<!-- llms-explorer concept facts · https://llms-explorer.com/tree/codex-model-visible-tool-exposure-rules-spec-pla/ · pack 2026-10-05 · ~1252 tokens -->

# Codex model-visible tool exposure rules (spec_plan.rs namespace_tools capability

> A reporter on LiteLLM says `supports_search_tool: false` did not expose MCP tools. Main code says it would make them direct at the Codex side; the remaining cause would sit on the wire (namespace serialization), not in the spec plan.

Parent: [Mac local LLMs: Agent clients, context and compaction](https://llms-explorer.com/tree/mac-local-llms-agent-clients-context-and-compaction/) · 2 facets · 16 facts · page: https://llms-explorer.com/tree/codex-model-visible-tool-exposure-rules-spec-pla/

## Facts

- A reporter on LiteLLM says `supports_search_tool: false` did not expose MCP tools. Main code says it would make them direct at the Codex side; the remaining cause would sit on the wire (namespace serialization), not in the spec plan. — source: `asserted`
- `https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/mcp_tool_exposure.rs` returns 404 on main; the MCP exposure policy is `apply_mcp_tool_exposure_policy` inside `spec_plan.rs`. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- `ToolExposure` has the variants Hidden, CodeModeOnly, DirectModelOnly, Direct, DeferredModelOnly and Deferred, derived from a (direct, deferred, code-mode) boolean triple. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- `build_model_visible_specs` skips every tool whose exposure is not direct, skips tools hidden by code-mode-only, appends hosted specs, then merges tools into namespaces. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- With `supports_search_tool` true and deferral allowed, an MCP tool loses its direct exposure and is reachable only through `tool_search` or code-mode `exec`. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- When `supports_search_tool` is false, deferred exposure is removed, so an MCP tool stays direct unless omitted. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- A per-server `omit_tools_from` list (and a per-connector one for the codex-apps server) removes named exposures from that server's tools. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- `code_mode.direct_only_tool_namespaces` strips deferred and code-mode exposure from the named namespaces, and `apply_direct_model_only_namespace_overrides` later forces those tools to DirectModelOnly. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- The feature `CodeModeOnlyStrictThirdPartyTools` with tool mode CodeModeOnly ignores `omit_tools_from` for deferred and code-mode exposures and forces eligible third-party tools to Deferred, logging a warning. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- `effective_tool_mode` lets the model override the thread's configured tool mode. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- `finalize_tool_router` removes any registered tool named `tool_search` and any namespace tool with that name before appending its own `tool_search` executor, and records each removal as a collision. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- If the `error_on_tool_collisions` config is set, the first recorded tool collision fails the router build with `ToolCollision`. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- `hosted_model_tool_specs` returns nothing for `use_responses_lite` models and emits a hosted web-search spec only when `provider.capabilities().web_search` is true and no standalone `web.run` extension tool exists. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- Image generation requires `provider.capabilities().image_generation`, an image input modality on the model, and OpenAI actor authorization or OpenAI auth. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
- The v1 `spawn_agent` tool is registered Deferred when `supports_search_tool` is true and Direct otherwise. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)

## Corrections and disagreements

- CONTRADICTS: codex-tool-search-deferred-mcp-tools-and-the-sup.md (line 10, `search_tool_enabled` computed in spec_plan.rs as `supports_search_tool && provider.capabilities().namespace_tools`): on main fetched 2026-10-05 `spec_plan.rs` contains no `namespace_tools` and gates MCP deferral on `model_info.supports_search_tool` alone. — [source](https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/spec_plan.rs)
