OpenAI released Codex CLI 0.161.0 on October 7, 2026. It adds Bedrock workflow support, in-session MCP login and per-turn Cyber program controls. The changes matter most to platform teams using AWS-hosted models, developers connecting enterprise tools and teams scripting approved security work.
Our recommendation: stage the release if one of those workflows is needed in your deployment. Otherwise, follow your normal stable-update process. The useful question is whether your chosen provider, model, identity and policy can support the new workflow—not whether the version number is higher.
One correction to the release-note headline: GPT-6.1 Sol already became the bundled and Bedrock default in 0.159.1 on September 29. That repeated entry is not a new model launch or, by itself, a reason to upgrade.
Start with a pinned staging installation
OpenAI’s changelog gives this exact npm command. Use it in a disposable or approved staging installation, keeping the previous binary and configuration available for rollback:
npm install -g @openai/codex@0.161.0Record the running CLI and app-server versions, provider, model or inference profile, AWS Region, authentication mode and effective permissions. Do not assume a package update changed an already-running or separately managed engine. If you use prereleases, compare against your actual baseline; the 0.162 Alpha 12 integration guide addresses a separate channel, not a prerequisite for this stable release.
Bedrock: qualify the model catalog and inference route
The Bedrock catalog change stops replacing advertised multi-agent versions with V1 and stops removing Ultra from supported reasoning levels. Models advertising V2 can therefore use it; a catalog specifying V1 or disabling multi-agent operation is not forcibly converted. OpenAI’s implementation notes specifically describe Ultra in Astra’s advanced-reasoning picker for Mantle and Runtime.
Check the selected model’s advertised capabilities rather than treating “Ultra on Bedrock” as support for every model. Ultra is a reasoning setting, not Fast mode: the release-pinned catalog code still removes speed-tier metadata.
Choose the inference route separately. OpenAI’s Bedrock guide maps Mantle to in-Region inference and Runtime to cross-Region inference. Authentication is AWS-native; this direct model-request path does not use OpenAI’s hosted Responses API. Runtime does not offer hosted web search.
For GPT-6.1 Sol specifically, the current AWS model card documents these commercial routes. These are configuration choices, not evidence that your account can invoke them:
Inference scope | Codex provider | Model or profile |
|---|---|---|
In-Region: us-east-1 | amazon-bedrock | openai.gpt-6.1-sol |
US geographic cross-Region | amazon-bedrock-runtime | us.openai.gpt-6.1-sol |
Global cross-Region | amazon-bedrock-runtime | global.openai.gpt-6.1-sol |
Select a supported source Region and inspect the chosen profile’s destinations and permissions. AWS’s published short-context Standard rates also differ: Global costs US$2 per million uncached input tokens and US$10 per million output tokens; regional Mantle and US cross-Region cost US$2.20 and US$11. These rates apply at up to 272,000 input tokens and do not predict total agent-task cost.
Suggested acceptance check: inspect /status for the intended provider and model, then perform one permitted repository task and a follow-up. For V2 or Ultra adoption, record the effective catalog and behavior of that exact model. A plausible answer alone does not prove the intended route was used.
GovCloud support is a client change, not blanket model availability
The 0.161.0 Mantle client recognizes both us-gov-east-1 and us-gov-west-1. That does not establish service or model availability in both. The AWS Mantle endpoint page lists GovCloud West; the Sol model card checked for this guide does not establish Sol availability in GovCloud.
Follow OpenAI’s GovCloud configuration guide for the approved identity, model, endpoint, managed requirements and network restrictions. API-mode sessions do not inherit ChatGPT workspace requirements or role-based access controls, and sending inference to Bedrock does not make all application traffic AWS-only.
There is an important interaction with the MCP feature: the guide’s empty MCP allowlist blocks configured MCP servers. Do not weaken that deployment policy just to demonstrate the new login command. Confirm the integration belongs in the approved workflow, then verify that route failures cannot send content to an unapproved destination.
MCP: sign in without leaving the active session
MCP, or Model Context Protocol, connects the agent to external tools and context. For a configured OAuth-enabled server, enter this command inside the active Codex terminal session, replacing the placeholder with its configured name:
/mcp login <name>The new login flow opens authorization in the browser and reports success or failure in the originating thread. It is an in-session starting point, not browser-free authentication.
Afterward, inspect /mcp and retrieve one known permitted item. The existing shell commands codex mcp list and codex mcp login <server-name> remain documented. Keep tool allowlists and approval settings separate from sign-in success; leave write access unchanged for a read-only check.
For a concrete Jira or Confluence connection, use the Atlassian connection guide rather than treating authentication as the complete integration.
Cyber: distinguish automatic routing, a turn override and entitlement
The Daybreak opt-in change disables controls and automatic Cyber-program routing by default, including resumed sessions and background turns. Opt in with --enable cli_daybreak or features.cli_daybreak=true; daybreak=true alone is insufficient. The release notes require eligible ChatGPT sign-in, the OpenAI provider and advertised model/program support for automatic routing.
A stable CLI package does not make every optional feature mature: cli_daybreak is marked UnderDevelopment and default-off in the 0.161.0 feature registry.
For a single scripted turn,
codex exec --cyber-access-programacceptsstandard,daybreak_blueordaybreak_red. The TypeScript SDK equivalent iscyberAccessProgram. The per-turn selection change applies to new, resumed and prompted-fork turns without rewriting the saved choice; review and forks without a prompt reject the flag.An explicit override remains available when
cli_daybreakis disabled. Consequently, hiding the Daybreak controls is not a blanket prohibition on explicit selection. The opt-in implementation keeps those paths separate.For OpenAI API-key sessions, explicit forwarding requires
features.api_key_cyber_access_programs. That gate is default-off and independent of API-key model discovery. The provider check is for the built-in OpenAI provider; this flag is not a way to provision Bedrock access.
None of these controls grants account entitlement. OpenAI’s access documentation ties approval to the identity, organization or workspace, model and product surface; Blue approval does not include Red. In an eligible staging setup, compare default-off behavior, intentional opt-in and an explicit standard turn, then check the saved preference on the next turn.
Promote only the workflow you have checked
The release notes also report fixes for permission continuity, resumed history, database recovery and elevated Windows sessions. Keep the regression work relevant: where your workflow uses approved filesystem escalation, verify that denied reads and network restrictions remain enforced; where operations continue in the background, check their originating-turn permissions across a later turn.
Retain the candidate version, non-secret configuration, task inputs and outputs, usage, expected versus actual results and rollback procedure. Mark unavailable test cases unperformed. Promote the configuration that passes those checks, without simultaneously expanding its access. No release-specific coding-quality, speed or cost improvement was established by this reporting.
Methodology: AI-assisted reporting and analysis from official OpenAI documentation, release-pinned source, GitHub release metadata and AWS documentation, rechecked on October 7, 2026. No installation, live model call, OAuth flow or benchmark was performed. The acceptance checks are proposed, not observed results.
