zephex
CLIGet StartedPricingMCP ToolsCommunityGuidesDocs
←BackSign in
CLIGet StartedPricingMCP ToolsCommunityGuidesDocs
Get started freeSign in
DocsAPIToolsEditorsChangelogHelp

GET STARTED

WelcomeQuickstartSetup videoMCP Q&A (learn)BlogWhat is MCP?Who is Zephex for?Plans & PricingZ-GASAB benchmarkBenchmark chart (live)Changelog

INSTALLATION

Web Terminal tools (plain English)Terminal tools (complete)Connect MCPVS Code Marketplace extensionCLI (no AI agent)CLI init (first run)CLI account & logoutNPX (Recommended)Test Pulse (check test)Test Pulse commandsProject MemorySupply Pulse (supply)Supply Pulse commandsTerminal CLI referenceSlash commands (37 palette)Web Terminal (dashboard)Command CompassCLI commandsCLI in DockerCLI: All editors (one command)CLI: Crush, Hermes, ChatGPT, KiloOAuth & HTTP setupInstall overviewHTTP APISetup WalkthroughHTTP vs stdio

API & KEYS

API Key ManagementKey Naming & FormatAuthenticationKey Dashboard

CONFIGURATION

Universal RequirementsSupported EditorsHow It WorksArchitectureCLAUDE.md TemplateAGENTS.md Template

EDITORS28 guides

Supported EditorsVS CodeVS Code extension (Marketplace)Claude CodeCursorWindsurfJetBrains

PLATFORM

macOSWindowsLinux

TOOLS10 tools

Capabilities OverviewTools OverviewTool FilteringTool Workflowsget_project_contextread_codefind_codecheck_packageexplain_architectureZephex_dev_infocheck_testaudit_headerskeep_thinkingproject_memory

GUIDES

Best PracticesToken EfficiencyUse CasesZephex vs Local MCPZephex vs Context7Zephex vs GitHub MCPZephex vs SmitheryMCP EcosystemMarkdown Access

SUPPORT

Help CenterMCP troubleshootingTeam rolloutFAQConnection IssuesRate LimitsDowntime & ErrorsBillingTier GuidePro & Max guideUsage LimitsUsage Analytics

LEGAL

System StatusTerms (summary)Privacy (summary)Data UseSecurityAuthenticationSecurityData HandlingPrivacy PolicyTerms of Service

Quick Links

API Reference

Complete API documentation

Troubleshooting

Common issues and solutions

Community

Join our Discord community

Plugins

Editor and CLI integrations

Pricing

Free, Pro, and Max plans

Enter
Zephex_devzephex-devzephexzephexhello@zephex.dev
© 2026 Zephex. All systems operational.

Editor setup

OpenAI Codex CLI MCP Server

Codex now speaks remote Streamable HTTP natively (CLI and the Codex IDE extension share one config.toml). Connect straight to https://zephex.dev/mcp with a bearer token, or run codex mcp login zephex for OAuth — no local process. npx -y zephex setup --codex still writes the stdio block when you want the local zephex process to read your project files.

Official OpenAI Codex CLI MCP documentation: OpenAI Codex MCP docs

MCP endpointhttps://zephex.dev/mcp
AuthenticationRemote HTTP: bearer_token_env_var = ZEPHEX_API_KEY, or OAuth via codex mcp login. stdio: ZEPHEX_API_KEY in [mcp_servers.zephex.env].
Config file~/.codex/config.toml or .codex/config.toml (trusted projects only)

Why Zephex

Without MCP, your agent guesses project layout and misses supply-chain risk. Zephex connects one hosted endpoint so every session gets the same ten tools — no per-machine npm installs, no version drift across the team.

Before you start

  • Codex CLI or the Codex IDE extension installed (config.toml is shared between them).
  • Node.js 18+ if you use the npx stdio option.
  • Network access to https://zephex.dev/mcp.
  • An API key from Dashboard → API Keys for the bearer-token paths.

Get and paste your API key

HTTP and stdio setups both need a key from your Zephex dashboard. OAuth-only flows (ChatGPT, Claude.ai web) sign you in in the browser instead — skip this section for those.

  1. Sign in at zephex.dev → Dashboard → API Keys (or /dashboard/api-keys).
  2. Click Create API key, give it a name you will recognize (e.g. "Kilo — work laptop"), then create.
  3. Copy the key as soon as it appears — Zephex only shows the full secret once. It starts with mcp_sk_ or a newer mcp_prod_… format.
  4. Paste into your config: either only the key in an env field (ZEPHEX_API_KEY), or the full HTTP header value Authorization: Bearer YOUR_KEY — match what your editor’s form asks for.
  5. Do not wrap the key in extra quotes inside JSON unless the file already quotes other string values.
  6. Never commit API keys to git. Revoke and create a new key in the dashboard if one leaks.

Setup policy for OpenAI Codex CLI

Matches the published CLI (mcp-proxy/src/commands/setup.ts). One command signs you in, writes the correct transport, and verifies 10 tools.

Recommended commandnpx -y zephex setup --codex
Project-scopednpx -y zephex setup --codex --project
Transportstdio (npx -y zephex + ZEPHEX_API_KEY)
Config parent keymcp_servers.zephex

Global vs project config

  • Global setup is the default — run setup without --project so Zephex works in every folder you open.
  • Global setup also removes stale project-level Zephex entries that shadow your user config.
  • Add --project only when you intentionally want workspace-scoped config (e.g. .cursor/mcp.json in one repo).

After setup

  • Codex TOML uses command/args/env — the wizard writes stdio, not url/http_headers.
  • Fully quit the editor after setup — reload window alone is often not enough.
  • Start a new agent/chat session so MCP tools register.

Account teardown: logout vs disconnect · Connect MCP walkthrough

Find where setup wrote your config

Search docs for “where is my MCP file” — the answer is always: run list first, then open the path it prints.

  1. Run npx -y zephex@latest list — canonical path list for codex-cli.
  2. Wizard writes to: ~/.codex/config.toml or <project>/.codex/config.toml
  3. macOS uses ~/ and ~/.config; Windows uses %USERPROFILE% and %APPDATA%; Linux uses ~/.config.

Documented paths: ~/.codex/config.toml or <project>/.codex/config.toml

Fastest install

Codex TOML uses command/args/env — the wizard writes stdio, not url/http_headers.

Guided install (matches published CLI)

Runs the same code as mcp-proxy/src/commands/setup.ts — OAuth in browser, creates a CLI key, writes your editor config, verifies tools.

shell
npx -y zephex setup --codex

Already have a key?

Skip browser OAuth — paste a key from zephex.dev/dashboard/keys. Must start with mcp_prod_, mcp_dev_, or mcp_sk_.

shell
npx -y zephex setup --codex --api-key mcp_prod_your-key-here

What setup writes (stdio TOML)

command/args/env — not url: Transport: stdio (see ~/.codex/config.toml or <project>/.codex/config.toml).

toml
[mcp_servers.zephex]command = "npx"args = ["-y", "zephex"]env = { "ZEPHEX_API_KEY" = "mcp_sk_your_key_here" }startup_timeout_sec = 40

After CLI install, fully restart the app if tools do not appear. Manual JSON/TOML blocks below are equivalent — use them when CLI commands are unavailable.

Hosted HTTP vs npx stdio

  • Recommended: npx -y zephex setup --codex — Codex TOML uses command/args/env — the wizard writes stdio, not url/http_headers.
  • Config path: ~/.codex/config.toml or <project>/.codex/config.toml
  • Manual stdio shape: command "npx", args ["-y","zephex"], env ZEPHEX_API_KEY (parent key: mcp_servers.zephex).
  • Optional hosted HTTP (https://zephex.dev/mcp + Bearer) only if you do not need automatic workspace file access — pass github: URLs in prompts.
  • Never keep two zephex entries (stdio + HTTP) in the same config — pick one transport.
  • Cloud-only tools (check_package, project_memory, audit_headers, keep_thinking, Zephex_dev_info) work on both transports.
  • Repo tools (get_project_context, read_code, find_code, explain_architecture, check_test) need either stdio/npx setup or an explicit github:owner/repo or absolute path on HTTP.

Full comparison: HTTP vs stdio · npx zephex reference

How to connect Zephex

  1. Pick ONE transport — never keep two [mcp_servers.zephex] blocks.
  2. Remote HTTP + API key (recommended): export ZEPHEX_API_KEY=… then add the url + bearer_token_env_var block below.
  3. Remote HTTP + OAuth: add the url-only block, then run codex mcp login zephex and approve in the browser.
  4. stdio (local files): run npx -y zephex setup --codex, or codex mcp add zephex --env ZEPHEX_API_KEY=… -- npx -y zephex.
  5. Run codex mcp list (or /mcp in the TUI) — zephex should show as connected.
  6. Test get_project_context from a project directory.

Configuration

Replace mcp_sk_your_key_here with your key from Dashboard → API Keys. Copy the full key once at creation — paste into Authorization: Bearer … for HTTP configs, or into ZEPHEX_API_KEY for stdio/npx configs.

Remote HTTP + bearer token (recommended)

Codex reads the token from the ZEPHEX_API_KEY env var — no key written to config.toml. export ZEPHEX_API_KEY before launching Codex.

toml
[mcp_servers.zephex]url = "https://zephex.dev/mcp"bearer_token_env_var = "ZEPHEX_API_KEY"startup_timeout_sec = 40

Remote HTTP + OAuth (codex mcp login zephex)

Add this url-only block, then run codex mcp login zephex. Codex uses Zephex's advertised scopes (including offline_access) so refresh tokens keep working.

toml
# Pin the OAuth callback port only if your provider requires a fixed# redirect URI. Omit it and Codex binds an ephemeral port automatically.# mcp_oauth_callback_port = 1455 [mcp_servers.zephex]url = "https://zephex.dev/mcp"startup_timeout_sec = 40

stdio via npx (local file access)

What npx -y zephex setup --codex writes. Use this when repo tools should read your local project tree without passing github: URLs.

toml
[mcp_servers.zephex]command = "npx"args = ["-y", "zephex"]env = { "ZEPHEX_API_KEY" = "mcp_sk_your_key_here" }startup_timeout_sec = 40

Note

CLI shortcuts: `codex mcp add zephex --env ZEPHEX_API_KEY=mcp_sk_your_key_here -- npx -y zephex` adds the stdio server; `codex mcp login zephex` authenticates the remote HTTP server; `codex mcp list` shows status. npx setup --codex always rewrites the [mcp_servers.zephex] block to stdio.

Verify, repair, disconnect (CLI)

Run these in a terminal when the editor UI is unclear — catches stale npm, wrong transport, and project shadows.

shell
npx -y zephex@latest listnpx -y zephex@latest doctornpx -y zephex@latest repair# Fully quit the editor (Cmd+Q / Alt+F4), reopen, start a new agent session

Repair policy

  • npx -y zephex@latest repair pins stdio to zephex@latest, fixes OpenCode command-array shape, and adds PATH hints for GUI-launched apps.
  • repair migrates legacy HTTP → stdio for filesystem editors — not for Cursor, Claude Code global HTTP, or Crush.

Disconnect & skills

  • disconnect --<editor> removes Zephex from config files the CLI knows about and revokes the API key found in those files.
  • There is no disconnect --project flag — disconnect checks both global and project paths (project paths use your current terminal cwd).
  • Terminal-only sign-out: mcpcli logout (editors unchanged). Full teardown: mcpcli logout --all.
  • This editor: mcpcli disconnect --codex
  • Fresh OAuth: mcpcli reconnect --codex
  • Add agent guidance: mcpcli setup --codex --with-skill or mcpcli skills --<editor>.
  • Remove skills from one editor: mcpcli reset --codex (disconnect + skill files).
  • Remove all skill copies: mcpcli skills --remove.

Check that it works

After saving your config, confirm Zephex is connected before you rely on it in real work.

    Common searches

    Questions people ask when OpenAI Codex CLI does not show Zephex tools — indexed for docs search.

    How do I connect Zephex to codex-cli?

    Fastest: npx -y zephex setup --codex (browser sign-in, writes config, verifies 10 tools). Or paste manual config on this page, save, fully quit the app, reopen.

    Where did setup save my codex-cli MCP config?

    Run npx -y zephex@latest list — it prints every config path on this machine that references Zephex.

    codex-cli works in terminal but not in the editor

    GUI apps often lack nvm/fnm PATH. Run npx -y zephex@latest repair, ensure Node is on system PATH, fully quit the editor.

    How do I disconnect Zephex from codex-cli?

    mcpcli disconnect --codex — revokes key and strips config.

    Example ways to use the tools

    You do not call tools yourself — ask your agent in plain language. Try these once Zephex is connected:

    “In Codex, run check_test: implement refresh-token rotation in our OAuth service.”

    File-level plan before Codex edits Rust or Go handlers.

    “get_project_context on . — we're in a trusted .codex/config.toml project.”

    Confirms stack markers from the repo Codex already trusts.

    “check_package on a Go module path a coworker suggested in code review.”

    Registry intelligence from the same TOML-backed MCP session.

    “explain_architecture for our microservices in services/* — auth between them.”

    Cross-service diagram for reasoning in long Codex runs.

    “read_code the main() entry in cmd/worker — outline first if the file is huge.”

    Outline mode then symbol drill-down saves tokens in big files.

    “keep_thinking on a race condition; then audit_headers on our public docs site.”

    Debug structure plus optional URL audit in one workflow.

    Which tools need your project path?

    You do not pick tools from a menu — ask your agent in normal sentences. Half of the tools only need a package name or URL; the other half need to know which codebase you mean (your Mac/Windows project folder or a GitHub repo).

    Need a repo or folder path

    • get_project_context — full stack snapshot for one repo
    • read_code — read functions/classes by symbol name
    • find_code — search definitions and usages
    • explain_architecture — Mermaid diagrams for the repo
    • check_test — minimal file list for a task you describe

    Work without a local project

    • check_package — npm/PyPI/Cargo/Go registry safety (no repo path)
    • project_memory — Cross-session project memory: remember decisions, gotchas, goals, conventions across sessions via local SQLite (stdio only).
    • audit_headers — security grade for any HTTPS URL you own or may test
    • keep_thinking — structured debugging notes across steps
    • Zephex_dev_info — vetted patterns (auth, DB, deploy, etc.)

    How to tell the agent where the code lives

    • GitHub (no clone required): say github:owner/repo — example: github:vercel/next.js
    • Local folder: give the absolute path to the project root (the folder that contains package.json, pyproject.toml, or go.mod).
    • If your editor already has the repo open, try “use get_project_context on this workspace” first; if the tool returns empty, repeat with the full path or github: URL in the same chat.
    • For read_code / find_code, name the symbol or search term in the same message as the path (e.g. “find_code AuthService in github:myorg/api”).

    macOS and Windows paths

    • macOS example path: /Users/yourname/Developer/my-app
    • Windows example path: C:\Users\yourname\projects\my-app
    • Replace yourname with your Mac or Windows login — the agent cannot guess your home directory.
    • Cloud-only tools (check_package, audit_headers) never need your username or project folder.

    When Zephex will not connect

    These situations usually mean the setup cannot work until you fix the underlying issue:

    • No internet or a firewall blocks outbound HTTPS to zephex.dev (port 443).
    • API key never created, revoked, or pasted incorrectly (missing Bearer , extra quotes, or truncated copy).
    • Wrong MCP URL — must be exactly https://zephex.dev/mcp (not /docs, not /api, no wrong host).
    • Mixed stdio + HTTP — two zephex entries (npx and url) confuse many clients; keep one transport.
    • Corporate proxy strips Authorization headers or chunked transfer encoding.
    • Monthly request limit reached on the Free plan (555 requests/month) — tools stop until next cycle, share for bonus requests, or upgrade.
    • Editing the wrong config file — global vs project-level paths differ by editor and OS.
    • App not fully quit after save — MCP often loads only on a cold start (especially IDEs).
    • Tools connect but return “no project” — not a connection failure; add github:owner/repo or an absolute path (see tool usage section).
    • Node.js or npx not on PATH when the desktop app launches (common on macOS Dock launches).
    • Invalid JSON in the config file (comments, trailing commas, or wrong wrapper key).
    • ZEPHEX_API_KEY missing, still set to the placeholder, or pasted in the wrong field (stdio uses env, not Bearer headers).
    • You edited Claude Code’s config but opened Claude Desktop (different files).
    • App was not fully quit after saving the config — MCP only reloads on a cold start.
    • npx works in Terminal but not inside the app — use absolute paths to node/npx in the command block if needed.
    • First npx -y zephex run can take 30–60s — increase startup_timeout_sec where the editor supports it.
    • Still have an HTTP url block while testing stdio — remove the duplicate zephex server.
    • Both url and command blocks present for zephex after a partial edit.
    • OAuth login skipped on the url-only block (run codex mcp login zephex).
    • ZEPHEX_API_KEY not exported in the shell that launches Codex (bearer path).
    • Invalid TOML section headers.

    If something goes wrong

    Still stuck? Quickstart · MCP troubleshooting

    Tools included with Zephex

    Codex TOML MCP registers zephex over Streamable HTTP — tools surface in codex sessions:

    • get_project_context

      Reads your project structure, dependencies, scripts, env vars, and framework markers in one call. Replaces manually opening package.json, tsconfig, and multiple config files at the start of every session.

    • read_code

      AST-based code extraction: pass a symbol name and get the implementation without reading entire files. Supports symbol lookup, batched file reads, and structural outlines for large files.

    • find_code

      Ranked search across the repo for definitions, usages, and patterns. Faster than blind grep when the agent does not know where a symbol lives.

    • check_package

      Live registry lookup for npm, PyPI, Cargo, and Go modules. Surfaces typosquat risk, maintainer changes, and suspicious version jumps before you run install.

    • explain_architecture

      Generates Mermaid diagrams for auth flows, service boundaries, and module dependencies so the agent reasons about structure instead of guessing.

    • check_test

      Turns a task description into the smallest file set to read or edit, with risk ratings and caller impact notes.

    • audit_headers

      Grades a deployed URL for CSP, HSTS, TLS, cookies, and redirects. Returns fix snippets for common hosts (Vercel, Cloudflare, Nginx).

    • keep_thinking

      Structured multi-step debugging: tracks hypotheses and conclusions so long investigations do not loop.

    • Zephex_dev_info

      Expert patterns for authentication, databases, frontend frameworks, deployment, and mobile stacks when the agent needs vetted guidance.

    • project_memory

      Persists decisions, gotchas, and conventions per project in ~/.zephex/memory (SQLite FTS5). recall before unfamiliar areas; remember after discoveries. Local stdio only on npx zephex.

    Related

    • npx zephex reference
    • Quickstart — create your first API key
    • HTTP vs stdio — which to use
    • MCP troubleshooting
    • All supported editors
    • All 10 MCP tools
    • Install wizard
    • Pricing and limits