tuqo
CLI · OAuth · no key

Tuqo in OpenAI Codex CLI

Codex CLI connects remote MCP servers over streamable HTTP and supports OAuth: after codex mcp login the browser opens, you sign in to Tuqo and pick the project, the scope and the lifetime. For CI and machines without a browser there is a second path: a tqk_ project key in ~/.codex/config.toml.

OAuth sign-in · choose project and scope · revoke in one click
1

Add the server

Run codex mcp add tuqo --url with the MCP address. The entry lands in ~/.codex/config.toml, section mcp_servers.tuqo.

2

Sign in over OAuth

codex mcp login tuqo opens the browser: sign in to Tuqo, choose the project, the scope (read-only, editor or full) and the lifetime.

3

Check the connection

codex mcp list shows the server and its auth status. In a session, ask "show my sites": Codex calls list_sites.

4

Deploy

"Build a landing page and publish it." Codex calls create_site and deploy_files and returns the live link.

# OAuth: the browser opens by itself
codex mcp add tuqo --url https://mcp.tuqo.ru/mcp
codex mcp login tuqo

# Or a project key instead of OAuth: ~/.codex/config.toml
[mcp_servers.tuqo]
url = "https://mcp.tuqo.ru/mcp"
http_headers = { "Authorization" = "Bearer tqk_xxx_yyy" }
# safer: keep the secret in an environment variable
# bearer_token_env_var = "TUQO_TOKEN"

The Tuqo panel is in English, and the labels here are the ones it shows.

OpenAI Codex CLI + Tuqo: frequently asked

Do I need a tqk_ key? +

Not with OAuth: codex mcp login tuqo approves access in the browser, and the connection shows up in the panel → project → AI connections, where it is also revoked. A key is for CI and servers without a browser: set http_headers with Authorization: Bearer tqk_…, or bearer_token_env_var with the name of an environment variable so the secret does not sit in the config.

Windows: where is the config and how do I write paths? +

The same file in your home folder: %USERPROFILE%\.codex\config.toml. TOML values go in double quotes; double the backslashes in paths or use forward slashes. The authorization header is one quoted string with no quotes inside.

Won't 52 tools flood the context? +

Tuqo exposes 52 tools, which is noticeable on models with a small context window. Tip: for "look and check" tasks connect with read-only access (a read-only key, or read-only on the consent screen), and switch to full access for the deploy.

I edited the config and nothing changed +

Codex reads config.toml at startup: restart the session. Server status: codex mcp list. On an auth error, run codex mcp login tuqo again.

Connect another AI