Codex’s hook events, from its hooks documentation. The old snake_case
names Tuff wrote before 0.12.0 (pre_tool_execution, before_finish,
after_save) stay as aliases, so a manifest that names one still
resolves.
Codex reads a project’s hooks from .codex/hooks.json, in the grouped
shape Claude Code uses, and only in a trusted project after the hooks
are approved. Checked in Codex CLI 0.154.0 on 2026-09-16: a
PreToolUse and a SessionStart hook registered here both ran.
Codex reads a project’s MCP servers from .codex/config.toml, under
[mcp_servers.<id>], only in a trusted project. Checked in Codex CLI
0.154.0 on 2026-09-16: a server declared there was listed by
codex mcp list and its tools reached a live session.
How Codex enforces each kind of policy rule, from its rules and MCP
documentation and checked against Codex CLI 0.154.0 on 2026-09-15 and
16. Command rules compile to prefix_rule entries, and MCP tool rules
to settings on the server’s table in .codex/config.toml.
Why Codex cannot enforce a rule its matrix covers: an MCP rule with a
*, since disabled_tools and a tool’s approval_mode take exact
names (ToolFilter in codex-rs 0.154.0 compares names as a set).