Codex Desktop: BrowserOS MCP "Always allow" does not persist and permission prompts keep reappearing

Resolved 💬 1 comment Opened Apr 20, 2026 by ghosTM55 Closed Apr 25, 2026

Summary

When using BrowserOS MCP tools in Codex Desktop, choosing Always allow in the permission prompt does not persist. Subsequent BrowserOS tool calls still trigger the same permission confirmation again.

Environment

  • Product: Codex Desktop
  • Platform: macOS on Apple Silicon
  • Account: ChatGPT Pro
  • Approximate version context: local Codex state shows latest available version 0.121.0 checked on April 20, 2026, but the exact About dialog version was not captured during this report.
  • MCP server: BrowserOS via http://127.0.0.1:9000/mcp

Steps to reproduce

  1. Enable BrowserOS MCP in Codex Desktop.
  2. Open a thread and invoke a BrowserOS tool call.
  3. In the permission dialog, choose Always allow and click Submit.
  4. Invoke another BrowserOS tool call of the same type in the same thread.
  5. Observe that Codex asks for permission again.
  6. Restart Codex Desktop.
  7. Repeat the same BrowserOS action.
  8. Observe that the permission prompt still reappears.

Expected behavior

After selecting Always allow, Codex should stop prompting again for subsequent BrowserOS MCP tool calls, at least for the same server or same tool category.

Actual behavior

Codex continues to show permission prompts for later BrowserOS MCP tool calls even after Always allow was selected. Restarting the app does not resolve it.

Concrete example

This reproduced while using BrowserOS to interact with X/Twitter and switch between timeline tabs such as Following, IT Folks, and Science in the same session.

Additional notes

  • BrowserOS itself was reachable and functioning.
  • The issue appears to be permission persistence, not MCP connectivity.
  • This was reproduced multiple times in the same session and after restarting Codex Desktop.

View original on GitHub ↗

This issue has 1 comment on GitHub. Read the full discussion on GitHub ↗