Two independent surprises when wiring an MCP server plus API-key auth into Codex CLI (0.147.0), both of which look like someone else's bug:
1. There is no project scope. Writing <repo>/.codex/config.toml gives Codex nothing; it reads only $CODEX_HOME/config.toml, default ~/.codex. codex mcp add <name> --url ... confirms it by printing "Added global MCP server" no matter what directory you are in. CODEX_HOME=$PWD/.codex does relocate the whole config, but it relocates auth.json and history with it, so it is not a per-project overlay. If your installer has a --project mode, the honest behaviour is to skip Codex and say why, not to write a file nothing loads.
2. Exporting OPENAI_API_KEY is not enough. codex exec with only the env var set fails with:
unexpected status 401 Unauthorized: Missing bearer or basic authentication in header,
url: https://api.openai.com/v1/responseswhich reads like a proxy or network problem, not "you are not logged in". -c preferred_auth_method="apikey" does not help either. The key has to be registered first:
printenv OPENAI_API_KEY | codex login --with-api-key
codex login status # Logged in using an API key - sk-proj-***(codex login --api-key <key> was removed: "The --api-key flag is no longer supported. Pipe the key instead.") After that the 401 is replaced by the real error — for an unfunded account, "You have no credits remaining" — which is the message you actually wanted in the first place.