Skip to content
handup
  • How it works
  • Pricing
  • Blog
  • Docs
  • GitHub
Download
handup · betaDownloads · Agents · Compare · Blog · Changelog · llms.txt · API · Docs · GitHub · Support · Terms · Privacy

handup for agents · Codex

Approve Codex CLI permission requests remotely

Send OpenAI Codex CLI permission requests to handup and approve or deny them from your desktop or phone, with deny feedback that Codex reads.

DownloadBuy · $30Codex guide

Free for 14 days, no signup. Linux, macOS and Windows, with an Android app for your phone.

What handup does for Codex

  • A PermissionRequest hook sends Codex's permission requests to handup when Codex asks for escalation.
  • The handup MCP server lets Codex ask on its own before risky steps.
  • A denial with a note reaches Codex as the decision message, for example "Use staging instead".

Set it up

  1. Install handup

    On glibc Linux or macOS, use the install script below. On Alpine, use the musl APK package from the downloads page instead. On Windows, download the desktop EXE or CLI ZIP instead of running the install script: the desktop app starts the daemon, or run handup serve in its own terminal for the CLI ZIP. The service command below is Linux/macOS only. (handup setup starts handup and connects every agent it finds in one go; Windows has no background service.)

    curl -fsSL https://github.com/gethandup/handup/releases/latest/download/install.sh | sh
    handup service install # Linux/macOS only; on Windows run handup serve
  2. Connect Codex

    Preview, then install the hook and the MCP server into $CODEX_HOME (default ~/.codex). Other handlers are kept and changed files are backed up.

    handup integrate codex --dry-run
    handup integrate codex
  3. Trust the hook and run Codex

    Codex asks you to review the new hook; approve it. Then run Codex with an approval policy that asks.

    codex --sandbox workspace-write --ask-for-approval on-request

What the approval looks like

  • Bash requests show the command; other tools show their input as JSON.
  • Requests carry the Codex session ID and working directory.
  • Approve, or deny with feedback. Codex gets allow or deny; this hook cannot rewrite the tool call.
  • If the daemon is unreachable, Codex keeps its own permission prompt. handup never approves as a fallback.

Limits

  • The hook only runs when a command needs escalation, not for commands Codex's sandbox already allows.
  • codex exec forces the approval policy to never, so use the interactive CLI for approval round-trips.
  • Codex defaults to a 60-second MCP tool timeout; handup's wait_requests returns well inside it.

Full details: the Codex guide in the handup docs.

Try it, then pay once

Every feature works free for 14 days. A personal license is $30 USD one-time plus tax where applicable, with all future released updates.

Download handupPricingOther agents