GOVENANT
Free · read-only · Coding tool

Audit your Codex CLI agents.

Audit your Codex CLI agents for free in two commands. Add the GOVENANT Audit MCP server, log in from the terminal, and have Codex run a read-only governance sweep of your own agent system, graded against the open standard.

Step 1

Add the audit to Codex

Paste one URL — no API key. Codex CLI connects itself.

Step 2

Sign in

Browser login via codex mcp login. That’s the whole ask.

Step 3

Ask for the audit

Say “Run a GOVENANT trust sweep.” Get a shareable report back.

Add the GOVENANT Audit to Codex CLI

The MCP server URL:

https://mcp.govenantstandard.org/mcp

Run these commands:

codex mcp add govenant --url https://mcp.govenantstandard.org/mcp
codex mcp login govenant
  1. Run: codex mcp add govenant --url https://mcp.govenantstandard.org/mcp
  2. Run: codex mcp login govenant (browser opens).
  3. Ask Codex: “Run a GOVENANT trust sweep.”

On older builds, run npm i -g @openai/codex@latest first.

Authentication: Browser login via codex mcp login.

What the Codex CLI audit tells you

Anomalies first

The bad news up top: motion without delivery, missed work, approvals expiring unapproved, decisions never graded — the signs of performed autonomy.

Your grade

Where your Codex agents land on the GOVENANT ladder — Logged → Gated → Delivered → Earned — and the delivery numbers behind it.

Delivery, not activity

Verified outcomes vs. total actions, work delivered vs. missed — measured against the record, never self-reported.

A shareable page

Every run has its own URL, with an optional one-click “share for a free expert review.”

Codex CLI audit — FAQ

codex mcp add isn’t recognized — how do I fix it?
Update Codex first: npm i -g @openai/codex@latest, then run the add and login commands.
Is the GOVENANT Audit really free?
Yes. You sign in with GitHub or Google so we know who ran it — that’s the whole ask. No API key, no credit card, no paywall on the audit.
What does it read, and what does it never see?
It reads aggregate numbers from your agents’ own records: how many ran, how many finished, whether checks passed, which models you use. It never reads your prompts, your agents’ messages, your customers’ data, or any secrets.
What is “performed autonomy”?
Agents that look busy — fluent plans, satisfied logs — but don’t verifiably ship. Motion is not delivery. The audit measures verified outcomes against the record, never the logs’ self-report.

Using a different tool?

Prove your agents actually deliver.

Free under the covenant — the method is free forever. Read-only and aggregate-only: your prompts, data, and secrets never leave your machine.