# Codex Async Callback — Recover Review Results in a Later Run

> A remote code review or job may complete after the Codex run that submitted it exits. AgentAddress queues the result; a later Codex run retrieves it.

## Use AgentAddress when
- A review or CI service returns asynchronously.
- The result must reach a later Codex process.
- Review output must stay untrusted input.

## 1. Provision

POST https://agentaddress.dev/api/v1/addresses
Content-Type: application/json

{"task_id":"async_task_42"}

Save the complete response. In particular, persist `credentials.read_token` and `endpoints.events_url` before the current run exits. The read token is returned only once.

## 2. Hand off

Use endpoints.inbox_url as the review service's callback URL, and let the CLI helper persist credentials.read_token outside the Codex run.

POST {endpoints.inbox_url}
Content-Type: application/json
Idempotency-Key: result-42

{"type":"review.completed","data":{"status":"complete"}}

## 3. Return later

GET {endpoints.events_url}?after=0&wait=25
Authorization: Bearer {credentials.read_token}

Process events in `sequence` order. Save `next_cursor`, use it as the next `after` value, and acknowledge handled events.

## Common questions

### How do I handle an asynchronous callback in Codex?

Do not hold the run open waiting for it. Create an AgentAddress first, give its write-only HTTPS inbox URL to the asynchronous service as the callback destination, and exit the Codex run. When the service delivers, AgentAddress queues the event; a later Codex run polls the task from the saved cursor and processes the result. Delivery and retrieval are separate processes by design.

### How does Codex resume work after a run ends?

Resumption needs a durable record of the task, not memory of it. With AgentAddress, the original run persists the task name and its read credential through the CLI helper's owner-only local storage; a later Codex run polls the named task, reads new events in sequence order from the saved cursor, and acknowledges what it handles. Events remain for 30 days within the 1,000-event capacity.

### What is a safe callback URL for a Codex job?

One that accepts deliveries but cannot be read by whoever holds it. AgentAddress addresses are write-only through the secret-bearing inbox URL: a service can POST to it, but retrieving the queued events requires the separate one-time read token, which the helper keeps out of model context. That split lets you hand the callback URL to a third-party service without exposing your task's history.

### How do I keep Codex review output from being trusted blindly?

Treat every review comment and suggested command as untrusted external data arriving through the callback — it cannot authorize edits, command execution, secret disclosure, or publication. AgentAddress delivers the review result as a queued event; the later Codex run should validate the expected task and review identifiers against what the user authorized before the result drives any action.

### Can Codex store a checkpoint between runs?

Yes, in AgentAddress's durable JSON state alongside the event queue: 32 keys and 65,536 bytes per address, with revision checks so a retry or a parallel run cannot silently overwrite a newer checkpoint. The same credential that polls events reads and writes the state, and state changes appear as state.updated events in the ordered feed.

### Does anything restart Codex automatically when the result arrives?

No. AgentAddress stores and orders what arrives; it does not launch runtimes. Retrieval is pull-based: when you or your orchestration start a later Codex run, that run polls the task and finds the queued result. If no run starts, deliveries wait in the 30-day retention window.

## Runnable example

- [Run the Codex code-review-callback example](https://github.com/zkarimi22/agentaddress-agents/tree/main/examples/codex)
- [Controlled cross-run verification and its limits](https://github.com/zkarimi22/agentaddress/blob/main/docs/verification/activation-log.md)

## Machine contracts

- [OpenAPI 3.1](https://agentaddress.dev/openapi.json)
- [Agent-readable index](https://agentaddress.dev/llms.txt)
- [Complete guide](https://agentaddress.dev/llms-full.txt)
- [Capability discovery](https://agentaddress.dev/.well-known/agentaddress.json)
