Bind selection, policy, and approval memory
Use when: one Codex Apps connector has multiple connected accounts, especially when the same write-capable tool can target both. A connector/tool match alone must not reuse another account’s session approval.
Action:
require
Codex
0.153.0
or
later.
For
multi-account
Apps
tools,
resolve
link_id
from
arguments
when
metadata
sets
requires_explicit_link_id=true;
reject
missing,
blank,
or
non-string
selectors
before
approval
or
execution.
Carry
that
resolved
identity
into
policy
evaluation,
approval-request
metadata,
and
the
remembered-approval
key.
For
sensitive
accounts,
set
default_tools_approval_mode="prompt"
and
approvals_reviewer="user"
under
[apps.<app_id>.links.<link_id>],
substituting
actual
IDs.
Inspect
per-tool
overrides
and
managed
policy:
both
outrank
the
account’s
approval-mode
default.
Acceptance
check:
in
an
owned
mock
connector,
keep
catalog
account
A
fixed
while
calls
select
A,
B,
then
A.
Use
auto
approval
mode,
user
review,
and
session-persisted
consent
to
test
caching:
A
and
B
must
each
prompt;
returning
to
A
may
reuse
only
A’s
approval.
A
legacy
no-selector
variant
must
request
separate
consent.
With
explicit
selection
required,
missing,
empty,
whitespace,
and
numeric
selectors
must
produce
neither
approval
requests
nor
server
calls.
Separately
enable
B’s
prompt/user
override:
B
must
route
to
the
user,
with
B’s
link_id
in
the
elicitation
metadata.
Inspect
server-side
account
receipts,
not
just
the
assistant’s
description.
Evidence:
the
stable
release
explicitly
ships
account-scoped
remembered
approvals.
Merged
PRs
#42054,
#42056,
#42133,
and
#42134
expose
the
selector
resolver,
policy
precedence,
cache
binding,
and
elicitation
metadata.
The
inspected
auto_session_approval_is_scoped_to_tool_link_id
regression
uses
a
fixed
catalog
account,
two
selected
accounts,
and
a
legacy
case.
Caveat: this is Codex Apps session-approval isolation, not generic MCP OAuth account verification or cross-session consent persistence. Selector validation checks shape, not account ownership; the server must enforce authorization. Upstream’s integration file excludes Windows and can skip without network access. A skipped test is not acceptance; no runtime canary was executed for this issue.