Codex Elevated Input and Copilot Balanced Now Change Unattended Defaults

At a glance

  • Codex v0.158.0 (1:07 AM ET, 28 Sep) now asks for approval by default before it sends input to a terminal running with elevated permissions, while runtime-only grants stop triggering unnecessary reviews.
  • The same release lets codex mcp add use a pre-registered OAuth client secret and lets direct exec-server WebSocket connections require a bearer token.
  • Starting today, per GitHub's 28 Aug notice, Copilot code review left on Default uses Balanced instead of Lite, unless you explicitly selected Lite.
  • GitHub's single Copilot experience for github.com chat, GitHub Mobile chat and cloud agent arrives no earlier than today, under one policy that will be on by default after launch.

Monday is a defaults day rather than a launch day, because the two changes worth your time both alter what happens when nobody touches a setting. Codex shipped v0.158.0 overnight and now asks before it types into a terminal running with elevated permissions, while GitHub’s 28 Aug plan for Copilot code review takes effect today, so a review effort left on Default now runs the deeper Balanced pass. Saturday’s brief already covered Claude Code v2.1.283’s exact model matching and GitHub’s managed settings validator, so if you missed those, read Saturday’s post rather than expecting a recap here.

Treat today as the morning you make both defaults explicit: pin Codex at v0.158.0 and tell on-call that an approval prompt before Codex sends input to an elevated terminal is working as designed, then set Copilot review effort to Lite or Balanced on purpose at every level you own.

Top Stories

Codex v0.158.0: input to elevated terminals now needs approval

Practical dev impact: OpenAI published Codex v0.158.0 as a stable release at 1:07 AM ET today, and the change that affects running teams is that terminal input approval is now enabled by default for commands running with elevated permissions. The check sits on input rather than launch: when Codex tries to send keystrokes or stdin to a terminal it started outside the sandbox or with extra permissions, that input now goes through approval first (the change promotes the write_stdin_approval feature to stable and on by default). Runtime-only grants no longer cause unnecessary reviews, so the stop is aimed at elevated terminals, and a session that used to feed an elevated process unattended will now sit and wait. Auto-review approvals also retry when new user input arrives, so asking the agent for a status update no longer aborts a pending action. That is the right trade for production work, but it will look like a hung agent to anyone who has not been told, so put the prompt in the runbook the day you roll out the version.

The release also closes two gaps that matter once Codex leaves a laptop. MCP servers that require a pre-registered OAuth client secret now connect, including through codex mcp add --oauth-client-secret, which also needs --url and --oauth-client-id, and direct exec-server WebSocket connections can be secured with bearer tokens, including connections configured through app-server. If either server is reachable beyond the local machine, turn the token on now, and keep the MCP secret out of shared shell history and committed config. Sandbox fixes cover Windows 10 paths and stored credentials, Linux nested writable roots, and Git metadata protection on Linux and macOS, while the fullscreen TUI gains configurable copy-on-select and right-click paste that keep Markdown in copied selections.

Copilot code review: Default now means Balanced

Practical dev impact: GitHub’s 28 Aug policy note set today as the day the review effort value of Default starts using Balanced, for existing and new repositories and organizations using Copilot code review. If you explicitly selected Lite, GitHub says it respects that choice, so the orgs and repos that change are the ones still sitting on Default. The organization default applies to every owned repository that has not picked its own level, the repository default applies to automatically requested reviews, and a manually requested review can still pick a level from the Reviewers bar on the pull request. GitHub’s docs describe Balanced as deeper analysis of complex logic, security-sensitive code and cross-service changes, and they also say Balanced reviews use more AI credits and may consume marginally more GitHub Actions minutes. If rulesets request a review on every new push, that difference multiplies, so decide per repository. The 23 Sep release also added an enterprise default review effort that organization-owned repositories inherit, so check that setting too if your enterprise left it on the GitHub default.

The same 28 Aug note said that no earlier than 28 Sep, GitHub will relaunch Copilot Chat on github.com, Copilot Chat in GitHub Mobile and Copilot cloud agent as one experience under a single policy, enabled by default after launch. Chat on github.com moves to the agent sessions experience, so chat data will be retained for the life of the account instead of 28 days, and anyone who opts out loses Copilot on github.com and GitHub Mobile once the new experience launches. GitHub has committed only to “no earlier than,” so check the policy under Copilot settings, Copilot cloud agent (coming soon), rather than assuming the switch has already flipped.

What else moved, and what did not

Practical dev impact: Gemini CLI stable has not moved since 23 Sep, but the v0.62.0-preview.0 build from that day is where a Gemini team can try Gemini 3.8 Flash and 3.5 Flash Lite without touching production defaults. Cursor’s weekend movement came in the Origin API, which is in early beta. There, Merge Pull Request now returns Aborted (HTTP 409) instead of InvalidArgument (HTTP 400) when a head branch has moved past its latest recorded version, and a pageSize sent with a pageToken now applies to that page on fourteen list endpoints, including List Pull Requests and List Repos, which matters only to teams automating merges or listings against Origin.

Practical Impact Analysis

The through-line is that both of today’s changes land on the unattended path, which is exactly where nobody is looking when a default moves. An elevated Codex session and a Copilot review fired on every push are both jobs a team set up once and stopped thinking about, so a new default changes behavior without anyone touching config. Codex moved toward caution and GitHub moved toward depth, and each has a cost you only notice later, since one shows up as a stalled agent and the other as a credit report.

That is why the useful response is the same for both: replace the implicit default with an explicit choice you can defend. Pin Codex at v0.158.0, keep the elevated approval on, and write down which sessions may run elevated at all, because the prompt only helps if on-call expects it. For Copilot, pick Lite or Balanced per repository instead of inheriting Default, since the same Balanced pass that is worth it on security-sensitive services may be wasted on a docs repo that gets a review on every push.

The unified Copilot policy is the item to watch this week, because it will be on by default after launch and opting out has a visible cost. Admins who want chat on github.com and Mobile to keep working do not need to act, but anyone planning to restrict cloud agent should read the policy first, since one switch will replace the old separate ones.

Tutorial

Make today’s two defaults explicit. About fifteen minutes. The block runs on macOS or Linux (or WSL on Windows) with bash and assumes Codex is installed and on your PATH. It changes nothing locally or on GitHub, because it only reads codex output and checks the review effort values you pass in.

  1. Upgrade Codex to v0.158.0 through your usual install channel on every machine that runs elevated sessions, then save the block below as monday-check.sh.
  2. Look up the review effort level your organization and your busiest repository use, then run the block with those values, for example ORG_EFFORT=Lite REPO_EFFORT=Balanced bash monday-check.sh. Any level you leave out is treated as Default and flagged.
  3. For any level the block flags, open repository or organization Settings, then under “Code, planning, and automation” click Copilot, then Code review, and set “Review effort level” to Lite or Balanced. Your personal level lives under your profile, Copilot settings, Code review, and enterprise admins can set one enterprise default that organization-owned repositories inherit.
  4. In an interactive Codex session, let Codex start one interactive command that needs elevated permissions in your setup, approve the launch as usual, and confirm Codex asks again before it sends input to that running terminal, then add that expectation to your on-call runbook.
  5. Admins: open Copilot settings, select Copilot cloud agent (coming soon), and confirm the single policy matches whether github.com and Mobile chat should stay on.
bash Tutorial
#!/usr/bin/env bash
# Monday check: Codex v0.158.0 floor, MCP OAuth flag, review effort left on Default.
# Usage: ORG_EFFORT=Lite REPO_EFFORT=Balanced bash monday-check.sh
set -u
FLOOR="0.158.0"

if command -v codex >/dev/null 2>&1; then
  # 1) From v0.158.0, input sent to elevated terminals needs approval by default
  VER="$(codex --version 2>/dev/null | grep -Eo '[0-9]+\.[0-9]+\.[0-9]+' | head -n 1)"
  IFS=. read -r a b c <<<"${VER:-0.0.0}"
  IFS=. read -r x y z <<<"$FLOOR"
  if (( a > x || (a == x && (b > y || (b == y && c >= z))) )); then
    echo "OK   codex $VER meets the $FLOOR floor"
  else
    echo "FAIL codex ${VER:-unknown} is below $FLOOR; upgrade before unattended elevated runs"

... click "Show full code" below to expand
▸ Show full code (34 lines)
#!/usr/bin/env bash
# Monday check: Codex v0.158.0 floor, MCP OAuth flag, review effort left on Default.
# Usage: ORG_EFFORT=Lite REPO_EFFORT=Balanced bash monday-check.sh
set -u
FLOOR="0.158.0"

if command -v codex >/dev/null 2>&1; then
  # 1) From v0.158.0, input sent to elevated terminals needs approval by default
  VER="$(codex --version 2>/dev/null | grep -Eo '[0-9]+\.[0-9]+\.[0-9]+' | head -n 1)"
  IFS=. read -r a b c <<<"${VER:-0.0.0}"
  IFS=. read -r x y z <<<"$FLOOR"
  if (( a > x || (a == x && (b > y || (b == y && c >= z))) )); then
    echo "OK   codex $VER meets the $FLOOR floor"
  else
    echo "FAIL codex ${VER:-unknown} is below $FLOOR; upgrade before unattended elevated runs"
  fi

  # 2) This build should list the MCP OAuth client-secret flag
  if codex mcp add --help 2>&1 | grep -q -- '--oauth-client-secret'; then
    echo "OK   codex mcp add lists --oauth-client-secret"
  else
    echo "WARN codex mcp add --help does not list --oauth-client-secret"
  fi
else
  echo "SKIP codex is not on PATH"
fi

# 3) Copilot code review: Default uses Balanced starting 28 Sep 2026
for level in "org=${ORG_EFFORT:-Default}" "repo=${REPO_EFFORT:-Default}"; do
  case "${level#*=}" in
    Lite|lite|Balanced|balanced) echo "OK   ${level%%=*} review effort is explicitly ${level#*=}" ;;
    *) echo "WARN ${level%%=*} review effort is ${level#*=}; Default now uses Balanced" ;;
  esac
done

You are done when both Codex lines print OK, neither review level prints WARN, and Codex asks for approval before sending input to an elevated terminal.

Recommended AI prompt

Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever AI you use.

You are a staff engineer helping me make two changed defaults explicit for my team this week. I will paste the output of codex --version from our developer machines and CI, a short description of which Codex sessions run with elevated permissions or expose exec-server, app-server or MCP servers beyond localhost, the Copilot code review effort level set at our enterprise, organization and busiest repositories along with whether rulesets request a review on every push, and our current setting under Copilot cloud agent (coming soon). Using only what I paste, tell me which machines are below Codex v0.158.0 and what our on-call runbook should say now that Codex asks for approval by default before sending input to terminals running with elevated permissions; whether any exposed exec-server or app-server connection still needs a bearer token and whether any MCP server needs codex mcp add --oauth-client-secret; which repositories should explicitly select Lite and which should keep Balanced now that Default uses Balanced, keeping in mind that Balanced uses more AI credits; and whether our unified Copilot policy setting would cut off chat on github.com or GitHub Mobile once that experience launches. Keep your first reply to that four-part checklist, do not invent settings, flags or versions I did not give you, and wait for my paste before expanding.

Recommended AI prompt

Explore each Top Story in Grok. Links open in a new tab. On phones, the same link may open the Grok app if you have it installed (via your device's normal link handling).

Article: Codex Elevated Input and Copilot Balanced Now Change Unattended Defaults

Privacy: links open grok.com in your session only. AIDevPulse does not run your prompts through our API.

Leave a Comment