Codex CLI: "error: unexpected argument '--full-auto' found"
error: unexpected argument '--full-auto' found
tip: to pass '--full-auto' as a value, use '-- --full-auto'
Usage: codex exec [OPTIONS] [PROMPT]
codex exec [OPTIONS] <COMMAND> [ARGS]
For more information, try '--help'.Tool: OpenAI Codex CLI (codex). Versions: Affected: 0.147.0 and later; last version without this error: 0.146.1; we reproduced it on 0.146.1, 0.147.0, 0.160.1. Exit code 2.
Cause: Codex CLI 0.147.0 (released 2026-08-07) removed the hidden, deprecated --full-auto flag from codex exec, so the argument parser now rejects it.
Fix: Replace --full-auto with --sandbox workspace-write.
# before (0.146.1 and older)
# codex exec --full-auto "<prompt>"
codex exec --sandbox workspace-write "<prompt>"--full-auto never appeared in codex exec --help, so a diff of the help text does not show its removal. 0.146.1 printed a deprecation warning pointing to --sandbox workspace-write and ran with sandbox: workspace-write; with the replacement flag 0.160.1 prints the same sandbox: workspace-write [workdir, /tmp, $TMPDIR] header (see the reproduction below).
How did we reproduce the Codex CLI error?
A fresh Debian 13 VM from bin/sandbox-run (Node.js 24, root, online, no credentials for any service), destroyed after the run. Without an OpenAI login the model request itself fails, so the fix is verified by the session header Codex prints before it calls the API. Run on . Failing command: codex exec --full-auto --skip-git-repo-check "say hi" </dev/null.
Before: deprecated but accepted (Codex CLI 0.146.1):
$ codex exec --full-auto --skip-git-repo-check "say hi" </dev/null
warning: `--full-auto` is deprecated; use `--sandbox workspace-write` instead.
Reading additional input from stdin...
OpenAI Codex v0.146.1
--------
workdir: /root/work
model: gpt-5.6-sol
provider: openai
approval: never
sandbox: workspace-write [workdir, /tmp, $TMPDIR]
[… trimmed 26 lines …]
# exit 1After: rejected by the argument parser (Codex CLI 0.147.0):
$ codex exec --full-auto --skip-git-repo-check "say hi" </dev/null
error: unexpected argument '--full-auto' found
tip: to pass '--full-auto' as a value, use '-- --full-auto'
Usage: codex exec [OPTIONS] [PROMPT]
codex exec [OPTIONS] <COMMAND> [ARGS]
For more information, try '--help'.
# exit 2Same in the latest release (Codex CLI 0.160.1):
$ codex exec --full-auto --skip-git-repo-check "say hi" </dev/null
error: unexpected argument '--full-auto' found
tip: to pass '--full-auto' as a value, use '-- --full-auto'
Usage: codex exec [OPTIONS] [PROMPT]
codex exec [OPTIONS] <COMMAND> [ARGS]
For more information, try '--help'.
# exit 2Fix verified: the replacement flag parses and selects the same sandbox (the run then fails on the network, since the VM has no OpenAI login) (Codex CLI 0.160.1):
$ codex exec --sandbox workspace-write --skip-git-repo-check "say hi" </dev/null
Reading additional input from stdin...
OpenAI Codex v0.160.1
--------
workdir: /root/work
model: gpt-6.1-sol
provider: openai
approval: never
sandbox: workspace-write [workdir, /tmp, $TMPDIR]
[… trimmed 23 lines …]
# exit 124Why does Codex CLI print this error?
Pull request #36054 (merged 2026-07-30, shipped in 0.147.0) stops "accepting the hidden, deprecated --full-auto flag in codex exec" and removes "its implicit mapping to the workspace-write sandbox. Callers must now select the sandbox mode explicitly with --sandbox workspace-write." (openai/codex PR #36054)
Related Codex CLI fixes and pages
Not inside a trusted directory and --skip-git-repo-check was not specified.(Codex CLI all versions we ran (0.129.0 to 0.160.1))- Codex CLI tool page: codex exec --full-auto fails with unexpected argument
- All fix pages
Sources
- Remove legacy --full-auto handling from codex exec (PR #36054) (read 2026-10-07)
- Codex CLI 0.147.0 release notes (read 2026-10-07)
Last verified: 2026-10-07.