Codex capability diagnosis

Why does Codex keep asking for permission?

Include the exact action, approval/policy message, surface, and whether the prompt returns in a new session.

1 · Redacted on this device 2 · Matched to explainable rules 3 · Saved only when you choose

Paste the first useful error/status or describe the last thing that worked and the first thing that failed.

0 / 32,768
Which capability?
Collect private diagnostics locally

Raw text stays in this browser. Only the sanitized preview is submitted. The diagnosis is not stored unless you explicitly save a private report.

Optional context Improves surface and version boundaries

Result

Your first supported failing layer will appear here

Capability Doctor will either return a bounded diagnosis, show the exact evidence still needed, or stop at an honest unknown.

Method and limits

A capability chain, not an AI guess

Earliest supported layer

Rules distinguish availability, discovery, parsing, configuration, dependency, connection, authentication, registration, exposure, activation, authorization, execution, and persistence.

Evidence before verdict

A rule must meet a deterministic threshold. Conflicting or incomplete evidence becomes partial or unknown; it is not converted into a confident root cause.

No unknown execution

The site does not install capabilities, execute packages, contact private endpoints, edit configuration, or ask for credentials.

Private by explicit choice

A diagnosis is stateless by default. Saved reports use random URLs, expire after seven days, can be deleted immediately, and are excluded from indexing.