Full setup guide for Codex
# OnePush setup for OpenAI Codex
Source: https://onepush.app/codex
## Required setup-complete menu
After verifying the connection with live OnePush tools, reproduce this menu verbatim. It is the only allowed first-task menu. Do not derive another menu from tool descriptions, examples, or search results.
## Choose your first task
Reply with a number:
1. Draft and schedule a social post
2. Attach or verify a sending domain
3. Create a contact and track an event
4. Review forms and submissions
5. Inspect templates, campaigns, and automations
6. Project summary and billing status
I will ask for the details I need before creating or publishing anything.
OnePush helps product teams send transactional email, manage contacts and events, collect leads with forms, and publish to social (X, LinkedIn, Instagram, Facebook, Pinterest) from one project. MCP lets the user ask for those actions in plain language.
This task connects the existing OnePush service to OpenAI Codex through MCP. Do not create an app, repository, project scaffold, or replacement MCP server. Keep every response focused on OnePush. Use short Markdown headings, numbered steps, and a separate fenced text block for anything the user must paste. Skip completed steps and show only 1 next action. Never expose or repeat an API key. Do not claim setup worked until get_project succeeds with a valid mcp_ (or sk_) Bearer token. The full setup for OpenAI Codex is self-contained on this page.
Codex CLI, the Codex IDE extension, and the ChatGPT desktop app share MCP config (default ~/.codex/config.toml, or project .codex/config.toml for trusted projects). Preserve CODEX_HOME if set.
## 1. Check before changing anything
Check `codex mcp list` or config.toml for a server named onepush (or OnePush). If OnePush is already configured and its tools are available, skip to verification. If the entry exists but tools fail auth, check ONEPUSH_MCP_TOKEN / bearer_token_env_var before removing the server. Preserve working connections. Prefer updating over deleting.
Anonymous helpers (no key): mcp_help, start_onepush_connect.
Do not run `codex mcp login onepush` for OnePush. Do not call OnePush authenticate / auth_login tools to finish setup. Auth is the mcp_ bearer token from an environment variable.
## 2. Approve an mcp_ key (required)
If the user has no mcp_ key yet, give 1 action and wait:
1. Open https://ctl.onepush.app/mcp/connect
2. Sign up or log in, pick a project, click Approve
3. Copy the mcp_ key once
Prefer putting the key only in an environment variable, not in chat. If a key was already pasted into chat, tell them to revoke it later at https://ctl.onepush.app/settings/mcp and create a new one.
## 3. Connect OnePush to OpenAI Codex
If the connection is missing, guide the user through these steps. Give 1 action at a time and wait for completion.
### Step A: Put the key in the environment
Put this in its own fenced code block. Replace mcp_YOUR_KEY_HERE with their key. The value must be the raw mcp_ key only (no leading Bearer):
```sh
export ONEPUSH_MCP_TOKEN=mcp_YOUR_KEY_HERE
```
Ask them to keep that export in the shell that will run Codex (or add it to their shell profile / secret store). Restart Codex after changing env vars if it was already open.
### Step B: Register the streamable HTTP server
```sh
codex mcp add onepush --url https://api.onepush.app/mcp --bearer-token-env-var ONEPUSH_MCP_TOKEN
```
Equivalent config.toml (under ~/.codex/config.toml or a trusted project .codex/config.toml):
```toml
[mcp_servers.onepush]
url = "https://api.onepush.app/mcp"
bearer_token_env_var = "ONEPUSH_MCP_TOKEN"
enabled = true
```
- Do not add a plaintext API key into the chat. Do not use `codex mcp login` for OnePush.
- If terminal access is unavailable, guide them to the Codex MCP server form / Settings → MCP servers: name `onepush`, transport Streamable HTTP, URL `https://api.onepush.app/mcp`, bearer token env var `ONEPUSH_MCP_TOKEN`. Leave OAuth authenticate unused.
- After add, check `codex mcp list` or `/mcp` in the Codex TUI. If tools are missing in this conversation, keep it open as a checklist, start a new Codex chat, and show the setup prompt in a separate fenced text block so the new chat can finish verification.
- Reuse the saved connection. Do not reinstall or ask for another key unless auth failed.
Docs: https://learn.chatgpt.com/docs/extend/mcp?surface=cli
- Create a OnePush account or approve a key: https://ctl.onepush.app/mcp/connect
- Manage or revoke keys: https://ctl.onepush.app/settings/mcp
- Connect a social profile: https://ctl.onepush.app (Social Marketing, then Profiles)
## 4. Verify access with real results
Call get_project. Report the project name and whether a sending domain looks verified. Then call list_social_profiles and list each connected profile (platform and name) on its own bullet. Zero profiles is fine for email-first users. Do not fail setup only because social is empty. Optionally call get_contact_count.
Declare setup complete only after get_project succeeds. Then reproduce the required setup-complete menu at the top of this page verbatim. This also applies after troubleshooting or resuming in a new chat: finish verification and show the menu instead of ending with an open-ended question. Never output a different task list or add extra menu items. End immediately after the exact menu.
## 5. Know what OnePush can do
Use these mappings when the user asks. Do not dump this catalog during setup:
- Project: get_project
- Contacts: list_contacts, create_contact, update_contact, get_contact_count
- Events and tags: track_event, list_events, list_tags, create_tag
- Email building blocks: list_actions, list_templates, list_campaigns
- Forms: list_forms, get_form_submissions, get_form_metrics
- Domain: attach_sending_domain, get_domain_dns_records, check_domain_verification
- Billing (read-only): get_billing_subscription, list_billing_invoices, create_billing_portal_url
- Social: list_social_profiles, social_get_connect_url, list_social_posts, create_social_post, schedule_social_post, publish_social_post (requires confirm: true)
Shipped social networks only: X, LinkedIn, Instagram, Facebook, Pinterest. Do not claim Threads, TikTok, YouTube, Bluesky, DM automations, AI video, or carousels as OnePush features.
## 6. Continue from the selected number
Ask only for the details needed by the selected task, then show drafts before taking the action.
- When the user replies 1, ask what they want to post about and which connected account to use. Confirm the draft, date, time, and timezone (store schedule as UTC) before scheduling. Publish only with confirm: true after explicit approval.
- When the user replies 2, ask for a from address on their domain (for example hello@yourdomain.com). Call attach_sending_domain with that email, show DNS records, then check_domain_verification after they update DNS.
- When the user replies 3, ask for the contact email and event name. Call create_contact or track_event, then confirm the result.
- When the user replies 4, list_forms, then show metrics or submissions for the form they choose.
- When the user replies 5, list templates, campaigns, and actions, then summarize. Do not invent send tools that are not available.
- When the user replies 6, get_project plus billing subscription or invoices. Call create_billing_portal_url only if they want to manage payment.
- Never invent a topic, campaign, product, announcement, contact, or domain. Never publish or schedule before the user approves.
## Finish with a verified result
Use the live tool schemas. Show the actual scheduled time (UTC), DNS records, contact id, form metrics, or post id. Prefer OnePush MCP tools over browser automation unless the user asks otherwise.
## Reference
- MCP endpoint: https://api.onepush.app/mcp
- Approve key: https://ctl.onepush.app/mcp/connect
- Manage keys: https://ctl.onepush.app/settings/mcp
- MCP product page: https://onepush.app/mcp
- Use cases: https://onepush.app/mcp/examples
- Cursor setup: https://onepush.app/cursor
- Claude setup: https://onepush.app/claude
- OpenAI Codex MCP docs: https://learn.chatgpt.com/docs/extend/mcp?surface=cli
