Verify the provider
Confirm the publisher, package name or remote endpoint before connecting it.

Create a copy-ready config.toml block for a local STDIO or remote Streamable HTTP MCP server.
Choose how Codex reaches the server and enter the minimum connection information.
Security reminderKeep tokens in environment variables or an approved authentication flow. Never commit live credentials.
Review every value before adding it to a trusted Codex configuration file.
A valid structure is only the beginning. Confirm the connection itself is trusted and appropriately limited.
Confirm the publisher, package name or remote endpoint before connecting it.
Use environment variables or the provider’s supported authentication flow.
Limit the toolset and keep meaningful writes behind approval.