Daily harness signal

Same tool.
Different account.
New approval.

September 5, 2026 · JST · One fresh finding · Codex Apps
Remembering a tool approval without its account can silently transfer authority between personal and work data. Codex’s new account-binding repair makes that distinction an executable release gate.
Fresh · source dates September 1 / 3, 2026

Bind selection, policy, and approval memory

Use when: one Codex Apps connector has multiple connected accounts, especially when the same write-capable tool can target both. A connector/tool match alone must not reuse another account’s session approval.

Action: require Codex 0.153.0 or later. For multi-account Apps tools, resolve link_id from arguments when metadata sets requires_explicit_link_id=true; reject missing, blank, or non-string selectors before approval or execution. Carry that resolved identity into policy evaluation, approval-request metadata, and the remembered-approval key. For sensitive accounts, set default_tools_approval_mode="prompt" and approvals_reviewer="user" under [apps.<app_id>.links.<link_id>], substituting actual IDs. Inspect per-tool overrides and managed policy: both outrank the account’s approval-mode default.

Acceptance check: in an owned mock connector, keep catalog account A fixed while calls select A, B, then A. Use auto approval mode, user review, and session-persisted consent to test caching: A and B must each prompt; returning to A may reuse only A’s approval. A legacy no-selector variant must request separate consent. With explicit selection required, missing, empty, whitespace, and numeric selectors must produce neither approval requests nor server calls. Separately enable B’s prompt/user override: B must route to the user, with B’s link_id in the elicitation metadata. Inspect server-side account receipts, not just the assistant’s description.

Evidence: the stable release explicitly ships account-scoped remembered approvals. Merged PRs #42054, #42056, #42133, and #42134 expose the selector resolver, policy precedence, cache binding, and elicitation metadata. The inspected auto_session_approval_is_scoped_to_tool_link_id regression uses a fixed catalog account, two selected accounts, and a legacy case.

Caveat: this is Codex Apps session-approval isolation, not generic MCP OAuth account verification or cross-session consent persistence. Selector validation checks shape, not account ownership; the server must enforce authorization. Upstream’s integration file excludes Windows and can skip without network access. A skipped test is not acceptance; no runtime canary was executed for this issue.

Compact source notes

  1. Codex 0.153.0 — September 3, 2026. The inspected current patch, 0.153.2, changes display text, not this account-binding behavior.
  2. September 1 implementations: configuration #42047, selector #42054, policy #42056, session key #42133, and request identity #42134.
  3. Pinned source: account resolver, policy evaluator, and integration fixture. Primary source and test inspection, not a local test result.
  4. Countercheck: older approval-fatigue report #16911 concerns a different persistence scope. The current configuration reference does not enumerate these account-link fields; the merged schema and implementation are the precise evidence.
  5. Anchor lens: shipped repair and inspectable fixtures. Unity lens: account identity must survive selection, policy, and consent caching. confidence_confirmed for shipped semantics; deployment acceptance remains unmeasured. Falsifiers: A’s consent authorizes B, malformed required selectors reach the server, or request metadata names the wrong account.