Codex model-visible tool exposure rules (spec_plan.rs namespace_tools capability
Parent: Mac local LLMs: Agent clients, context and compaction · Published reference · snapshot 2026-10-05
↓ Facts as markdownall context files
A reporter on LiteLLM says `supports_search_tool: false` did not expose MCP tools. Main code says it would make them direct at the Codex side; the remaining cause would sit on the wire (namespace serialization), not in the spec plan.
These notes link each claim to its source. A source may be a research report hosted on this site rather than the primary document. A published reference means the content is available; it does not certify independent review or accuracy.Read the editorial policy and follow the sources before relying on a claim.
Facts
- A reporter on LiteLLM says `supports_search_tool: false` did not expose MCP tools. Main code says it would make them direct at the Codex side; the remaining cause would sit on the wire (namespace serialization), not in the spec plan. [source]
- `https://raw.githubusercontent.com/openai/codex/main/codex-rs/core/src/tools/mcp_tool_exposure.rs` returns 404 on main; the MCP exposure policy is `apply_mcp_tool_exposure_policy` inside `spec_plan.rs`. [source]
- `ToolExposure` has the variants Hidden, CodeModeOnly, DirectModelOnly, Direct, DeferredModelOnly and Deferred, derived from a (direct, deferred, code-mode) boolean triple. [source]
- `build_model_visible_specs` skips every tool whose exposure is not direct, skips tools hidden by code-mode-only, appends hosted specs, then merges tools into namespaces. [source]
- With `supports_search_tool` true and deferral allowed, an MCP tool loses its direct exposure and is reachable only through `tool_search` or code-mode `exec`. [source]
- When `supports_search_tool` is false, deferred exposure is removed, so an MCP tool stays direct unless omitted. [source]
- A per-server `omit_tools_from` list (and a per-connector one for the codex-apps server) removes named exposures from that server's tools. [source]
- `code_mode.direct_only_tool_namespaces` strips deferred and code-mode exposure from the named namespaces, and `apply_direct_model_only_namespace_overrides` later forces those tools to DirectModelOnly. [source]
- The feature `CodeModeOnlyStrictThirdPartyTools` with tool mode CodeModeOnly ignores `omit_tools_from` for deferred and code-mode exposures and forces eligible third-party tools to Deferred, logging a warning. [source]
- `effective_tool_mode` lets the model override the thread's configured tool mode. [source]
- `finalize_tool_router` removes any registered tool named `tool_search` and any namespace tool with that name before appending its own `tool_search` executor, and records each removal as a collision. [source]
- If the `error_on_tool_collisions` config is set, the first recorded tool collision fails the router build with `ToolCollision`. [source]
- `hosted_model_tool_specs` returns nothing for `use_responses_lite` models and emits a hosted web-search spec only when `provider.capabilities().web_search` is true and no standalone `web.run` extension tool exists. [source]
- Image generation requires `provider.capabilities().image_generation`, an image input modality on the model, and OpenAI actor authorization or OpenAI auth. [source]
- The v1 `spawn_agent` tool is registered Deferred when `supports_search_tool` is true and Direct otherwise. [source]
Corrections and disagreements
- CONTRADICTS: codex-tool-search-deferred-mcp-tools-and-the-sup.md (line 10, `search_tool_enabled` computed in spec_plan.rs as `supports_search_tool && provider.capabilities().namespace_tools`): on main fetched 2026-10-05 `spec_plan.rs` contains no `namespace_tools` and gates MCP deferral on `model_info.supports_search_tool` alone. [source]
Children
- No children recorded.