Codex CLI 0.161.0 makes GPT-6.1 Sol the default and lets you pick a cyber access program per turn
This release changes the default model and smooths permissions and MCP sign-in, worth a look before upgrading.
// Key points
- GPT-6.1 Sol is the default in the bundled and Amazon Bedrock catalogs; Bedrock supports multi-agent V2 and Ultra reasoning on compatible models.
- You can choose a cyber access program per turn with codex exec --cyber-access-program or the TypeScript SDK's cyberAccessProgram option.
- You can sign in to MCP servers from an active terminal session with /mcp login <name>.
- Fixes: approved filesystem escalation still honors denied reads and network restrictions, background tasks keep their originating turn's permissions, and retries and WebSocket-to-HTTP fallback follow server retry guidance.
Builder's takeWhen the default model changes, the same scripts change in cost and output style. If you run codex exec in CI, I'd pin the model explicitly and switch only after comparing Sol's results and bill on non-critical jobs.
// Background · from #Coding agents
Full timeline →- Oct 9 GitHub Copilot CLI 1.0.94-0 discovers local Ollama models in /model and switches to them in-session
- Oct 8 Local sandboxing for GitHub Copilot is generally available, restricting agent commands’ file, network and credential access with enforceable enterprise policies
- Oct 8 GitHub ships a purpose-built model for leaked secrets that reads surrounding code to catch unformatted passwords, coming to push protection and Copilot /security-review