Sign inSign up

docker/sbx-kit-codex-acp

Verified Publisher

By Docker, Inc.

•Updated 2 days ago

Runs the Codex ACP adapter inside a Codex sandbox over stdio.

Sandbox Kit
Image
0

872

docker/sbx-kit-codex-acp repository overview

Digest

sha256:9e9a5a25b568…

Size

41 MB

Schema

v3

Pushed

2 days ago

Specificationspec.yaml

MIXIN

The Agent Client Protocol adapter for Codex as a mixin — the codex-acp stdio server with its Node runtime in an overlay, bound to the composed codex binary. Layer it onto a base that composes the codex-mixin kit and point an ACP client (such as Zed) at `codex-acp`.


Arguments
NameRequiredDefaultDescription
versionOptional2.0.1

codex-acp release to install



CapabilitiesExpand a row to see its full configuration. See the full spec for the complete descriptor.
TypeRequiredDescription
com.docker.sandbox/agent-context@1Required—

Requirescodex >= 0.159.1, < 0.160.0

Apply this mixin to a sandbox

sbx run <agent> --kit docker/sbx-kit-codex-acp:latest

Make sure you have docker sbx installed

Run the following command to install sbx on your machine.

macOS
brew install docker/tap/sbx
Windows
winget install Docker.sbx
Learn more about docker sbx⁠

Note

Experimental: Sandbox Kit v3

This kit uses the experimental Sandbox Kit specification⁠, specifically v3⁠. The format and runtime behavior may change before v3 is stable.

⁠codex-acp

Run the Codex ACP adapter inside a Docker Sandbox.

This is a kind: mixin kit (schemaVersion: "3") that requires: ["codex"], so it composes onto any kit providing that name — the codex⁠ workload kit or the codex-mixin⁠ overlay. It adds /home/agent/.local/bin/codex-acp, a small launcher that runs @agentclientprotocol/codex-acp with CODEX_PATH=codex.

The kit ships no layers of its own: the launcher is written by a lifecycle files entry at sandbox start and resolves the adapter through npx when it runs, which is why registry.npmjs.org is in the kit's runtime allow list rather than only needed at build time.

⁠Authentication

codex-acp inherits OpenAI authentication from whichever kit provides codex in the composition — it declares no credential of its own. Seed OpenAI auth with sbx before creating the sandbox so the non-interactive ACP adapter can start authenticated.

For ChatGPT OAuth:

sbx secret set -g openai --oauth

For an OpenAI API key:

echo "$OPENAI_API_KEY" | sbx secret set -g openai

You can also import a detected host environment variable:

sbx secret import openai

The Codex ACP adapter does not advertise a terminal-auth command. Keep provider credentials in the sbx credential store rather than passing API keys through sbx exec argv or ad-hoc environment variables. If you add OpenAI auth after a sandbox has already been created, recreate the sandbox so the codex-providing kit can refresh its Codex auth files.

⁠Usage

Create a sandbox from its published OCI artifact on Docker Hub:

sbx create --kit "docker.io/docker/sbx-kit-codex-acp:latest" --name my-task codex /path/to/task

Or from a git URL targeting this repo:

sbx create --kit "git+https://github.com/docker/sbx-kits-contrib.git#dir=codex-acp" --name my-task codex /path/to/task

Run the adapter over stdio:

sbx exec -i my-task /home/agent/.local/bin/codex-acp

Do not allocate a TTY for ACP sessions; the adapter expects newline-delimited JSON-RPC on stdin/stdout.

⁠References

This week's pulls

Pulls:

172

Last week