ISMS Copilot
How to

Connect ISMS Copilot to Codex

Talk to a specialist compliance AI from the harness you already use. Connected over MCP, Codex can read your ISMS Copilot workspaces, document metadata, and memories, and hold real compliance conversations, acting as you within the scopes you grant. Usage rides your ISMS Copilot chat subscription; there is no separate agent plan.

Set up in three steps

  1. 1Sign up free at chat.ismscopilot.com (a free tier exists, no card required), then create a token: Settings, Connected apps, Create token. Grant the narrowest scopes for the job and copy the pat-isms secret immediately; it is shown once.
  2. 2Add the server to your Codex config: the entry below goes in ~/.codex/config.toml. Set ISMSCOPILOT_TOKEN in your shell profile so the token itself never lands in the file. (The Codex CLI also has codex mcp add for creating entries; the bearer_token_env_var line lives in the config, the secret does not.)
  3. 3Start Codex and verify: run codex mcp list to confirm ismscopilot is configured, or /mcp inside the TUI to see it connected. Then ask in plain English, for example: list my ISMS Copilot workspaces.

The config.toml entry

[mcp_servers.ismscopilot]
url = "https://account.ismscopilot.com/v1/account/mcp"
bearer_token_env_var = "ISMSCOPILOT_TOKEN"

Set ISMSCOPILOT_TOKEN in your shell profile (for example: export ISMSCOPILOT_TOKEN="pat-isms-..."). Codex reads the variable named by bearer_token_env_var and sends its value as the Authorization Bearer header, so the token itself never lands in the TOML file. If a token ever lands in a committed file, treat it as compromised: revoke it in ISMS Copilot (Settings, Connected apps) and rotate the variable in your shell profile.

One config, every Codex client

Codex MCP configuration is shared: the same config.toml entry is read by the Codex CLI, the IDE extension, and the Codex surface inside the ChatGPT desktop app. You configure once and the server is available in whichever client you use. This is distinct from ChatGPT's own native MCP connectors feature (ChatGPT web does not read local config files and cannot connect to ISMS Copilot yet).

  • Config lives at ~/.codex/config.toml by default. A project-scoped .codex/config.toml can scope the server to a single project (trusted projects only); the environment-variable form above applies to project configs too, so no raw pat-isms token ever needs to be committed.
  • A shell profile only reaches clients launched from that shell. The Codex CLI inherits it from your terminal; a GUI-launched IDE extension or ChatGPT desktop app may not, depending on how your OS starts it. If ismscopilot shows up but calls fail with 401, launch that client from the same terminal (or set the variable at the OS level) so it sees ISMSCOPILOT_TOKEN, or use the http_headers alternative below.
  • If you prefer a static header instead of the environment variable, Codex supports http_headers in the server entry. Prefer bearer_token_env_var so the secret stays out of the file.
  • Codex supports per-server control without deleting the entry: enabled = false switches the server off, and tool allow or deny lists (enabled_tools, disabled_tools) can restrict which ISMS Copilot tools an agent may call, which pairs well with least-privilege tokens.
  • Longer turns may not answer inline: create_conversation and send_message can return status generating, and the agent polls get_reply instead. Point your agent at the machine connect feed for the polling pattern.

What it costs

In our pre-registered test (2026-09-28, 3 runs each, Claude Code with claude-sonnet-5), Claude Code delegating to ISMS Copilot scored the same as Claude Code researching alone on 20 identifier lookups across five frameworks (ISO 27001, ISO 42001, CMMC, DORA RTS, NIS2), using fewer Claude tokens per correct answer. ISMS Copilot plan usage is not counted there, and delegated turns count against your ISMS Copilot plan. Codex was not measured. Method and limits.

Account MCP, the surface this page connects to, is covered by your ISMS Copilot chat subscription: a fixed cost with no per-token billing. The metered option is the separate Model API (sk-isms keys), a different credential plane. Its rates, with sources and dates, live in the cost comparator on the GRC engineers page. See the comparator.

Secure by design

Access from outside your account happens only through a token you create yourself, and you stay in control of it.

  • A token acts as you and is limited to the scopes you grant when you create it. Grant the minimum.
  • It is covered by your subscription, with no separate billing to set up, and it can be revoked anytime in Settings, Connected apps.
  • Tokens do not unlock the Model API (sk-isms keys) or Embed partner billing. The credential planes are separate.
  • Toggling Advanced Data Protection is not available over MCP. Manage it in the web app.
  • The in-app Agent Tasks surface is separate from Account MCP and is not available through it (as of 2026-09-03, flags off in production).

Facts and dates

  • Codex behavior as documented at learn.chatgpt.com/docs/extend/mcp (the earlier developers.openai.com/codex/mcp URL now 308-redirects there), fetched 2026-09-23 and re-verified 2026-10-07: MCP servers are configured in ~/.codex/config.toml (or a project-scoped .codex/config.toml in trusted projects) under [mcp_servers.<name>]; Streamable HTTP servers take url, bearer_token_env_var, http_headers, and env_http_headers; the Codex CLI, IDE extension, and the Codex surface inside the ChatGPT desktop app share MCP configuration, separate from ChatGPT's own native MCP connectors feature; /mcp in the TUI and codex mcp list show configured servers.
  • ISMS Copilot endpoint, token steps, scopes, and limits verified against the machine connect feed (GET /api/public/connect/v1) and the product truth feed (GET /api/public/agents/v1), both fetched 2026-09-23 and re-verified 2026-10-07 (both HTTP 200).

Create a token and connect

Open Settings, Connected apps in ISMS Copilot, create a token, and paste the config above into Codex.