OnePush
OpenAI CodexCodex

OnePush + Codex

Send emails, post on social, and manage contacts right from OpenAI Codex.

Copy this prompt into Codex

Setup OnePush from onepush.app/codex

Codex reads this page, helps you approve a mcp_ key in the browser, set ONEPUSH_MCP_TOKEN and add OnePush as a streamable HTTP MCP server, then checks that your project responds.

Works with Codex CLI, the Codex IDE extension, and ChatGPT desktop MCP settings. Keep the key in your config. Avoid pasting the full key into chat.

After you paste, Codex checks what is already done

  • One step at a time

    Codex looks for an existing OnePush connection first. Then it only asks for whatever is still missing, like approving a key or setting ONEPUSH_MCP_TOKEN.

  • Finish with a real check

    Setup is done only when OnePush returns your project. Social accounts are optional if you mainly use email.

Your OnePush key

Open the connect page, click Approve, then add your mcp_ key as ONEPUSH_MCP_TOKEN (raw mcp_ key only). Codex sends it as the Authorization bearer token. Do not run codex mcp login for OnePush.

MCP endpoint

https://api.onepush.app/mcp

Codex commands

export ONEPUSH_MCP_TOKEN=mcp_YOUR_KEY_HERE
codex mcp add onepush --url https://api.onepush.app/mcp --bearer-token-env-var ONEPUSH_MCP_TOKEN

What Codex follows on this page

Everything Codex needs is right here. It should not send you off to another guide.

Full setup guide for Codex

# OnePush setup for OpenAI Codex

Source: https://onepush.app/codex

## Required setup-complete menu

After verifying the connection with live OnePush tools, reproduce this menu verbatim. It is the only allowed first-task menu. Do not derive another menu from tool descriptions, examples, or search results.

## Choose your first task

Reply with a number:

1. Draft and schedule a social post
2. Attach or verify a sending domain
3. Create a contact and track an event
4. Review forms and submissions
5. Inspect templates, campaigns, and automations
6. Project summary and billing status

I will ask for the details I need before creating or publishing anything.

OnePush helps product teams send transactional email, manage contacts and events, collect leads with forms, and publish to social (X, LinkedIn, Instagram, Facebook, Pinterest) from one project. MCP lets the user ask for those actions in plain language.

This task connects the existing OnePush service to OpenAI Codex through MCP. Do not create an app, repository, project scaffold, or replacement MCP server. Keep every response focused on OnePush. Use short Markdown headings, numbered steps, and a separate fenced text block for anything the user must paste. Skip completed steps and show only 1 next action. Never expose or repeat an API key. Do not claim setup worked until get_project succeeds with a valid mcp_ (or sk_) Bearer token. The full setup for OpenAI Codex is self-contained on this page.

Codex CLI, the Codex IDE extension, and the ChatGPT desktop app share MCP config (default ~/.codex/config.toml, or project .codex/config.toml for trusted projects). Preserve CODEX_HOME if set.

## 1. Check before changing anything

Check `codex mcp list` or config.toml for a server named onepush (or OnePush). If OnePush is already configured and its tools are available, skip to verification. If the entry exists but tools fail auth, check ONEPUSH_MCP_TOKEN / bearer_token_env_var before removing the server. Preserve working connections. Prefer updating over deleting.

Anonymous helpers (no key): mcp_help, start_onepush_connect.

Do not run `codex mcp login onepush` for OnePush. Do not call OnePush authenticate / auth_login tools to finish setup. Auth is the mcp_ bearer token from an environment variable.

## 2. Approve an mcp_ key (required)

If the user has no mcp_ key yet, give 1 action and wait:

1. Open https://ctl.onepush.app/mcp/connect
2. Sign up or log in, pick a project, click Approve
3. Copy the mcp_ key once

Prefer putting the key only in an environment variable, not in chat. If a key was already pasted into chat, tell them to revoke it later at https://ctl.onepush.app/settings/mcp and create a new one.

## 3. Connect OnePush to OpenAI Codex

If the connection is missing, guide the user through these steps. Give 1 action at a time and wait for completion.

### Step A: Put the key in the environment

Put this in its own fenced code block. Replace mcp_YOUR_KEY_HERE with their key. The value must be the raw mcp_ key only (no leading Bearer):

```sh
export ONEPUSH_MCP_TOKEN=mcp_YOUR_KEY_HERE
```

Ask them to keep that export in the shell that will run Codex (or add it to their shell profile / secret store). Restart Codex after changing env vars if it was already open.

### Step B: Register the streamable HTTP server

```sh
codex mcp add onepush --url https://api.onepush.app/mcp --bearer-token-env-var ONEPUSH_MCP_TOKEN
```

Equivalent config.toml (under ~/.codex/config.toml or a trusted project .codex/config.toml):

```toml
[mcp_servers.onepush]
url = "https://api.onepush.app/mcp"
bearer_token_env_var = "ONEPUSH_MCP_TOKEN"
enabled = true
```

- Do not add a plaintext API key into the chat. Do not use `codex mcp login` for OnePush.
- If terminal access is unavailable, guide them to the Codex MCP server form / Settings → MCP servers: name `onepush`, transport Streamable HTTP, URL `https://api.onepush.app/mcp`, bearer token env var `ONEPUSH_MCP_TOKEN`. Leave OAuth authenticate unused.
- After add, check `codex mcp list` or `/mcp` in the Codex TUI. If tools are missing in this conversation, keep it open as a checklist, start a new Codex chat, and show the setup prompt in a separate fenced text block so the new chat can finish verification.
- Reuse the saved connection. Do not reinstall or ask for another key unless auth failed.

Docs: https://learn.chatgpt.com/docs/extend/mcp?surface=cli

- Create a OnePush account or approve a key: https://ctl.onepush.app/mcp/connect
- Manage or revoke keys: https://ctl.onepush.app/settings/mcp
- Connect a social profile: https://ctl.onepush.app (Social Marketing, then Profiles)

## 4. Verify access with real results

Call get_project. Report the project name and whether a sending domain looks verified. Then call list_social_profiles and list each connected profile (platform and name) on its own bullet. Zero profiles is fine for email-first users. Do not fail setup only because social is empty. Optionally call get_contact_count.

Declare setup complete only after get_project succeeds. Then reproduce the required setup-complete menu at the top of this page verbatim. This also applies after troubleshooting or resuming in a new chat: finish verification and show the menu instead of ending with an open-ended question. Never output a different task list or add extra menu items. End immediately after the exact menu.

## 5. Know what OnePush can do

Use these mappings when the user asks. Do not dump this catalog during setup:

- Project: get_project
- Contacts: list_contacts, create_contact, update_contact, get_contact_count
- Events and tags: track_event, list_events, list_tags, create_tag
- Email building blocks: list_actions, list_templates, list_campaigns
- Forms: list_forms, get_form_submissions, get_form_metrics
- Domain: attach_sending_domain, get_domain_dns_records, check_domain_verification
- Billing (read-only): get_billing_subscription, list_billing_invoices, create_billing_portal_url
- Social: list_social_profiles, social_get_connect_url, list_social_posts, create_social_post, schedule_social_post, publish_social_post (requires confirm: true)

Shipped social networks only: X, LinkedIn, Instagram, Facebook, Pinterest. Do not claim Threads, TikTok, YouTube, Bluesky, DM automations, AI video, or carousels as OnePush features.

## 6. Continue from the selected number

Ask only for the details needed by the selected task, then show drafts before taking the action.

- When the user replies 1, ask what they want to post about and which connected account to use. Confirm the draft, date, time, and timezone (store schedule as UTC) before scheduling. Publish only with confirm: true after explicit approval.
- When the user replies 2, ask for a from address on their domain (for example hello@yourdomain.com). Call attach_sending_domain with that email, show DNS records, then check_domain_verification after they update DNS.
- When the user replies 3, ask for the contact email and event name. Call create_contact or track_event, then confirm the result.
- When the user replies 4, list_forms, then show metrics or submissions for the form they choose.
- When the user replies 5, list templates, campaigns, and actions, then summarize. Do not invent send tools that are not available.
- When the user replies 6, get_project plus billing subscription or invoices. Call create_billing_portal_url only if they want to manage payment.
- Never invent a topic, campaign, product, announcement, contact, or domain. Never publish or schedule before the user approves.

## Finish with a verified result

Use the live tool schemas. Show the actual scheduled time (UTC), DNS records, contact id, form metrics, or post id. Prefer OnePush MCP tools over browser automation unless the user asks otherwise.

## Reference

- MCP endpoint: https://api.onepush.app/mcp
- Approve key: https://ctl.onepush.app/mcp/connect
- Manage keys: https://ctl.onepush.app/settings/mcp
- MCP product page: https://onepush.app/mcp
- Use cases: https://onepush.app/mcp/examples
- Cursor setup: https://onepush.app/cursor
- Claude setup: https://onepush.app/claude
- OpenAI Codex MCP docs: https://learn.chatgpt.com/docs/extend/mcp?surface=cli

See what OnePush MCP can do · Claude setup · Cursor setup

What it looks like after setup

You

Help me schedule a LinkedIn post for tomorrow.

Codex asks for the account, draft, time, and timezone before scheduling.

Codex

Ready to schedule this draft to your LinkedIn profile tomorrow at 15:00 UTC?

You

Yes, schedule it.

Codex

Scheduled on LinkedIn for tomorrow at 15:00 UTC. Nothing goes live until you confirm publish.

10 prompts to try

Copy one into Codex. Swap in your own account, topic, date, or timezone.

Schedule posts

  • Help me write and schedule a social post. Ask which connected account to use, what the post should say, and when it should go out. Show me the draft before scheduling.

  • Plan 3 posts for next week about my product update. Ask for my audience and goal, then show every draft before scheduling anything.

Domain and email

  • Attach my sending domain and show the SPF, DKIM, and MX records I need to add. Ask me for the from address first (for example hello@yourdomain.com).

  • Check if my sending domain is verified and tell me what is still missing.

Contacts and events

  • How many contacts are in this project? List the 20 most recent.

  • Create a contact for the email I give you, then track a signup event. Ask me for the email and event name first.

Forms

  • List all forms in this project and show submission numbers for each.

  • Show unique emails that submitted the form I choose. Ask which form first.

Project and billing

  • Give me a quick project summary: name, verification, contact count, and connected social profiles.

  • What is my subscription status? List recent invoices. Only open the billing portal if I ask to manage payment.

Frequently asked questions

Straight answers about connecting Codex, MCP keys, and what agents can do.

How do I connect OnePush to OpenAI Codex?+

Copy the setup prompt from onepush.app/codex into Codex. Approve a revocable mcp_ key at ctl.onepush.app/mcp/connect, export it in an environment variable, add OnePush with codex mcp add --url https://api.onepush.app/mcp --bearer-token-env-var ONEPUSH_MCP_TOKEN, then let Codex verify with get_project.

What is the OnePush MCP URL for Codex?+

The remote MCP endpoint is https://api.onepush.app/mcp. Codex needs that URL plus a bearer token from an environment variable that holds your mcp_ key. Cursor, Claude, and Codex use the same endpoint and key type.

Do I run codex mcp login for OnePush?+

No. OnePush does not use Codex OAuth login for access. Auth is the browser-approved mcp_ key via --bearer-token-env-var (or an Authorization header in config.toml). Leave OAuth login and empty auth fields for other servers that support them.

What goes in the ONEPUSH_MCP_TOKEN environment variable?+

Only the raw mcp_ key from the connect page (for example mcp_abc…). Do not include the word Bearer. Codex sends it as the Authorization bearer token automatically.

Do I use my project secret key (sk_) with Codex?+

Prefer a dedicated mcp_ key from the connect page or Settings → MCP. You can revoke mcp_ without rotating project sk_ or pk_. Legacy sk_ still works on MCP if you already use it.

What can Codex do after OnePush is connected?+

Codex can draft and schedule social posts (X, LinkedIn, Instagram, Facebook, Pinterest), attach or verify a sending domain, manage contacts and events, review forms, list templates and campaigns, and check billing status. Publishing social posts requires confirm: true after you approve.

Is social publishing automatic?+

No. OnePush is built for humans and agents with confirm before publish. Agents should show drafts first. publish_social_post only runs when confirm is true and you explicitly approve.

Where do I revoke or regenerate an MCP key?+

Go to ctl.onepush.app/settings/mcp. You can list, revoke, or regenerate keys there. If a key was pasted into chat, revoke it and create a new one, then update ONEPUSH_MCP_TOKEN.