Codex CLI update fixes reconnect recovery and model catalogs
Codex CLI 0.160.0 improves queued message recovery and model catalog handling while keeping new Guardian review capabilities optional.

OpenAI released Codex CLI 0.160.0 on October 1 with changes to message recovery, model selection and session permissions. The update focuses on problems that can interrupt an agent during ordinary work, including a dropped connection or a model list that no longer matches its provider.
The release also includes experimental additions to Guardian, the approval reviewer. Those capabilities remain disabled by default and are marked as under development in the tagged feature registry. Updating the CLI alone does not turn them on.
Reconnect without repeating an uncertain request
The message recovery change separates input that was never sent from submissions whose delivery is uncertain. Codex checks message identifiers against restored history and receipts, removes confirmed submissions from the recovered queue and lets unsent input continue once uncertainty is resolved.
A request with unknown delivery remains paused and produces a notice. That distinction matters when a prompt could trigger edits or other actions. Sending it again immediately can repeat work that already began. The change does not establish a guarantee about every external action an agent might perform.
A model menu should reflect the actual provider
A provider catalog fix makes an explicit model catalog authoritative. Unsupported bundled models should no longer appear alongside that catalog, and failed refreshes should not leave stale entries in use. This is a configuration reliability change, with no claim that the release introduces a new model.
Experimental review can use more context
The history retrieval addition lets an enabled reviewer look for earlier user instructions, restrictions or revoked permission. Calls remain subject to the parent conversation’s current app and tool rules. The purpose is to help a review account for relevant authorization that a shortened transcript may omit.
A separate handoff context addition selects relevant conversation evidence around delegated work and retains recent messages so cancellations remain visible. Both additions are optional. Neither should be treated as a promise that an automated reviewer will always interpret permission correctly.
Session permissions still depend on policy
The projectless session update allows workspace defaults outside a recognized project when local execution, configuration and managed policy permit them. Resuming a task restores its saved permissions unless explicitly overridden. Windows may still require sandbox setup before implicit workspace writing is enabled.
For teams evaluating the update, useful checks are concrete. Confirm that the selected model exists at the provider, inspect a recovered queue before repeating a request, and verify the permissions shown after resuming a task. ByteForward has not independently run this release.
These operational details complement the recovery questions in our Pi 1.0 and Pi Durable coverage. A useful agent workflow needs clear answers about what was saved, what was sent and what still needs approval.
Original AI generated conceptual illustration of connected coding tasks and stored context. Created for ByteForward.



