Codex 0.133.0 makes goals default and expands permissions

Codex 0.133.0, released May 21, makes Goals enabled by default, adds a dedicated goal store, and changes remote-control behavior to run like a foreground command. The release also expands permission profiles, plugin discovery, and extension hooks, while fixing several app-server, TUI, and runtime issues.

Codex 0.133.0 makes goals default and expands permissions

Codex version 0.133.0 was released on May 21, according to the project changelog. The update adds several major product changes, including Goals being enabled by default, a reworked remote-control command flow, broader permission profile support, and more extension events for plugins and automations.

The release notes say Goals are now backed by dedicated storage and can track progress across active turns. In other words, Codex now treats goals as a first-class feature rather than an optional experiment, and the system can retain goal state separately from other session data.

⚡ New to this?

This is a software release note for Codex, the AI coding tool. The biggest changes are that Goals are no longer experimental and permission profiles now have more control and structure.

A permission profile is a preset that defines what the tool can access or do. Extensions are add-ons that can react to events like a subagent starting, a tool being used, or a turn finishing.

🦞 OpenClaw angle

If you run Codex or a similar self-hosted agent, treat this release as a signal to separate goals, permissions, and extensions more cleanly in your own system. Store goal state independently from session data, and make permission profiles reloadable at runtime so you do not have to restart agents for policy changes.

If you build plugins or hooks, update them to handle lifecycle events such as subagent start/stop and tool execution. Also review any code that depends on remote-control or app-server startup behavior, because this release changes foreground command handling, daemon commands, and websocket compatibility.

Remote-control also changed in this release. According to the changelog, the codex remote-control command now runs like a foreground command, waits for readiness, reports machine status, and uses explicit daemon-style start and stop commands.

Permission handling got a substantial update as well. The project says permission profiles now have list APIs, inheritance, managed requirements.toml support, runtime refresh behavior, and stronger Windows sandbox integration. The release notes also mention support for managed permission profiles in requirements.toml, along with a new permission profile picker metadata API and updates to how Windows runner permissions are passed through.

Plugin discovery was expanded to make inspection easier. According to the changelog, list output now reflects marketplace-aware discovery, installed versions, visible marketplace roots, and remote collection support. The release also includes clearer guidance for plugin creators updating and reinstalling local personal plugins.

Extensions gained more visibility into Codex’s lifecycle. The changelog says extensions can now observe subagent start and stop events, tool execution, turn metadata, and async approval or turn processing. Other changes include a turn_id and truncation_policy for extension tool calls, plus support for compact SessionStart hooks.

The release also includes several bug fixes. The project says it fixed TUI startup choosing the wrong working directory when reusing a local app-server socket, plan-mode free-form answers submitting unexpectedly when modified Enter keys were used, stale terminal poll events after a process exits, and more reliable AGENTS instruction loading. Codex also now preserves raw code-mode exec output unless a token limit is explicitly requested.

App-server stability received attention too. According to the notes, fixes landed for startup and shutdown races, empty resume and fork paths, plugin upgrade failures, and realtime v1 websocket compatibility. Documentation updates in this release expand app-server and API coverage around managed permission profile requirements.

On the packaging side, the project introduced a canonical Codex package archive pipeline and moved installers, npm packages, DotSlash, and SDK runtimes toward a shared layout. The release notes also mention Linux runtime wheel tag fixes for glibc-based systems, improved release and CI reliability, and packaging changes for prebuilt resources and package archives.

Overall, 0.133.0 is a broad release that pushes Codex toward a more structured goal system, tighter permission management, and better support for plugins and extensions, while also cleaning up several startup and packaging issues.

Source: Codex Releases ↗

More from OpenClaw News