did this” is a filter you apply, not a story you reconstruct.

When Codex runs where your desktop isn’t

If Codex is running in CI or a cloud sandbox rather than on your laptop, the local stdio binary isn’t reachable — but Termalin’s hosted MCP endpoint is. Create an API key in the web cabinet, scope it to the servers that job should touch, set it to read-only or an allowlist, and give it an expiry. The endpoint reaches your Connector-enrolled servers keyless, authenticating each run with a short-lived certificate — no key handed out, nothing standing. The full pattern, with a copy-paste pipeline example, is in giving an agent SSH access in CI/CD.

The habit that makes it stick

Treat the first week like onboarding a fast-typing teammate. Keep the watch grid open. Give Codex chores with a clear done-state — “make the health check pass”, “renew the cert” — and read how it gets there. Keep approvals on until it’s earned auto-approve for the dull tools, and widen the host list one unexciting box at a time.

The asymmetry is the whole point: Codex gets real reach, and you keep the one thing that can’t be handed back once it’s out.


Termalin is a cross-platform SSH client with a built-in MCP server, a key custodian and per-host agent policy. Start from the Codex SSH page, read the MCP reference, or download the app — the Free tier has no host limits.

Try it on one host.

Termalin is a fast SSH client for you — and your agents.

Free tier · 14-day Pro trial · pricing