Files
Drew Newberry 1905069948 feat(sandbox): expose services during creation (#3439)
* feat(sandbox): expose services during creation

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* feat(providers): refresh Codex credentials in gateway

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(cli): normalize create-time service URLs

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(server): roll back failed service exposure

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* docs(example): simplify Codex provider setup

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* docs(example): separate provider setup commands

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(sandbox): harden create-time service exposure

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* docs(example): bundle Codex provider profile

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

* fix(example): allow npm-installed Codex binary

Signed-off-by: Drew Newberry <anewberry@nvidia.com>

---------

Signed-off-by: Drew Newberry <anewberry@nvidia.com>
2026-09-20 23:19:25 -07:00

70 lines
2.0 KiB
YAML

# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
# SPDX-License-Identifier: Apache-2.0
# Provider profile for the Codex app-server example. The gateway owns refresh
# material and injects opaque handles for the access token and account ID.
id: codex
display_name: Codex
description: OpenAI Codex CLI with gateway-managed token refresh
category: agent
inference_capable: true
credentials:
- name: access_token
description: Codex OAuth access token refreshed by the gateway
env_vars: [CODEX_AUTH_ACCESS_TOKEN]
required: true
auth_style: bearer
header_name: authorization
refresh:
strategy: oauth2_refresh_token
token_url: https://auth.openai.com/oauth/token
refresh_before_seconds: 300
max_lifetime_seconds: 3600
material:
- name: client_id
description: Codex OAuth client ID
required: true
- name: refresh_token
description: Codex OAuth refresh token
required: true
secret: true
- name: refresh_token
description: Codex OAuth refresh token for clients that manage their own refresh
env_vars: [CODEX_AUTH_REFRESH_TOKEN]
- name: account_id
description: Codex account identifier
env_vars: [CODEX_AUTH_ACCOUNT_ID]
required: true
- name: id_token
description: Codex OAuth ID token
env_vars: [CODEX_AUTH_ID_TOKEN]
discovery:
credentials: [access_token, refresh_token, account_id, id_token]
endpoints:
- host: api.openai.com
port: 443
protocol: rest
access: read-write
enforcement: enforce
- host: auth.openai.com
port: 443
protocol: rest
access: read-write
enforcement: enforce
- host: chatgpt.com
port: 443
protocol: rest
access: read-write
enforcement: enforce
- host: ab.chatgpt.com
port: 443
protocol: rest
access: read-write
enforcement: enforce
binaries:
- /usr/bin/codex
- /usr/local/bin/codex
- /usr/lib/node_modules/@openai/**
- /usr/local/lib/node_modules/@openai/**