Codex Desktop APP - Full Access mode keep asking for Permission - issue in 26.614.11602 - 26.616.32156

Open 💬 27 comments Opened Jun 18, 2026 by praveshkhatana
💡 Likely answer: A maintainer (github-actions[bot], contributor) responded on this thread — see the highlighted reply below.

What version of the Codex App are you using (From “About Codex” dialog)?

26.614.11602

What subscription do you have?

Pro Max

What platform is your computer?

macOS Darwin 25.5.0 arm64 arm

What issue are you seeing?

after recent update to 26.614.11602.
Now 'full access' mode keep asking for file edit, mcp run, etc. permissions.

What steps can reproduce the bug?

just upgrade to 26.614.11602 and use codex desktop app in full access mode.

What is the expected behavior?

_No response_

Additional information

_No response_

View original on GitHub ↗

27 Comments

github-actions[bot] contributor · 1 month ago

Potential duplicates detected. Please review them and close your issue if it is a duplicate.

  • #27803
  • #28574
  • #28296
  • #28776

Powered by Codex Action

justinjiaxinghu · 1 month ago

seeing same issue, seems to be related to an update?

praveshkhatana · 1 month ago
seeing same issue, seems to be related to an update?

Yes, this version contains Permission issues. I hope they solve it soon.

Anyone know how to switch to old stable version?

andreisoare-speak · 1 month ago

Same issue on Version 26.616.30709, it's unusable, asking every 5 seconds.

MantraMedia · 1 month ago

Lots of reports on X as well , let's hope the devs see it quick

praveshkhatana · 1 month ago

new update is here Version 26.616.31447

TJKlein · 1 month ago

Still having issues with Version 26.616.31447 on mac

HENGRUIZZZZ · 1 month ago

Still for 26.616.31447 on Mac, and having problems of installing Github plugin. Stucked

xiao2dou · 1 month ago

Same issue on Codex App 26.616.31447.

Feedback ID: 019eddad-5dac-78b0-a3ae-dcbf8d909761

Environment:

  • Subscription: Pro
  • Platform: Darwin 25.5.0 arm64 arm
  • App setting: Full Access enabled
  • Global config also contains:

``toml
approval_policy = "never"
sandbox_mode = "danger-full-access"
``

Observed behavior:

  • The app still repeatedly prompts for command approvals.
  • A new session behaves like a restricted workspace-write session.
  • Writing inside the local workspace succeeds.
  • Writing to a temporary directory succeeds.
  • Writing to ~/.codex/test fails with: Operation not permitted.

Expected behavior:
Full Access sessions should honor the selected permission profile and not keep prompting for approvals.

Pennliu · 1 month ago

Adding another macOS data point focused specifically on Approve for me / auto-review not taking effect.

Environment:

  • Codex Desktop App: 26.616.31447
  • Bundle build: 4133
  • Bundled CLI: codex-cli 0.142.0-alpha.1
  • Platform: macOS 26.5.1 / Darwin 25.5.0 / arm64

Relevant config:

approvals_reviewer = "auto_review"
approval_policy = "on-request"
sandbox_mode = "workspace-write"
default_permissions = ":workspace"

What I am seeing:

  • I want to use the Desktop App's Approve for me / auto_review approval mode.
  • However, the app effectively behaves as if only Request approval / user approval is available.
  • Approval requests still surface as manual approval prompts instead of being handled by the auto-reviewer.
  • This makes the Approve for me mode unusable on my current Desktop build.

Additional note:

  • My old config used approvals_reviewer = "guardian_subagent"; current source confirms this is a legacy alias for auto_review, so I normalized it to auto_review.
  • The issue still appears to be that the Desktop app's selected/effective approval reviewer does not reliably take effect.

Expected behavior:

  • When approvals_reviewer = "auto_review" or the Desktop UI is set to Approve for me, eligible approval prompts should be routed to the auto-reviewer rather than requiring manual Request approval every time.
jorgengk · 1 month ago

I’m seeing the same or a very similar issue after the latest update.

In my case, Codex keeps asking for approval repeatedly even though the session is set to Full Access. I also keep selecting “Approve for session”, but the same or very similar approval prompts keep coming back.

This is not just an occasional approval prompt. It happens so frequently that I’m effectively getting interrupted almost every minute, which makes Codex impossible to run unattended.

Expected behavior:

  • If Full Access is enabled, normal shell/file actions should not require repeated manual approval.
  • If I select “Approve for session”, Codex should remember that decision for matching actions during the same session.

Actual behavior:

  • Codex continues to ask for approval again and again.
  • “Approve for session” does not appear to be remembered or respected.
  • The workflow requires constant babysitting.

This started after a recent Codex update. It feels like either the approval cache is not working, or the effective runtime permission mode is stricter than what the UI shows.

This may be related to earlier reports such as #23393 and #24934.

TJKlein · 1 month ago

Version 26.616.32156 • Released Jun 19, 2026

Problem persists...

zikwall · 1 month ago

I updated a couple of days ago only because Codex was pushing the update very aggressively — the update notification was appearing almost on every click.

After the update, a serious issue appeared: Codex no longer seems to properly respect the auto approve and full access policies. Even with full access enabled, it still asks for confirmation for almost every file change.

As a result, I have to constantly click Approve — sometimes dozens of times per minute and hundreds of times during a single work session. This significantly disrupts the workflow and makes Codex extremely inconvenient to use, especially considering the $200 Pro subscription.

Please investigate this issue, because this behavior did not exist before the update.

soloish90 · 1 month ago

same here. (on mac). updated yesterday to latest version and immediately it requires approvals for everything it does - even though my codex desktop app is set for Full Access and the config is set to 'danger-full-access'

such a small bug, but such large consequences... unusable!

soloish90 · 1 month ago

I will say - i accidently fixed it somehow - i wish i new exactly how. i was trying to install an older version of Codex Desktop from a few days ago. when i opened the older version, it had a problem with reading my current session. it completely failed to do so. (i made a backup copy of current Codex.app beforehand)

i delete the 'older version' from applications and copied by backup version back in.

no more permissions problems. could the fix be as simple as deleting Codex.app from Applications and doing a fresh install?

if anyone tries it, let us know.

FireDragon11111 · 1 month ago

I am having the same issue as everyone else is above, I just updated about an hour ago to the most recent version, and at least on Windows I am seeing this permission issue. Not going to be using Codex at all if this issue persists for very long. It's the reason I don't use Antigravity. It's unusable this way.

praveshkhatana · 1 month ago

Has anyone else noticed a sudden spike in token usage after the recent updates? Previously, I never reached the limit even on the standard Pro 5x plan. However, over the last two days, 40% of my weekly limit on the 20x Pro plan has already been used up.

TJKlein · 1 month ago
Has anyone else noticed a sudden spike in token usage after the recent updates? Previously, I never reached the limit even on the standard Pro 5x plan. However, over the last two days, 40% of my weekly limit on the 20x Pro plan has already been used up.

Yes, same here. Even when going back to Opus 4.7 and low/medium, you burn through the tokens rather fast, which used to be like an infinite time horizon in the past.

hardW · 1 month ago

I hit the same regression in Codex App on macOS today.

Working version after rollback: 26.611.62324
Broken latest version: 26.616.x, updated this morning through the Codex App updater
Platform: macOS arm64

Impact:
Approve for me stopped working. Codex started asking for approval on nearly every step. Switching to the more permissive Full Access / approve-all style mode did not fix it. The app still kept prompting for routine agent actions.

This breaks the main agent workflow because the agent can no longer run unattended. I had to approve actions constantly, then rolled back to 26.611.62324. After rollback, the workflow is usable again.

This does not look like a local machine issue, because other users are reporting the same approval regression in this issue.

TJKlein · 1 month ago

Actually, for me logging out and logging in again resolved the issue (with the latest version).

FireDragon11111 · 1 month ago
I am having the same issue as everyone else is above, I just updated about an hour ago to the most recent version, and at least on Windows I am seeing this permission issue. Not going to be using Codex at all if this issue persists for very long. It's the reason I don't use Antigravity. It's unusable this way.

Hey everyone I tried a few things and going into Installed Apps on Windows -> Codex -> Advanced Options -> Reset actually worked. It didnt lose any data, though I did make a full ZIP backup of all threads and context beforehand just in case

completej · 1 month ago
> I am having the same issue as everyone else is above, I just updated about an hour ago to the most recent version, and at least on Windows I am seeing this permission issue. Not going to be using Codex at all if this issue persists for very long. It's the reason I don't use Antigravity. It's unusable this way. Hey everyone I tried a few things and going into Installed Apps on Windows -> Codex -> Advanced Options -> Reset actually worked. It didnt lose any data, though I did make a full ZIP backup of all threads and context beforehand just in case

This worked for me as well. No backup necessary. Logged out, closed app, reset, and reloaded.

jorgengk · 1 month ago

<img width="1400" height="465" alt="Image" src="https://github.com/user-attachments/assets/e0bfa51b-f842-4165-aa9d-5886d47cc9f8" />

just came over theese settings. Switched them as in pic. Might seem to work now...

FireDragon11111 · 1 month ago
<img width="1400" height="465" alt="Image" src="https://github.com/user-attachments/assets/e0bfa51b-f842-4165-aa9d-5886d47cc9f8" /> just came over theese settings. Switched them as in pic. Might seem to work now...

Mine had these messed up also; but switching them back to the correct setting didn't do anything for me - only the Windows App -> Reset process worked for me

Pennliu · 1 month ago

Follow-up: after upgrading the Desktop app, this appears fixed for me.

Current version:

  • Codex Desktop App: 26.616.32156
  • Bundle build: 4157
  • Bundled CLI: codex-cli 0.142.0-alpha.1
  • Platform: macOS 26.5.1 / Darwin 25.5.0 / arm64

With the same relevant config:

approvals_reviewer = "auto_review"
approval_policy = "on-request"
sandbox_mode = "workspace-write"
default_permissions = ":workspace"

The Approve for me / auto_review mode is now working again after the upgrade. The issue I saw on 26.616.31447 no longer reproduces on 26.616.32156.

musnows · 28 days ago

I'm also seeing this issue on Codex Desktop for macOS after a recent update.

Full Access is enabled, but the app still repeatedly asks for manual confirmation/approval for actions that should be covered by the Full Access permission profile. This makes longer tasks difficult to run because the session keeps stopping for user confirmation.

Expected behavior: once Full Access is enabled, eligible actions should proceed without repeatedly requiring manual approval.

valentin-demange · 27 days ago

Adding another current macOS data point from Codex Desktop.

Environment:

  • Codex Desktop App build shown in local app resources/config: 26.616.71553
  • CLI: codex-cli 0.120.0
  • Platform: macOS / Darwin, arm64
  • Workspace/project is trusted in ~/.codex/config.toml
  • Current session context reports filesystem sandbox as unrestricted/full access and approval policy as never

Observed behavior:

  • Full Access / auto-approve is still not being respected.
  • Codex continues asking for approvals repeatedly during normal work.
  • This is happening even though the effective session metadata says full filesystem access and no approval prompts should be required.

Expected behavior:

  • Full Access / auto-approve should allow routine shell/file actions to proceed without manual approval prompts in trusted workspaces.

Impact:

  • The agent can no longer run unattended and needs constant manual approval, which makes the Full Access / auto-approve feature effectively unusable.