Agent guides

Connect Codex to IPMusk

Add IPMusk to Codex in config.toml. Codex reads your key from an environment variable, so the file holds no secret.

Who this is for

Developers who use the OpenAI Codex CLI or IDE extension and want it to fetch proxy URLs and account details.

What you need

  • An IPMusk account with a verified email address.
  • An IPMusk API key. Create it in Settings → API keys (/app/settings/api-keys). For typical use tick read and connect. Add support only if the assistant should open tickets, and order only if it should create orders that end in a payment link.
  • The key in an environment variable named IPMUSK_API_KEY, for example export IPMUSK_API_KEY="ipm_live_YOUR_KEY" in your shell profile. The examples below read it from there.
  • Codex installed.

Set it up

Add the server to ~/.codex/config.toml.

  • Or run: codex mcp add ipmusk --url https://ipmusk.com/mcp --bearer-token-env-var IPMUSK_API_KEY
  • Export IPMUSK_API_KEY before you start Codex. Codex reads it at start-up.
~/.codex/config.toml
[mcp_servers.ipmusk]
url = "https://ipmusk.com/mcp"
bearer_token_env_var = "IPMUSK_API_KEY"

Sign in with OAuth instead

Leave out bearer_token_env_var, then run codex mcp login ipmusk and sign in to IPMusk in your browser.

Add and sign in
codex mcp add ipmusk --url https://ipmusk.com/mcp
codex mcp login ipmusk

Some Codex versions need an extra setting before OAuth login works. Check Codex's current docs if login is not offered.

Check it works

Run codex mcp list. ipmusk should be listed.

Ask the assistant: Which IPMusk account am I connected as? It should call get_account and answer with your email address.

Try these prompts

  • How much IPMusk residential traffic do I have left?
  • Get a sticky US proxy URL for 10 minutes and use it in this script.
  • List my IPMusk Static ISP proxies and when they expire.

If it fails

  • 401 authentication_required: the key is missing, wrong, revoked or expired. Check that IPMUSK_API_KEY is set where the client starts. echo ${#IPMUSK_API_KEY} prints its length without showing the key.
  • Codex says the variable is not set: export IPMUSK_API_KEY in the same shell, then start Codex again.
  • 403 forbidden on one tool: the key lacks that tool's scope, or your email is not verified. Scopes cannot be added to a key, so create a new key with the scope and swap it in.
  • 429 rate_limited: too many calls in one minute (read 60, connect 20, support 30, order 10). Wait a minute and try again.

Remove access

  • Revoke the key in Settings → API keys (/app/settings/api-keys). It stops working at once.
  • Then run codex mcp remove ipmusk, or delete the [mcp_servers.ipmusk] block.
  • If you signed in with OAuth, disconnect Codex in Settings → API keys → Connected AI apps.