Set Up the Bridge
Bootstrap and plan
- Treat a plain invocation as
action=all target=peer scope=auto live=prompt.
- The loaded Claude plugin, Claude trust, Claude authentication, and current session are external bootstrap prerequisites. Never try to replace or restart the current invocation surface.
- Reject a model-supplied workspace; use Claude's launch workspace.
- Run
python --version first and stop if it is unavailable or older than Python 3.10.
- Parse only the documented
key=value grammar plus the one-release compatibility forms --live and --direction codex|claude; reject ambiguous or unknown arguments.
For one resolved target, invoke:
python "${CLAUDE_PLUGIN_ROOT}/bin/bridge_setup.py" --current-host claude --workspace "<launch-workspace>" --action "<action>" --target "<target>" --scope "<scope>" --live "<live>"
The deterministic planner performs credential-free inspection and returns the setup result JSON defined by schemas/setup-result.schema.json.
Check and approved changes
For check, report the result and stop. For all, configure, or repair:
- Show every planned
operations entry and the approval digest before any mutation.
- Obtain explicit approval for exactly that digest. State:
- action and purpose;
- exact native argv and resolved target/scope;
- external capability;
- credential behavior;
- filesystem and host-configuration effects;
- rollback evidence;
- retry policy; and
- safe denial outcome.
- After approval, rerun the identical command with
--approve "<approval_digest>".
The host-held HMAC makes the digest tamper-evident but does not grant consent; explicit operator or host approval remains required. The digest is action-bound, expires, and is consumed by its first execution attempt. Never substitute --approve without its digest. A denial, changed or expired digest, replay, unsupported capability, failed probe, or failed native operation stops without retry.
Authentication
When authentication remains:
- Re-plan the provider-owned interactive login with the identical host, workspace, target, scope, and live values but
--action authenticate.
- Obtain separate approval for that action's digest and state that the exact
authentication_argv may open a browser and use network and account state.
- Give the operator the identical authenticate command plus
--approve "<authentication_digest>" to run in their own terminal.
This is the sensitive phase: never run it through model-controlled Bash or another captured tool stream. Bridge then launches only the native login command with that terminal inherited. Never accept, request, pipe, echo, inspect, or store a token, API key, browser code, device code, email, or raw login output. Process exit means auth-flow-launched; only a later redacted status probe may establish host-authenticated.
Live verification
When live=prompt or live=required reaches inference-unverified:
- Re-plan with the identical host, workspace, target, and scope but
--action verify-live.
- Obtain a third approval for that action's digest and one paid provider call.
- State network, installed-CLI-managed credential, quota/cost, workspace, and point-in-time semantics.
- Rerun that same verify-live command with
--approve "<live_digest>".
Never invoke the lower-level live doctor outside this approval path. A successful live CLI result remains partial until applicable loaded-session/workspace evidence is also present. live=skip remains inference-unverified; never call it ready. Denial under live=required is non-ready.
Completion boundary
- Setup always owns one resolved peer target.
- To prepare both integrations, finish the peer lifecycle from Claude, start any required fresh session, then run
$bridge:setup from Codex for its peer; no digest, state claim, or readiness result is shared between hosts.
- The loaded-host branch is check/bootstrap-only and never mutates its current invocation surface.
bridge_status evidence belongs to a fresh Codex session and is required before claiming that reverse MCP session/workspace ready.
- Report the strongest verified level, exact remaining action, confidence, and limits.
Never equate static readiness, process exit, host authentication, session readiness, workspace readiness, or live verification.
1---2name: setup-63description: Configure, authenticate, repair, and verify the Claude Code to Codex Bridge; safe stages run by default and sensitive stages require separate approval.4---56# Set Up the Bridge78## Bootstrap and plan910- Treat a plain invocation as `action=all target=peer scope=auto live=prompt`.11- The loaded Claude plugin, Claude trust, Claude authentication, and current session are external bootstrap prerequisites. Never try to replace or restart the current invocation surface.12- Reject a model-supplied workspace; use Claude's launch workspace.13- Run `python --version` first and stop if it is unavailable or older than Python 3.10.14- Parse only the documented `key=value` grammar plus the one-release compatibility forms `--live` and `--direction codex|claude`; reject ambiguous or unknown arguments.1516For one resolved target, invoke:1718```bash19python "${CLAUDE_PLUGIN_ROOT}/bin/bridge_setup.py" --current-host claude --workspace "<launch-workspace>" --action "<action>" --target "<target>" --scope "<scope>" --live "<live>"20```2122The deterministic planner performs credential-free inspection and returns the setup result JSON defined by `schemas/setup-result.schema.json`.2324## Check and approved changes2526For `check`, report the result and stop. For `all`, `configure`, or `repair`:27281. Show every planned `operations` entry and the approval digest before any mutation.292. Obtain explicit approval for exactly that digest. State:30 - action and purpose;31 - exact native argv and resolved target/scope;32 - external capability;33 - credential behavior;34 - filesystem and host-configuration effects;35 - rollback evidence;36 - retry policy; and37 - safe denial outcome.383. After approval, rerun the identical command with `--approve "<approval_digest>"`.3940> The host-held HMAC makes the digest tamper-evident but does not grant consent; explicit operator or host approval remains required. The digest is action-bound, expires, and is consumed by its first execution attempt. Never substitute `--approve` without its digest. A denial, changed or expired digest, replay, unsupported capability, failed probe, or failed native operation stops without retry.4142## Authentication4344When authentication remains:45461. Re-plan the provider-owned interactive login with the identical host, workspace, target, scope, and live values but `--action authenticate`.472. Obtain separate approval for that action's digest and state that the exact `authentication_argv` may open a browser and use network and account state.483. Give the operator the identical authenticate command plus `--approve "<authentication_digest>"` to run in their own terminal.4950> This is the sensitive phase: never run it through model-controlled Bash or another captured tool stream. Bridge then launches only the native login command with that terminal inherited. Never accept, request, pipe, echo, inspect, or store a token, API key, browser code, device code, email, or raw login output. Process exit means `auth-flow-launched`; only a later redacted status probe may establish `host-authenticated`.5152## Live verification5354When `live=prompt` or `live=required` reaches `inference-unverified`:55561. Re-plan with the identical host, workspace, target, and scope but `--action verify-live`.572. Obtain a third approval for that action's digest and one paid provider call.583. State network, installed-CLI-managed credential, quota/cost, workspace, and point-in-time semantics.594. Rerun that same verify-live command with `--approve "<live_digest>"`.6061> Never invoke the lower-level live doctor outside this approval path. A successful live CLI result remains partial until applicable loaded-session/workspace evidence is also present. `live=skip` remains `inference-unverified`; never call it ready. Denial under `live=required` is non-ready.6263## Completion boundary6465- Setup always owns one resolved peer target.66- To prepare both integrations, finish the peer lifecycle from Claude, start any required fresh session, then run `$bridge:setup` from Codex for its peer; no digest, state claim, or readiness result is shared between hosts.67- The loaded-host branch is check/bootstrap-only and never mutates its current invocation surface.68- `bridge_status` evidence belongs to a fresh Codex session and is required before claiming that reverse MCP session/workspace ready.69- Report the strongest verified level, exact remaining action, confidence, and limits.7071> Never equate static readiness, process exit, host authentication, session readiness, workspace readiness, or live verification.