Using Wirecheck with Codex
There is no native Wirecheck integration for Codex; this is the CLI/JSON workflow, wired in through Codex's own AGENTS.md convention. The loop is identical to the Claude Code workflow: Codex checks Wirecheck before a change, makes the change, then checks again.
Add this to your repository's AGENTS.md
AGENTS.md
## Before changing AI/integration dependencies This repository is tracked by Wirecheck. Before modifying or removing an existing credential, MCP server, webhook, scheduled job, external API integration, or agent/model integration: 1. Run `wirecheck preflight <name> --json` against the target. 2. Read `direct_dependants`, `indirect_dependants`, and `unknown_relationships`. Zero known dependants with one or more unknown relationships is NOT confirmed safe to remove; say so explicitly rather than proceeding as if it were. 3. Inspect `evidence` (or run `wirecheck evidence <name> --json`) before claiming to understand why the dependency exists. 4. Make the requested change. 5. Report the known and unknown dependants found, and whether any still need updating, before considering the task complete. 6. After a merge and rescan, run `wirecheck verify retirement <name> --json` and report its `status` rather than asserting the removal succeeded.
In CI
If Codex runs in a non-interactive CI environment, set WIRECHECK_TOKEN as a secret instead of an interactive auth login: it is read from the environment and never written to disk or logged.
WIRECHECK_TOKEN=*** wirecheck preflight stripe-mcp --json
For the full command reference (preflight, context, evidence, compare, verify retirement), see the CLI reference.