Nexara Connect docs0.1.0

Codex CLI

Before you start

Configure

Add to ~/.codex/config.toml:

[mcp_servers.nexara]
url = "https://dev.nexara.ac/mcp"
bearer_token_env_var = "NEXARA_KEY"

and export the key in your shell profile:

export NEXARA_KEY="nxc_..."

Codex reads the bearer token from the environment at start-up. To expose only the read tools, add:

enabled_tools = ["context_bundle", "context_search", "context_get", "context_tree", "context_related", "context_whoami"]

Verify

Ask the agent to call context_whoami. It returns the agent name, workspace and grants. Or run:

curl -s https://dev.nexara.ac/mcp \
  -H "Authorization: Bearer $NEXARA_KEY" \
  -H "Content-Type: application/json" \
  -H "Accept: application/json, text/event-stream" \
  -d '{"jsonrpc":"2.0","id":1,"method":"tools/call","params":{"name":"context_whoami","arguments":{}}}'

Troubleshooting

SymptomCause
401 invalid, expired or revoked tokenWrong key, key revoked, or a workspace lockdown bumped the token epoch. Mint a new key
401 git tokens (nxg_) are not accepted on /mcpYou pasted a git token. Use an nxc_ agent key
403 forbidden host or originThe server has ALLOWED_HOSTS set and your Host header is not in it
Tool result forbidden: ...The agent's grant does not cover that Space, action or sensitivity. Widen it on the agent page
Tool result step_up_requiredThe change needs a human with step-up; it was turned into a proposal
Generated from connect/codex.md by docs/site/build.mjs. Edit the Markdown, then rebuild.