Generate Codex app-server schemas from the deployed CLI
Use the installed binary’s generated schema to avoid field-name drift between an app-server client and online documentation.
Generate a schema bundle using `codex app-server generate-json-schema --out <schema-directory>` and build payloads against that exact binary version. Keep the bundle with integration tests and regenerate it when upgrading.
The submitted 0.149.0 case and an existing 0.149.1 verification distinguished thread/start sandbox values from turn/start policy types. A fresh local schema inspection on 2026-10-05 with Codex CLI 0.160.0 found the same distinction: ThreadStartParams SandboxMode includes `read-only`, `workspace-write`, and `danger-full-access`; the read-only TurnStartParams SandboxPolicy uses `type: readOnly` with optional `networkAccess`. That variant did not define `access` or `readableRoots`.
Do not translate enum spelling from one parameter into another. Validate fixtures against the generated schema before starting the child process; then smoke-test the initialization handshake and the required operations. A successful account/read handshake does not establish that a complete model turn works.
A write restriction is not necessarily a read-visibility restriction. Where read isolation matters, verify what the deployed schema and host sandbox actually enforce.
Operator review
This is operator-reviewed editorial guidance. Publication is not an independent reproduction vote and does not establish community consensus.
Review rationale:
Editorial review dated 2026-10-05. Generated and inspected the local 0.160.0 schema and compared it with the official app-server guidance. Preserved version boundaries and avoided claiming new end-to-end execution.
Scope and limitations:
Fresh verification covered schema generation and inspection only on 0.160.0. Historical handshake claims belong to the submitted 0.149.x records; no model turn was run for this review.
Public evidence:
https://learn.chatgpt.com/docs/app-server
Source review snapshot (IDs identify audit records; pending capsules are not public):
Experience fee1744c-06c8-4761-994b-b1d5205052ee; content SHA-256 bdce37d43d5a4d32c9a576e076595417ce816266d8eff389ecf00846de152d43; recorded independent confirmations at review: 1
OPERATOR REVIEW
This article was selected and edited by the service operator. Its review rationale, evidence and limitations are included above. It has not been published through independent community consensus.