Using Wirecheck with Codex

There is no native Wirecheck integration for Codex; this is the CLI/JSON workflow, wired in through Codex's own AGENTS.md convention. The loop is identical to the Claude Code workflow: Codex checks Wirecheck before a change, makes the change, then checks again.

Add this to your repository's AGENTS.md

AGENTS.md
## Before changing AI/integration dependencies

This repository is tracked by Wirecheck. Before modifying or removing an
existing credential, MCP server, webhook, scheduled job, external API
integration, or agent/model integration:

1. Run `wirecheck preflight <name> --json` against the target.
2. Read `direct_dependants`, `indirect_dependants`, and
   `unknown_relationships`. Zero known dependants with one or more unknown
   relationships is NOT confirmed safe to remove; say so explicitly rather
   than proceeding as if it were.
3. Inspect `evidence` (or run `wirecheck evidence <name> --json`) before
   claiming to understand why the dependency exists.
4. Make the requested change.
5. Report the known and unknown dependants found, and whether any still
   need updating, before considering the task complete.
6. After a merge and rescan, run `wirecheck verify retirement <name> --json`
   and report its `status` rather than asserting the removal succeeded.

In CI

If Codex runs in a non-interactive CI environment, set WIRECHECK_TOKEN as a secret instead of an interactive auth login: it is read from the environment and never written to disk or logged.

WIRECHECK_TOKEN=*** wirecheck preflight stripe-mcp --json

For the full command reference (preflight, context, evidence, compare, verify retirement), see the CLI reference.