What you’ll need
- A paid plan (Gold, Platinum, or Diamond)
- A local OpenAI Codex client — the Codex CLI, desktop app, or IDE extension — installed and signed in
Pick your path
Codex can use a remote MCP server with OAuth or a bearer token. Use OAuth when your local Codex client completes Hoard’s sign-in flow; use a bearer token when you need terminal-only setup or OAuth is not offered by your installed Codex client.
The bearer-token path works across local Codex clients. Keep the token in an environment variable rather than in a committed project config.
OAuth (plugin UI)
1
Edit your Codex config
Open
~/.codex/config.toml (create it if it doesn’t exist) and add:2
Run Codex
Start a Codex session:The first time you use a Hoard tool, Codex may open your browser to sign in. Sign in to Hoard and click Allow. If your installed Codex client does not offer or complete OAuth, use the bearer-token path below instead.
3
Try it out
Ask Codex:
“use hoard: what’s my repricing scope set to?”Codex calls Hoard via the connector and reports back.
Bearer token (CLI or local Codex client)
Use your Hoard API key as a bearer token when you want terminal-only setup or your Codex client cannot complete the OAuth flow. The fastest path is the installer: sign in, open https://www.tryhoard.com/install/codex, and paste the one-line command into your terminal. It registers the server and setsHOARD_API_KEY in your shell rc in one step. The steps below are the manual equivalent.
1
Grab your API key
Open Settings → Profile and copy your API key from the Account card. It’s a 64-character hex string.
2
Register Hoard with Codex
Export the key and register the server in one shot:Make
HOARD_API_KEY permanent by adding the export line to your shell rc file (~/.zshrc, ~/.bashrc).3
Verify
hoard entry should now show Auth: Bearer (env) instead of Auth: Unsupported.4
Try it out
Ask Codex:
“use hoard: what’s my repricing scope set to?”
Revoking access
- OAuth path: Open Settings → Assistants in Hoard and click Revoke next to the Codex entry.
- Bearer-token path: Open Settings → Profile, find API Key, and click Regenerate key. The old key stops working immediately. Update
HOARD_API_KEYon every machine that uses it, or re-run the installer. See Rotating your agent bearer key.