Overview
Codex Desktop can open a built-in or external browser for web search. Teams often want coding agents to use an approved MCP server instead. Formal can enforce that on macOS with Endpoint Transparent Mode:- A network rule intercepts Codex Desktop and the processes it launches.
- The Endpoint classifies each flow as LLM, MCP, or HTTP.
- A request-stage allows LLM traffic and named MCP resources.
- Direct web search, spawned browsers, and other HTTP are blocked.
Prerequisites
- Formal Endpoint on macOS with Transparent Mode enabled
- Permission to create Network Rules, , and policies
- An approved MCP server created as a Formal MCP resource
Create approved MCP resources
Named MCP resources are the allowlist. Unnamed MCP traffic is blocked. Create one Formal MCP resource per approved server. Use the MCP hostname and port.- Control Plane
- Terraform
- Navigate to Resources
- Click Create Resource
- Set Technology to MCP
- Enter the MCP hostname and port
443 - Save the resource
mcp.example.com with your approved MCP hostname. Repeat for each allowed MCP server.
LLM calls to ChatGPT are classified from the wire protocol. You do not need a ChatGPT for this policy.
Create the network rule
Intercept Codex Desktop and any child it spawns. Leave Forward to Connector unset so the Endpoint evaluates policy locally. The Codex Desktop app is signed with bundle IDcom.openai.codex. Matching that ID on the connecting process or an ancestor covers spawned browsers and helper binaries.
- Control Plane
- Terraform
- Navigate to Network Rules
- Create a rule named
codex-desktop-egress - Paste the CEL below
- Leave Forward to Connector unset
- Save the rule and set it to Active
process.has_agent_ancestor is true for Codex Desktop itself and for children of any known agent. Use it when you want this intercept for every coding agent, not only Codex Desktop.
Do not add
forward_to_connector on this rule. LLM traffic is evaluated on
the Endpoint. User browsers without Codex in the ancestor list skip the rule.Create the policy
The policy blocks Codex Desktop requests that are not allowlisted. Allow LLM traffic, named MCP resources, and ChatGPT HTTP except built-in search. Codex Desktop still needs ChatGPT HTTP for auth and session setup. Those calls are not classified as LLM. The built-in search path stays blocked so Codex must use your MCP.- Control Plane
- Terraform
- Navigate to Policies
- Click Create Policy
- In Choose a Template, select Allow Codex Desktop LLM And MCP Only
- Click Create Policy to save
input.agent.type from the User-Agent. The value is Codex Desktop. Spawned browsers inherit that session through the process tree.
To allow another HTTP service, add a helper like chatgpt_http_not_search. Include that helper in the not conditions.
Verify
Confirm four outcomes after you activate the rule and policy. Allowed LLM traffic- Send a normal Codex Desktop prompt that does not search the web.
- Open Logs.
- Confirm
resource.technology:llmand Agent Codex Desktop. - Confirm the request is allowed.
- Ask Codex to search or fetch using your connected MCP server.
- Confirm
resource.technology:mcpand a non-emptyresource.name. - Confirm the request is allowed.
- Ask Codex to search the web without using your MCP server.
- Codex should receive a Formal block.
- Confirm a blocked log for
/backend-api/codex/alpha/search.
- Ask Codex to open an external or headless browser to an unapproved site.
- The request should fail with a Formal block.
- Confirm the HTTP log is attributed to Codex Desktop.
Next Steps
Transparent Mode
Install and enable Formal Endpoint Transparent Mode on macOS
Network Rules
Select which Endpoint traffic Formal intercepts
MCP Resources
Proxy and govern approved MCP servers
LLM Resources
Inspect classified LLM traffic on the Endpoint
Agent Policy Inputs
Use
input.agent in request-stage policies