Skip to main content
Use this endpoint in every client:
Start a new Codex session in the configured project and use /mcp to confirm that Niblet tools are loaded.

Authorize carefully

The consent page shows the signed-in account, client, return host, and requested permissions. Stop if the return host is unfamiliar or the client asks for more access than the task needs.
Never work around OAuth by pasting a bearer token into client configuration or chat. A supported client should discover and complete the browser flow itself.