AI Coding Tools Roundup: Codex CLI Ships Stable v0.158.0 With Default Terminal Approval

OpenAI's Codex CLI is the headline today: version 0.158.0 graduated to stable with OAuth client secrets for MCP servers and terminal input approval turned on by default for elevated-permission commands. OpenCode followed with v1.18.33, a bugfix release that stops credentials and sensitive headers from leaking into debug output, and GitHub Copilot CLI quietly shipped v1.0.89-5 with small editing conveniences. Claude Code stayed put at v2.1.283, the model-locking release from September 25. Here's what changed.
Codex CLI 0.158.0: OAuth for MCP Servers, Approval On by Default
OpenAI cut Codex CLI 0.158.0 from 132 commits and 54 contributors. The release lets Codex connect to MCP servers that require pre-registered OAuth client secrets, including via "codex mcp add --oauth-client-secret", and it secures direct exec-server WebSocket connections with bearer tokens, including connections configured through app-server. The bigger behavior change: terminal input approval is now enabled by default for commands running with elevated permissions, so runtime-only grants no longer trigger unnecessary review prompts. Image generation and editing can also explicitly request transparent backgrounds, and edits now accept file-backed conversation images. On the terminal side, the fullscreen TUI gained configurable copy-on-select and right-click paste, and copied transcript selections now preserve Markdown formatting.
Sandbox, Approval, and Rendering Fixes
0.158.0 also closes out a run of platform bugs: Windows sandbox failures tied to ordinary Windows 10 paths, rejected stored credentials, and oversized permission policies are fixed, and Linux sandbox startup now works with nested writable roots while preserving Git metadata protections across writable roots on both Linux and macOS. macOS patch operations recognize system path aliases already covered by existing permissions, cutting down on redundant approval prompts, and approval reviews now retry when new user input arrives instead of letting a stray status question abort a pending action. Mermaid flowcharts render quoted labels and ampersands correctly, and unsupported diagrams now explain why they fall back to source instead of failing silently.
OpenCode v1.18.33: Debug Logs Stop Leaking Secrets
OpenCode's v1.18.33 is a focused bugfix release. Cloudflare AI Gateway models now honor provider response and stream timeouts instead of hanging past the configured limit, and MCP browser launch failures are reported when the launcher process exits immediately rather than failing silently. The most notable fix for self-hosted teams: debug configuration output now redacts credentials and sensitive headers before printing, closing a real exposure risk for anyone who has shared a debug dump while troubleshooting. The release also aligns Gemini thinking defaults and effort options with the controls actually supported across each Gemini model generation, following contributions from five community members.
GitHub Copilot CLI v1.0.89-5: Small Quality-of-Life Polish
GitHub Copilot CLI's rolling v1.0.89 line added left-click support for form inputs and for opening Claude Code rule files directly from the CLI, plus session notifications that surface when a background turn has new output waiting. It's a minor release compared to Codex and OpenCode, but it continues Copilot CLI's fast weekly cadence, which earlier in the v1.0.89 line also added GPT-6 Sol and GPT-6 Luna model support and MCP OAuth client improvements.
Claude Code Holds at v2.1.283
Claude Code shipped nothing new today, remaining on v2.1.283 from September 25 — the release that added the availableModelsMatch and deniedModels managed settings for locking down model choice, plus the /doctor prompt-audit command for auditing CLAUDE.md files and prompting patterns. Worth watching after an unusually active week of daily point releases.
What It Means for Developers
If you run Codex CLI, the default-on terminal approval for elevated-permission commands is the change to notice first — it's a safety default, not an optional toggle, so review your approval policy if you rely on unattended elevated commands. Windows and Linux sandbox users should update immediately given the path, credential, and nested-root fixes. OpenCode self-hosters should upgrade to v1.18.33 before sharing any debug output, since earlier versions could print credentials and sensitive headers in the clear. Copilot CLI and Claude Code users have only incremental changes to note today.
Resources & References
Comments
Share your thoughts and join the conversation
