Docs menu
Get started
Quickstart Install: Claude Code Install: Codex Install: other clients API keysConcepts
How a run works The app profile The severity model What a run does not sayTools
check_access claim_trial_key set_profile run_lint get_law resolve_domain_jurisdiction submit_feedback upload_lint_runGuides
A whole run, end to end Console TestPack in CIReference
Endpoint and transport lexlint.yml schema Errors ChangelogHelp
Support and feedbackGet started
Install LexLint in Codex
Register the LexLint MCP server with Codex and give it your key.
codex mcp add lexlint --url https://mcp.lexlint.io/mcp
Register the server with the CLI. Codex writes the entry into
~/.codex/config.toml for you.
The Codex web app at
https://chatgpt.com/codex is the one Codex
surface with nowhere to put this: it exposes no server configuration at all, so there
is no version of these steps that can be done there. If that is where you are reading
this, set LexLint up in the CLI, the IDE extension, or the desktop app instead. Those
three share the same
~/.codex/config.toml, so doing it once in any of them configures all three.
That gets the transport, not the key: mcp add has no flag for a custom
header, and --bearer-token-env-var sends an Authorization
header, which is not what mcp.lexlint.io reads. So add two header lines by hand, to the
entry the command just wrote. Name the environment variable rather than pasting the
key, and it stays out of the file:
The second value is the variable's name, not its contents. Codex reads
UNGOVR_API_KEY out of the environment at connect time and sends it as the
header. The first line is what lets the server answer before you have a key: with the
variable unset Codex sends no header at all, and mcp.lexlint.io reads no header as a
sign-in it cannot offer, so no tools appear. An empty header is read as no key, the
tools appear, and the variable's value replaces it the moment it is set. Either way
codex mcp get lexlint reads the
entry back, and an older build without mcp add --url takes the block above
written by hand.
The tools are the whole interface here, so the order of use is on you: call
check_access first, and declare the app profile rather than letting the
agent infer one from the code. The same procedure the Claude Code skill follows ships
as an AGENTS.md in the LexLint plugin bundle, for any agent that reads
one. The worked run shows the whole loop
end to end.