On October 7, OpenAI shipped Codex CLI 0.161.0. The headline feature is one command: /mcp login <name>, signing in to MCP servers from the active terminal session.

It looks small and matters a lot to daily coding-agent users. External tool auth, connection recovery, permission durability. Apart from models getting smarter, work stops when these three break. This post reads the full release notes and keeps only what touches practice.

Headline: MCP login without leaving the session

The change in one sketch:

Before: MCP auth stuck → leave the session for browsers and settings
Now:    inside the terminal session → /mcp login <name> → auth in place

Three PRs travel together. /mcp login in the TUI (#49290), enterprise MCP sign-in with account-scoped grant cleanup (#49276), and restricted enterprise MCP auth that fails closed on config refresh (#49260).

The enterprise wording matters. Fail closed. When configuration refreshes, auth state is not optimistically kept; it fails toward closed. Account-scoped grants get cleaned up when they stop applying. Easier and more latched at once. It shares the spirit of the step-up approval flow in the MCP re-auth post. Connected is not the end; every ask gets an answer.

Model news alongside: GPT-6.1 Sol becomes the default

The release also touched the model catalog.

1. Default catalog model → GPT-6.1 Sol, bundled and Bedrock (#49318, #49339)
2. Multi-agent V2 + Ultra reasoning on Bedrock (#49345)
3. AWS GovCloud regions accepted for Bedrock Mantle (#49813)

Defaults change feel. Fresh installs start on GPT-6.1 Sol. Multi-agent teams on Bedrock should check V2 and Ultra reasoning; GovCloud shops should check region acceptance. Catalog, permissions, and regions shipped as one update, not one model.

Permission durability: reconnects keep their permissions

The most welcome part for practitioners:

1. Approved filesystem escalation grants broader writes while
   preserving denied reads and network restrictions (#49353)
2. Background tasks retain their originating turn's permissions (#49880)
3. Explicit launch permissions survive reconnects and new sessions (#49809)
4. Implicit client settings stop overwriting server and saved-thread
   web-search settings (#49799)
5. The TUI follows server-authoritative permissions (#49472)

In plain words: approving "this folder is writable" no longer silently unlocks denied reads and network blocks. Background jobs stop losing their originating turn's permissions. Explicitly granted permissions survive terminal drops and reconnects. Permissions in agent operations are session-spanning state, not one-time tickets.

It overlaps the four-layer security post. Stop when hard to undo, allow narrowly, keep denials. This time Codex extends the principle across sessions, reconnects, and background work.

Session recovery: the way back after a stall

Long jobs stall eventually. This release repairs the way back.

Resume: thread resume includes latest committed history (#49599)
Recover: startup detects SQLite corruption early, preserves backups (#49701)
Retry: honors server retry guidance plus WebSocket-to-HTTP fallback (#49441)
Windows: elevated sessions start embedded, sandboxed PowerShell keeps
         relative paths (#49855, #49690)
Input: Enter submits buffered input after paste detection expires (#49810)

The SQLite handling is the practical one. Detect early at startup, keep the damaged database as a backup. Never silently overwrite. Same direction as checkpoints and resume in the durable execution post. Runtimes, not models, save long jobs.

Everything else: Daybreak goes opt-in

Daybreak ships bundled too. It needs --enable cli_daybreak or features.cli_daybreak=true; the old daybreak=true alone no longer suffices. With it off, controls, indicators, and /daybreak hide and automatic Cyber routing drops out. Per-turn program choice comes from codex exec --cyber-access-program and the SDK's cyberAccessProgram.

Default: Daybreak off (quiet)
Enable:  --enable cli_daybreak or features.cli_daybreak=true
Per turn: codex exec --cyber-access-program (saved choice untouched)

Note the default. Quiet with no automatic routing is now the baseline. Agent auto-behavior defaults are moving toward less.

CodeBridge Mini Lab: three regression tests

The briefing's action, moved into tests verbatim.

# 1. MCP auth regression
# Pick 1 stuck MCP server inside the session
/mcp login <name>
# → does auth finish without leaving the session?
# → does enterprise config refresh fail closed?

# 2. Session reconnect regression
# Grant 1 explicit permission (e.g. write to a folder)
# Drop and reattach the terminal
# → does the permission survive?
# → are denied reads and networks still blocked?

# 3. File-access permission regression
# Check scope after approved escalation
# → broader writes work?
# → denied reads and networks stay blocked?
Checklist:
 [ ] /mcp login completes in the current session
 [ ] explicit permissions survive reconnects
 [ ] background jobs inherit the originating turn's permissions
 [ ] thread resume attaches the latest history
 [ ] Daybreak defaults to off (no auto routing)

It adds three lines, auth, reconnect, and permissions, to the verification loop from using Claude Code on real projects.

Conclusion: agent operations are auth, recovery, and permissions

One line to close.

A model doing work well and an agent finishing work are different problems.

0.161.0 shows it plainly. In-terminal login cuts auth friction, reconnect, background, and SQLite recovery save long jobs, and escalate-while-keeping-denials carries permissions past the session. Behind flashy model launches, these decide productivity.

Today's job is small. Upgrade the CLI to 0.161.0 and run the three tests once each. Whatever blocks is the runtime to fix next.

Further reading

References

Go deeper with a course

To practice controlling agents through permission, approval, and verification flows, this course builds CLAUDE.md, skills, hooks, subagents, and MCP in real projects, exactly like the regression tests here.