Skip to main content

Overview

The Restrict Codex Desktop egress recipe creates this network rule and policy for you. See Recipes.
Codex Desktop can open a built-in or external browser for web search. Teams often want coding agents to use an approved MCP server instead. Formal can enforce that on macOS with Endpoint Transparent Mode:
  1. A network rule intercepts Codex Desktop and the processes it launches.
  2. The Endpoint classifies each flow as LLM, MCP, or HTTP.
  3. A request-stage allows LLM traffic and named MCP resources.
  4. Direct web search, spawned browsers, and other HTTP are blocked.
Developer browsers that Codex did not launch stay off this path. They do not have Codex in the process tree.

Prerequisites

  • Formal Endpoint on macOS with Transparent Mode enabled
  • Permission to create Network Rules, , and policies
  • An approved MCP server created as a Formal MCP resource

Create approved MCP resources

Named MCP resources are the allowlist. Unnamed MCP traffic is blocked. Create one Formal MCP resource per approved server. Use the MCP hostname and port.
  1. Navigate to Resources
  2. Click Create Resource
  3. Set Technology to MCP
  4. Enter the MCP hostname and port 443
  5. Save the resource
Replace mcp.example.com with your approved MCP hostname. Repeat for each allowed MCP server. LLM calls to ChatGPT are classified from the wire protocol. You do not need a ChatGPT for this policy.

Create the network rule

Intercept Codex Desktop and any child it spawns. Leave Forward to Connector unset so the Endpoint evaluates policy locally. The Codex Desktop app is signed with bundle ID com.openai.codex. Matching that ID on the connecting process or an ancestor covers spawned browsers and helper binaries.
  1. Navigate to Network Rules
  2. Create a rule named codex-desktop-egress
  3. Paste the CEL below
  4. Leave Forward to Connector unset
  5. Save the rule and set it to Active
process.has_agent_ancestor is true for Codex Desktop itself and for children of any known agent. Use it when you want this intercept for every coding agent, not only Codex Desktop.
Do not add forward_to_connector on this rule. LLM traffic is evaluated on the Endpoint. User browsers without Codex in the ancestor list skip the rule.

Create the policy

The policy blocks Codex Desktop requests that are not allowlisted. Allow LLM traffic, named MCP resources, and ChatGPT HTTP except built-in search. Codex Desktop still needs ChatGPT HTTP for auth and session setup. Those calls are not classified as LLM. The built-in search path stays blocked so Codex must use your MCP.
  1. Navigate to Policies
  2. Click Create Policy
  3. In Choose a Template, select Allow Codex Desktop LLM And MCP Only
  4. Click Create Policy to save
You can also paste this Rego if you skip the template:
Create the policy in Draft or Dry-run first. Set it to Active after you review matching logs. Desktop LLM sessions set input.agent.type from the User-Agent. The value is Codex Desktop. Spawned browsers inherit that session through the process tree. To allow another HTTP service, add a helper like chatgpt_http_not_search. Include that helper in the not conditions.

Verify

Confirm four outcomes after you activate the rule and policy. Allowed LLM traffic
  1. Send a normal Codex Desktop prompt that does not search the web.
  2. Open Logs.
  3. Confirm resource.technology:llm and Agent Codex Desktop.
  4. Confirm the request is allowed.
Allowed MCP traffic
  1. Ask Codex to search or fetch using your connected MCP server.
  2. Confirm resource.technology:mcp and a non-empty resource.name.
  3. Confirm the request is allowed.
Blocked built-in search
  1. Ask Codex to search the web without using your MCP server.
  2. Codex should receive a Formal block.
  3. Confirm a blocked log for /backend-api/codex/alpha/search.
Blocked child-process browsing
  1. Ask Codex to open an external or headless browser to an unapproved site.
  2. The request should fail with a Formal block.
  3. Confirm the HTTP log is attributed to Codex Desktop.
Unchanged developer browsing Open your own browser to the same site. That flow should not match the Codex rule. It should not show Agent as Codex Desktop.

Next Steps

Transparent Mode

Install and enable Formal Endpoint Transparent Mode on macOS

Network Rules

Select which Endpoint traffic Formal intercepts

MCP Resources

Proxy and govern approved MCP servers

LLM Resources

Inspect classified LLM traffic on the Endpoint

Agent Policy Inputs

Use input.agent in request-stage policies