You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
At the pinned Parsar Core revision 2b34ea4630a5a0daf90e745fe1af3edcfa4f0e9e, the public Agents API has two bounded tool profiles that Web can expose honestly:
non-deferred external Function callbacks
service-origin HTTP MCP, including anonymous servers
The current Web can render function_call, function_call_output, mcp_call, command_execution, and web_search_call Items. It can also manually submit a Function result for an existing configured Agent. However, Agent create/edit has no Tools controls, and the TypeScript client does not model MCP write input, so users cannot configure the supported Function/MCP profiles from Web.
This Issue is Web-only. It must not modify, emulate, or vendor Parsar Core, daemon, executor, or Codex runtime behavior.
Bounded outcome
Add a protocol-honest Tools section to Agent create/edit so a user can configure the Core-supported Function callback profile and anonymous service-origin HTTP MCP profile. Unsupported or saved-only tools remain hidden/read-only and fail closed.
Acceptance criteria
Function tools
Agent create/edit can add, edit, and remove a non-deferred Function with name, description, and an object JSON Schema in parameters.
The UI explains that Core emits a function_call; an external application or the existing Web result form must execute the business action and submit agent.session.input.tool_result with the exact Turn/call identity.
Client/form validation matches the supported Core subset: unique non-empty names, object schema, at most 64 Functions, and no defer_loading:true.
Existing Function call/result rendering and success/error result submission remain intact.
Anonymous HTTP MCP
Agent create/edit can add, edit, and remove an MCP server with server_label, HTTP(S) server_url, optional allowed_tools, and optional required.
Writes always use transport.type=http and connection_origin=service.
The UI explains that MCP discovery/calls run on trusted Core service compute; under self_hosted, workspace commands run on the executor but MCP still does not run in the browser or executor.
The first slice is anonymous only: no credential_id, inline authorization, headers, request metadata, OAuth, stdio, client-origin connection, or secret input.
allowed_tools semantics are explicit: omitted/null permits all advertised tools, while an empty list permits none.
Fail-closed editing and compatibility
Existing unknown, malformed, credentialed, deferred, or saved-only tool definitions are shown read-only and are never silently discarded or rewritten by an unrelated Agent edit.
tool_search and programmatic_tool_calling remain marked saved-only and cannot be enabled for Session execution.
No Web Search switch is shown. The pinned Core rejects persisted web_search and sends execution with Web Search disabled.
No command/filesystem or Code Mode toggle is shown. environment:none does not provide that environment, and the current self-hosted runtime readiness gap is upstream-owned.
Session admission continues to state that accepted configuration is not proof of runtime readiness; Core remains the authority for daemon/executor/MCP capability.
Validation and documentation
Add focused unit/component tests for Function and anonymous MCP serialization, validation, editing, and preservation of unsupported values.
Add fixture coverage for successful and failed Function/MCP Items without making a paid provider call.
Update docs/protocol-coverage.md with the exact Parsar revision and distinguish configure, execute, callback, render-only, saved-only, and unsupported states.
Run pnpm check and git diff --check.
Non-goals
No Parsar, daemon, executor, image, or codex-code-mode-host change.
No Web Search, Code Mode command/file tools, tool_search, or programmatic_tool_calling execution UI.
No Vault credential attachment, OAuth, arbitrary headers, inline secrets, stdio MCP, or browser-side MCP client.
No paid model/provider smoke, deployment, merge, or branch/worktree deletion in this Issue.
Ownership note
The observed codex-code-mode-host failure is not fixed here. Web must display the safe Core error but cannot repair a missing runtime companion. This Issue only exposes Core profiles already supported by the pinned public contract.
Context
At the pinned Parsar Core revision
2b34ea4630a5a0daf90e745fe1af3edcfa4f0e9e, the public Agents API has two bounded tool profiles that Web can expose honestly:The current Web can render
function_call,function_call_output,mcp_call,command_execution, andweb_search_callItems. It can also manually submit a Function result for an existing configured Agent. However, Agent create/edit has no Tools controls, and the TypeScript client does not model MCP write input, so users cannot configure the supported Function/MCP profiles from Web.This Issue is Web-only. It must not modify, emulate, or vendor Parsar Core, daemon, executor, or Codex runtime behavior.
Bounded outcome
Add a protocol-honest Tools section to Agent create/edit so a user can configure the Core-supported Function callback profile and anonymous service-origin HTTP MCP profile. Unsupported or saved-only tools remain hidden/read-only and fail closed.
Acceptance criteria
Function tools
name,description, and an object JSON Schema inparameters.function_call; an external application or the existing Web result form must execute the business action and submitagent.session.input.tool_resultwith the exact Turn/call identity.defer_loading:true.Anonymous HTTP MCP
server_label, HTTP(S)server_url, optionalallowed_tools, and optionalrequired.transport.type=httpandconnection_origin=service.self_hosted, workspace commands run on the executor but MCP still does not run in the browser or executor.credential_id, inline authorization, headers, request metadata, OAuth, stdio, client-origin connection, or secret input.allowed_toolssemantics are explicit: omitted/null permits all advertised tools, while an empty list permits none.Fail-closed editing and compatibility
tool_searchandprogrammatic_tool_callingremain marked saved-only and cannot be enabled for Session execution.web_searchand sends execution with Web Search disabled.environment:nonedoes not provide that environment, and the current self-hosted runtime readiness gap is upstream-owned.Validation and documentation
docs/protocol-coverage.mdwith the exact Parsar revision and distinguish configure, execute, callback, render-only, saved-only, and unsupported states.pnpm checkandgit diff --check.Non-goals
codex-code-mode-hostchange.tool_search, orprogrammatic_tool_callingexecution UI.Ownership note
The observed
codex-code-mode-hostfailure is not fixed here. Web must display the safe Core error but cannot repair a missing runtime companion. This Issue only exposes Core profiles already supported by the pinned public contract.