OpenAI Codex CLI Keyboard Shortcuts
Codex CLI is a terminal application, so its keyboard surface splits into two halves that behave differently. There is a small set of true key bindings in the composer — the text area at the bottom of the full-screen interface — and a much larger set of slash commands typed into that composer. Neither is a keyboard shortcut in the sense a desktop application means, and confusing them is the most common reason people conclude the tool has almost no shortcuts. It has plenty; most of them are words. The genuinely important distinction here has no equivalent in an editor at all. While the agent is running, Enter and Tab both send what you have typed, and they do different things with it. Enter interrupts — your message goes into the turn already in progress and changes what the agent is doing right now. Tab queues — your message waits until the current turn completes and then becomes the next instruction. 'Stop, do not touch that file' is an Enter. 'After that, run the tests' is a Tab. Getting these the wrong way round is the difference between a correction that lands and one that arrives after the mistake it was meant to prevent. A warning about references, including this one. Codex CLI moves quickly and its bindings have genuinely changed: newline insertion, the approval flow and the session commands have all been reworked since the tool's first public releases, and older cheat sheets — some still highly ranked — document a version that no longer exists. Everything below reflects the interface as of the v0.135.0-era releases in mid-2026. The authoritative answer for your install is always typing /help in the composer, which lists the commands your binary actually has, and that is worth doing after any update rather than assuming continuity. One last piece of framing. Because Codex acts on your filesystem and can run shell commands, several of the controls below are not conveniences but safety boundaries. The approval preset governs what the agent may do without asking, and the sandbox governs what it can reach at all. Those are the settings worth understanding before the ones that save keystrokes.
Session Control
| Action | Windows | Mac | Description |
|---|---|---|---|
| Cancel the current operation | Ctrl+C | Ctrl+C | Stops whatever the agent is doing and returns control to the composer, leaving the conversation intact. Pressing it a second time quits the session — so a reflexive double tap ends more than you meant. |
| Exit the session | Ctrl+D | Ctrl+D | Leaves Codex CLI, with a second press forcing the exit if something is still winding down. The /exit and /quit slash commands do the same thing from the composer if your hands are already there. |
| Clear the terminal screen | Ctrl+L | Ctrl+L | Wipes the visible scrollback without touching the conversation — the model still remembers everything. This is the key difference from /clear, which resets the transcript and starts a fresh chat inside the same session. |
| Reset the conversation | /clear | /clear | Clears the visible transcript and starts a fresh chat, discarding the context the model was carrying. /new does the same without leaving the terminal, and both are what you want when the conversation has drifted rather than merely got long. |
| Summarise the conversation to free context | /compact | /compact | Replaces the accumulated conversation with a summary, reclaiming context window while keeping the thread of what you were doing. The middle option between carrying on and starting over, and the right one when a long session is still going somewhere. |
| Resume or fork a previous conversation | /resume, /fork | /resume, /fork | /resume picks a saved conversation back up where it stopped; /fork branches the current one into a new thread while leaving the original intact. Forking is the safe way to try a different approach without losing the path you were on. |
Input Editing
| Action | Windows | Mac | Description |
|---|---|---|---|
| Steer the running turn | Enter (while the agent is working) | Enter | Injects your message into the turn already in progress, changing what the agent is doing immediately. This is the control for urgent corrections — a wrong file, a wrong assumption, a command you do not want run. |
| Queue a follow-up prompt | Tab (while the agent is working) | Tab | Holds your message until the current turn finishes, then delivers it as the next instruction. The right choice for anything that should happen after the present work rather than instead of it. |
| Insert a newline without sending | Ctrl+J | Ctrl+J | Adds a line break inside the composer instead of submitting. Shift+Enter works in some terminals and not others because of how they encode the keypress, which is why Ctrl+J is the binding to rely on. |
| Open the prompt in your editor | Ctrl+G | Ctrl+G | Hands the current composer contents to whatever VISUAL or EDITOR points at, and takes back what you save. The practical answer for a long or structured prompt, since the composer is not a text editor and does not pretend to be. |
| Edit your previous message | Esc Esc (composer empty) | Esc Esc | Double-pressing Escape on an empty composer reopens your last message for editing, and continuing to press walks further back through the transcript. Useful when a prompt was misread and rewording beats explaining. |
| Navigate draft history | Up / Down | Up / Down | Steps back through earlier composer drafts, restoring their text and any image placeholders they carried. Distinct from Esc Esc, which edits messages you actually sent rather than drafts you typed. |
| Attach a file with @ | @ then Tab or Enter | @ then Tab or Enter | Typing @ opens a fuzzy search across the workspace; accepting a match attaches that file to the conversation. Far more reliable than describing a path in prose and hoping the agent locates the right thing. |
| Run a local shell command with ! | !command | !command | Executes the command on your machine outside Codex's sandbox and shows you the output — without sending any of it to the model. The way to check something for yourself mid-session without spending context on it. |
| Attach an image | Paste into the composer, or -i at launch | Paste into the composer, or -i at launch | Screenshots can be pasted straight into the composer in terminals that support it, or attached at launch with the -i flag. Useful for a failing UI or an error dialog where describing the problem takes longer than showing it. |
Approval Modes
| Action | Windows | Mac | Description |
|---|---|---|---|
| Change the approval preset mid-session | /permissions | /permissions | Opens a picker for how much the agent may do without asking, switchable at any point rather than fixed at launch. The most important control in the tool — it decides whether a shell command pauses for you or simply runs. |
| Set the approval policy at launch | -a / --approval-mode flag | -a / --approval-mode flag | Fixes the policy for the whole run from the command line, which is how you would drive Codex in a script or a CI job. Setting it to never removes every prompt, so it belongs only where the sandbox is doing the actual containing. |
| Show model, policy and token usage | /status | /status | Reports the active model, the approval policy in force, which directories are writable, and how much context you have used. The one command worth running before letting the agent work unattended. |
| Grant access to another directory | --add-dir at launch | --add-dir at launch | Extends the sandbox beyond the working directory to a path you name. Needed when a task genuinely spans repositories or has to read logs elsewhere, and worth granting narrowly rather than broadly. |
| Persist settings across sessions | config.toml, or -c key=value inline | config.toml, or -c key=value inline | Preferences set with slash commands last only for the session; config.toml makes them the default. The -c flag overrides a single key inline, which is the quick way to test a setting before committing to it. |
| Test a command under the sandbox policy | codex sandbox <command> | codex sandbox <command> | Runs a command you choose under exactly the restrictions the agent would face, so you can see what the sandbox permits before trusting it. The enforcement differs by platform — Seatbelt on macOS, Landlock and seccomp on Linux, restricted tokens on Windows. |
Review Project Tools
| Action | Windows | Mac | Description |
|---|---|---|---|
| Show the working-tree diff | /diff | /diff | Displays the Git diff of everything currently changed, untracked files included. The habitual check after an agent turn, and the reason untracked files are covered is that a new file is exactly what you would otherwise miss. |
| Run a code review | /review | /review | Reviews the working tree, with presets for comparing against a base branch, uncommitted changes only, or specific commits. Distinct from reading the diff yourself — this is the agent examining its own output against the code around it. |
| Switch to plan mode | /plan | /plan | Produces an execution plan without changing anything on disk. Worth reaching for on any task large enough that you would rather argue with the approach before it becomes a diff you have to read. |
| Generate an AGENTS.md scaffold | /init | /init | Creates a repository instructions file that Codex reads on every future session in that directory. The place to record conventions you would otherwise repeat in every prompt — build commands, style rules, directories to leave alone. |
| Change model and reasoning effort | /model | /model | Opens a picker for the active model and how much reasoning effort it should spend, switchable mid-conversation. Dropping to a lighter model for mechanical work and back up for design questions is a real cost lever within a single session. |
| List configured MCP tools | /mcp | /mcp | Shows which Model Context Protocol servers this session can reach. The first thing to check when an integration you configured appears to be doing nothing — an MCP server that failed to start is silent rather than loud. |
| Copy the last response | /copy | /copy | Puts the most recent completed output on the system clipboard, which beats selecting multi-line text in a terminal by a wide margin. Particularly useful for a generated command or block of code headed somewhere else. |
Frequently Asked Questions
How do I add a newline without sending my message?
Ctrl+J. Shift+Enter is what most people try first, and it works in some terminals and not others — the reason is that terminals differ in whether they transmit a distinguishable code for Shift+Enter at all, so the application never sees it as separate from a plain Enter. Ctrl+J sends an actual line-feed character that every terminal passes through identically, which is why it is the binding to rely on. For anything longer than a few lines, Ctrl+G hands the prompt to your real editor and is a better answer than fighting the composer.
What is the difference between pressing Enter and pressing Tab while Codex is working?
Both send what you typed; they differ in when it takes effect. Enter interrupts the turn in progress and injects your message into it immediately, changing what the agent is doing right now. Tab queues the message to be delivered once the current turn completes. Use Enter for corrections that cannot wait — a wrong file, a command you do not want run — and Tab for follow-up work such as running the tests afterwards. Choosing wrong is not destructive but it is frustrating: a queued correction arrives after the mistake it was meant to prevent.
Does Ctrl+L clear my conversation?
No, and the distinction matters. Ctrl+L clears the visible terminal scrollback only — the model still holds the entire conversation and will answer as though nothing was erased. /clear resets the transcript and starts a fresh chat within the same session, genuinely discarding the context. If a session has gone in a direction you want to abandon, /clear is the command; if you simply want a tidy screen, Ctrl+L is enough and costs nothing.
How do I stop Codex asking permission for every command?
/permissions opens a picker for the approval preset and applies it from that point in the session, and the -a flag sets the policy at launch for a whole run. Before loosening it, run /status to see what is actually in force, including which directories are writable. The setting worth understanding is that approval and sandboxing are separate: approval decides whether you are asked, the sandbox decides what is reachable at all. Turning approvals off in a properly scoped sandbox is a reasonable trade; turning them off with a broad sandbox is not.
Why does an old cheat sheet say Y and Enter to approve a command?
Because the approval flow was reworked. Earlier Codex CLI releases prompted per command with a yes/no answer; current versions use named permission presets chosen through /permissions or set at launch, so there is no standing Y-then-Enter to memorise. This is the clearest example of a general problem with Codex CLI references: the tool has changed quickly enough that several widely-shared cheat sheets describe an interface that no longer exists. Typing /help lists what your binary actually supports, and that is the only answer that cannot go stale.
What does the @ prefix do?
Typing @ in the composer opens a fuzzy search across your workspace, and pressing Tab or Enter on a match attaches that file to the conversation. It is more reliable than describing a path in prose, because the agent then has the file's actual contents rather than an instruction to go and find something matching your description. For large files, be aware that attaching consumes context — /status shows how much you have left, and /compact reclaims some without ending the session.
What does the ! prefix do, and is it sandboxed?
! runs the rest of the line as a shell command on your machine, outside Codex's sandbox, and displays the output locally without sending it to the model. Both halves matter. Outside the sandbox means it is your shell with your permissions, so the safety boundary that constrains the agent does not constrain you here. Not sent to the model means you can check something — a git log, a directory listing — without spending context on it, which is the main reason to use it rather than asking the agent to look.
Can I recover a session I closed?
Yes. /resume lists saved conversations and picks one back up where it stopped, and codex resume does the same from outside an interactive session. /fork is the related command worth knowing: it branches the current conversation into a new thread while leaving the original intact, which is the safe way to try a different approach without destroying the path that got you there. Both are considerably more useful than they sound until the first time a long session goes wrong at the end.
Do the shortcuts work the same on Windows?
The composer bindings — Ctrl+C, Ctrl+D, Ctrl+J, Ctrl+G, Ctrl+L, Esc Esc — are identical across platforms, because they are terminal control codes rather than application shortcuts. What differs is the sandbox underneath: macOS uses Seatbelt, Linux uses Landlock and seccomp, and Windows uses restricted tokens and ACLs under WSL. One command exists only on Windows as a result, /sandbox-add-read-dir, which grants the sandbox read access to additional directories. A few subcommands are also macOS-only, so /help on your own machine is the reliable inventory.
How do I stop repeating the same project context in every prompt?
/init generates an AGENTS.md file in the current directory, which Codex reads at the start of every future session there. Build commands, test commands, code style, directories that must not be touched, deployment caveats — anything you find yourself explaining twice belongs in it. This is the single highest-value few minutes available in the tool, because every instruction you move into that file is one you stop paying for in attention and context on every subsequent session.