Connect Codex CLI to Guard.ch
Set up browser access once. Then ask Codex CLI to work in a browser or continue a session you already opened.
What you need
A Guard.ch account with MCP access enabled and an app key from that account. Your agent can access your own sessions.
Install Codex CLI and sign in. Use Bash or Zsh (macOS, Linux or WSL) for the commands below.
1. Create an app key
Open the Agents page in your dashboard and choose Create a key. Give it a name, such as your agent name. Copy the key before closing the window. It is only shown once.
Create a key2. Add Guard.ch to Codex CLI
Run both commands in the same terminal, replacing YOUR_API_KEY. The first supplies the key; the second registers Guard.ch.
export GUARDCH_API_KEY="YOUR_API_KEY"
codex mcp add guardch --url https://api.guard.ch/mcp \
--bearer-token-env-var GUARDCH_API_KEYSwap YOUR_API_KEY for your own key before you save this.
For JSON configuration: if you already use other MCP servers, only add the guardch entry inside mcpServers. Keep your other entries.
3. Check the connection
Start codex from that same terminal, then use /mcp to inspect the server. Send the task below. Supply GUARDCH_API_KEY again whenever you start from a new terminal.
Open example.com in a Guard.ch browser and tell me what the page says.The connection works when your agent opens a Guard.ch browser and returns the page content. Find the session under Agents in your dashboard to watch it live.
Continue an open session
In your Guard.ch viewer, choose Hand to an agent. Copy the prepared prompt into your connected agent chat. It includes the session ID so your agent continues in that exact browser. Use a key from the same account.
If something goes wrong
If authentication fails, the Codex process may not have GUARDCH_API_KEY in its environment. Export it in that terminal and start Codex again. Use codex mcp list to inspect the configuration.
For an authentication error, check that your app key is still valid. For an access error, check MCP access in your dashboard. Verify the connection in your agent; Guard.ch cannot automatically detect its configuration.
Your app key grants access to your sessions. Only add it to your agent settings, never to a chat or shared file. You can revoke it under Apps.