Docs menu

Get started

Install LexLint in Codex

Register the LexLint MCP server with Codex and give it your key.

codex mcp add lexlint --url https://mcp.lexlint.io/mcp

Register the server with the CLI. Codex writes the entry into ~/.codex/config.toml for you.

The Codex web app at https://chatgpt.com/codex is the one Codex surface with nowhere to put this: it exposes no server configuration at all, so there is no version of these steps that can be done there. If that is where you are reading this, set LexLint up in the CLI, the IDE extension, or the desktop app instead. Those three share the same ~/.codex/config.toml, so doing it once in any of them configures all three.

That gets the transport, not the key: mcp add has no flag for a custom header, and --bearer-token-env-var sends an Authorization header, which is not what mcp.lexlint.io reads. So add two header lines by hand, to the entry the command just wrote. Name the environment variable rather than pasting the key, and it stays out of the file:

[mcp_servers.lexlint] url = "https://mcp.lexlint.io/mcp" http_headers = { "X-API-Key" = "" } env_http_headers = { "X-API-Key" = "UNGOVR_API_KEY" }

The second value is the variable's name, not its contents. Codex reads UNGOVR_API_KEY out of the environment at connect time and sends it as the header. The first line is what lets the server answer before you have a key: with the variable unset Codex sends no header at all, and mcp.lexlint.io reads no header as a sign-in it cannot offer, so no tools appear. An empty header is read as no key, the tools appear, and the variable's value replaces it the moment it is set. Either way codex mcp get lexlint reads the entry back, and an older build without mcp add --url takes the block above written by hand.

The tools are the whole interface here, so the order of use is on you: call check_access first, and declare the app profile rather than letting the agent infer one from the code. The same procedure the Claude Code skill follows ships as an AGENTS.md in the LexLint plugin bundle, for any agent that reads one. The worked run shows the whole loop end to end.