# Codex iMessage setup: read and send texts from the terminal | SealGate

Codex iMessage setup: install the SealGate connector, add the MCP server to ~/.codex/config.toml, approve it once, then read and send texts from the terminal.

Source: https://sealgate.ai/connect/imessage/codex

---

[Docs](https://sealgate.ai/docs/) [Product](https://sealgate.ai/product) By role

[Security teams See every agent, prove control](https://sealgate.ai/product#for-security-leaders) [IT & platform Kill shadow MCP, clear the ticket queue](https://sealgate.ai/product#for-it-teams) [Engineering teams Keep your agents, skip the blocks](https://sealgate.ai/product#for-developers) [Compliance & enterprise Govern to the standards you answer to](https://sealgate.ai/product#for-compliance)

By feature

[Discovery Find and quarantine shadow MCP](https://sealgate.ai/product#discovery) [MCP gateway One enforcement point for every call](https://sealgate.ai/product#mcp-gateway) [Supply chain security Pin tools, catch silent changes](https://sealgate.ai/product#supply-chain) [Detection and Response Stop data leaving in real time](https://sealgate.ai/product#detection-response) [Risk scoring Score every session Low to High](https://sealgate.ai/product#risk-scoring) [Agent inventory & records One control plane for the fleet](https://sealgate.ai/product#system-of-actions) [Audit-ready Forensic trail for every action](https://sealgate.ai/product#audit-ready) [Chrome extension Track ChatGPT and Claude tool calls](https://sealgate.ai/chrome) [Self-hosting Run it in your own VPC or air-gapped](https://sealgate.ai/self-hosting)

[Developers](https://sealgate.ai/dev) AI Data Leaks [Cursor/VSCode Data Leak](https://www.linkedin.com/posts/eito-miyamura-157305121_cursor-github-mcp-can-lead-to-private-keys-activity-7383899320326160384-tMCX) [ChatGPT Gmail/Outlook Data Leak](https://www.linkedin.com/feed/update/urn:li:activity:7372306174253256704/) [Perplexity Comet Bankruptcy](https://www.linkedin.com/feed/update/urn:li:activity:7386434090901671936/) [Postgres Data Exfiltration](https://www.youtube.com/watch?v=cqvC7hGXy8Y) [Claude Desktop Data Leak](https://gatlingx.notion.site/Calendar-only-exfiltration-23e89dcc2f088029ade9e81e7d1c275f) [Claude Code Outlook Data Leak](https://www.youtube.com/watch?v=Wldae7-SN5E) [Confluence Insider Threat](https://www.youtube.com/watch?v=SpXUPto90IA)

[Blog](https://sealgate.ai/blog/) [Pricing](https://sealgate.ai/pricing) [Book a demo](https://cal.com/eito80/demo)

[Docs](https://sealgate.ai/docs/) [Product](https://sealgate.ai/product) [Developers](https://sealgate.ai/dev) [Pricing](https://sealgate.ai/pricing) [Self-hosting](https://sealgate.ai/self-hosting) AI Data Leaks [Cursor/VSCode Data Leak](https://www.linkedin.com/posts/eito-miyamura-157305121_cursor-github-mcp-can-lead-to-private-keys-activity-7383899320326160384-tMCX) [ChatGPT Gmail/Outlook Data Leak](https://www.linkedin.com/feed/update/urn:li:activity:7372306174253256704/) [Perplexity Comet Bankruptcy](https://www.linkedin.com/feed/update/urn:li:activity:7386434090901671936/) [Postgres Data Exfiltration](https://www.youtube.com/watch?v=cqvC7hGXy8Y) [Claude Desktop Data Leak](https://gatlingx.notion.site/Calendar-only-exfiltration-23e89dcc2f088029ade9e81e7d1c275f) [Claude Code Outlook Data Leak](https://www.youtube.com/watch?v=Wldae7-SN5E) [Confluence Insider Threat](https://www.youtube.com/watch?v=SpXUPto90IA)

[Blog](https://sealgate.ai/blog/) [Book a demo](https://cal.com/eito80/demo)

→

Codex

# Connect iMessage to Codex

Let Codex read, triage, and reply across iMessage, governed by SealGate and policy-checked on every call.

Part of the [iMessage setup guide](https://sealgate.ai/connect/imessage) , which covers every agent and how the connection works under the hood.

Paste this into your coding agent, or run it yourself in a terminal.

Agent prompt easier Terminal faster

## Set up Codex for iMessage, step by step

- 1 ### Create your SealGate account from this link If you do not already have a SealGate account, sign up at the link below. Starting there pre-approves the Beeper connector, so the install needs no dashboard approval afterward. https://dashboard.sealgate.ai/start/personal-messaging?utm_source=sealgate.ai&utm_campaign=seo-connect&utm_content=imessage-codex
- 2 ### Install the connector on your computer Run the installer in a terminal. It sets up the Beeper desktop app bridge and the sealgate-stdiod tunnel that carries your messaging apps to the SealGate gateway. Requires macOS or Windows with Beeper signed in. macOS / Linux Windows (PowerShell) curl -fsSL https://sealgate.ai/install-beeper.sh | SEALGATE_UTM_CAMPAIGN=seo-connect SEALGATE_UTM_CONTENT=imessage-codex bash $env:SEALGATE_UTM_CAMPAIGN='seo-connect'; $env:SEALGATE_UTM_CONTENT='imessage-codex'; powershell -ExecutionPolicy Bypass -Command "irm https://sealgate.ai/install-beeper.ps1 | iex"
- 3 ### Add SealGate to Codex Register the gateway as a streamable HTTP MCP server, then log in. The login opens your browser for OAuth, and codex mcp list should show sealgate afterwards. codex mcp add sealgate --url https://mcp.sealgate.ai/mcp codex mcp login sealgate
- 4 ### Approve the connector if you skipped the signup link If you signed up through the link above, Beeper is already approved. Otherwise open the SealGate dashboard, approve it once, and decide whether Codex may send messages or only read them.
- 5 ### Ask Codex to work with your messages Start a Codex session and ask for something concrete. Codex calls the messaging tools through SealGate, and every call is policy-checked and logged. Summarize my unread message threads and draft replies for me to approve

Please help me connect iMessage to Codex through SealGate on my machine. If I do not already have a SealGate account, have me sign up at https://dashboard.sealgate.ai/start/personal-messaging?utm_source=sealgate.ai&utm_campaign=seo-connect&utm_content=imessage-codex first, since starting there pre-approves the Beeper connector. Then follow the setup steps at https://sealgate.ai/connect/imessage/codex.md and stop whenever I need to act myself: approving this device in the browser when the installer asks, and, only if I already had an account, approving the Beeper connector in the SealGate dashboard.

Requires macOS or Windows (Linux is experimental) with the Beeper desktop app installed.

## Connecting Codex

Codex adds the SealGate gateway as an MCP server in its configuration, so it can call your messaging tools straight from the terminal as you work. See the [Codex setup guide](https://sealgate.ai/docs/getting-started) for the exact steps.

## What Codex can do with iMessage

- Triage unread texts and draft replies in your own voice for you to send.

- Summarize a long thread so you catch up in seconds.

- Find that address, link, or photo someone texted you weeks ago.

- Turn a text conversation into a task or calendar note.

Ready to let Codex handle your iMessage? Paste the setup prompt into your coding agent and you are connected in a couple of minutes.

Copy setup prompt [New to SealGate? Create your account first](https://dashboard.sealgate.ai/start/personal-messaging?utm_source=sealgate.ai&utm_campaign=seo-connect&utm_content=imessage-codex)

## A Codex session on your iMessage inbox

This is what a working setup looks like. Codex sees the connector as a set of beeper_* tools behind the SealGate gateway, finds the unread threads, drafts a reply, and stops for approval before anything is sent. The tool names, parameters, and call order are real; the contacts and message text are illustrative.

> Summarize my unread iMessage threads and draft replies for me to approve

* beeper_search_chats {"unreadOnly": true, "limit": 20}
3 chats: Mum, Priya Shah, Weekend ride (group)
* beeper_list_messages {"chatID": "imessage:priya"}
* beeper_search_messages {"chatIDs": ["imessage:priya"], "query": "invoice"}
* beeper_get_chat {"chatID": "imessage:weekend-ride"}

Summary
1. Mum: asks if you are coming on Sunday. Unanswered since yesterday.
2. Priya Shah: sent the revised invoice and wants confirmation it is correct.
3. Weekend ride: six messages settling on 8am at the bridge.

Draft reply to Priya Shah:
Got it, the revised invoice looks right. I will pay it today.

Send this with beeper_send_message? [y/N] y

* beeper_send_message {"chatID": "imessage:priya", "text": "Got it, the revised invoice looks right. I will pay it today."}
SealGate policy: allowed. Call logged.
* beeper_set_chat_reminder {"chatID": "imessage:mum", "reminder": {"remindAtMs": 1756835200000}}
Reminder set so you answer Mum tonight.

## Codex iMessage bridges compared

Most Codex iMessage bridges on GitHub take the same shape: a small MCP server on one Mac that reads ~/Library/Messages/chat.db directly and sends through the Messages app. That gets a local Codex session talking to your texts quickly, and it is worth knowing where the two routes differ before you pick one.

The SealGate route replaces the direct database read with the Beeper connector and the sealgate-stdiod tunnel, and puts the gateway between Codex and the send tool. Four differences matter in practice.

- What SealGate holds: a chat.db bridge reads your local Messages database directly. With SealGate only tool calls travel through the tunnel, and SealGate never stores your messages or credentials.

- Cloud agent support: a chat.db bridge serves the Codex CLI on that one Mac. The SealGate tunnel exposes the same connector to cloud-hosted agents through the gateway, so the setup is not tied to a single terminal.

- Send control: a chat.db bridge gives the agent unrestricted send once it is running. SealGate policy-checks every beeper_send_message call, and you can make the connector read-only for Codex while leaving sends on for another agent.

- Audit log: a chat.db bridge leaves whatever the process happens to print locally. SealGate records every tool call (which tool, when, which agent) in an audit trail without storing message content.

## Config reference

codex mcp add writes this block to ~/.codex/config.toml. You can add it by hand instead, then run codex mcp login sealgate to complete the OAuth login.

To skip the browser login, for example in a script or on a headless machine, use the API-key form of the URL with a key from your SealGate dashboard: url = "https://mcp.sealgate.ai/mcp/{api_key}/?client=codex". Treat that key like a password; it grants whatever the connector policy allows.

The companion repo walks through the same setup end to end: https://github.com/Edison-Watch/codex-imessage

[mcp_servers.sealgate]
url = "https://mcp.sealgate.ai/mcp"

## Why connect iMessage through SealGate

One setup for every app, works with cloud and mobile agents, fully governed and logged, and your messages are never stored.

### One setup, every network

The same command connects your whole unified inbox, so you are not wiring up a separate bridge for each app.

### Works with cloud and mobile agents

A local daemon tunnels the connector out, so ChatGPT, Claude, and other cloud agents can use it, not just CLI tools.

### Governed and logged

Every tool call runs through SealGate policies and lands in an audit trail that records only metadata, never your message content, so access stays under your control.

### SealGate never stores your messages

Message content only passes through in transit to be checked against your policies, and is never stored or read by anyone at SealGate.

## Related guides

[Connect ChatGPT to iMessage](https://sealgate.ai/connect/imessage/chatgpt) [Claude on iMessage](https://sealgate.ai/connect/imessage/claude) [Connect OpenCode to iMessage](https://sealgate.ai/connect/imessage/opencode) [Devin on iMessage](https://sealgate.ai/connect/imessage/devin) [iMessage to GitHub Copilot](https://sealgate.ai/connect/imessage/copilot) [Connect Grok to iMessage](https://sealgate.ai/connect/imessage/grok) [iMessage to Grokbot](https://sealgate.ai/connect/imessage/grokbot) [Hermes on iMessage](https://sealgate.ai/connect/imessage/hermes) [Use OpenClaw with iMessage](https://sealgate.ai/connect/imessage/openclaw) [Use Lovable with iMessage](https://sealgate.ai/connect/imessage/lovable) [Replit on iMessage](https://sealgate.ai/connect/imessage/replit) [Muse on iMessage](https://sealgate.ai/connect/imessage/muse) [Town on iMessage](https://sealgate.ai/connect/imessage/town) [Connect Codex to WhatsApp](https://sealgate.ai/connect/whatsapp/codex) [Codex on Telegram](https://sealgate.ai/connect/telegram/codex) [Use Codex with LinkedIn DMs](https://sealgate.ai/connect/linkedin/codex) [Connect Codex to Signal](https://sealgate.ai/connect/signal/codex) [Use Codex with Instagram DMs](https://sealgate.ai/connect/instagram/codex) [Codex on Messenger](https://sealgate.ai/connect/messenger/codex) [Connect Codex to X DMs](https://sealgate.ai/connect/x/codex) [Connect Codex to Discord DMs](https://sealgate.ai/connect/discord/codex) [Connect Codex to LINE](https://sealgate.ai/connect/line/codex) [All iMessage setups](https://sealgate.ai/connect/imessage) [SealGate vs other MCP gateways](https://sealgate.ai/comparison)

## Connecting iMessage to Codex: FAQ

Can Codex read and send iMessage messages? Yes. Codex adds the SealGate gateway as an MCP server, which lets it use your iMessage tools. Because it runs on your own machine, you can work with iMessage straight from the terminal while you code.

Do I need a Mac? iMessage runs on Apple's network, so connecting it through the Beeper desktop app needs an Apple device signed in to iMessage. Once connected, any agent you point at it can use it.

Where do my messages go? Your iMessage history and login are never stored on SealGate's servers. When your agent makes a call, the request and response route through SealGate to be policy checked in memory, and only metadata about the call is logged (which tool ran, when, and which agent ran it). SealGate never stores the message content itself.

What does SealGate store about my messages? SealGate routes each tool call to your connector and back, holding the request and response in memory only long enough to apply your policies, then discarding them. That check is automated: the gateway inspects the traffic programmatically to enforce your rules, and no one at SealGate can read your messages. They are never persisted and never used to train any model. SealGate keeps only call metadata (which tool ran, when, and which agent ran it), never the tool-call parameters or results, so your conversations and who you are talking to are never stored on SealGate's servers.

Can the agent send texts, or only read them? Both. You decide through SealGate policies whether a given agent can only read, or can also send, and every send is recorded in the audit log as metadata (that it happened, when, and by which agent), never the text of the message itself.

Want the full walkthrough? Read the [documentation](https://sealgate.ai/docs/) or email [hello@sealgate.ai](mailto:hello@sealgate.ai) .

### Contact Us

SealGate (GPU-EVM LTD)

3rd Floor, 86-90 Paul Street

London EC2A 4NE

Email: hello@sealgate.ai

### Legal

[Terms of Service](https://sealgate.ai/terms-of-service) [Privacy Policy](https://sealgate.ai/privacy-policy) [Subprocessors](https://sealgate.ai/subprocessors) [Delete your account](https://sealgate.ai/account-deletion) [Data Processing Addendum](https://sealgate.ai/dpa)

### Quick Links

[Home](https://sealgate.ai/) [Product](https://sealgate.ai/product) [Pricing](https://sealgate.ai/pricing) [For developers](https://sealgate.ai/dev) [Self-hosting](https://sealgate.ai/self-hosting) [Chrome extension](https://sealgate.ai/chrome) [Security](https://sealgate.ai/security) [Comparison](https://sealgate.ai/comparison) [For your team](https://sealgate.ai/for) [About](https://sealgate.ai/about) [Contact](https://sealgate.ai/contact) [Brand](https://sealgate.ai/brand) [Press](https://sealgate.ai/press) [Docs](https://sealgate.ai/docs/) [Developer docs](https://sealgate.ai/docs/developers) [Guides](https://sealgate.ai/guides/) [MCP gateway guide](https://sealgate.ai/guides/mcp-gateway) [Blog](https://sealgate.ai/blog/)

### Connect

[Connect AI to messaging](https://sealgate.ai/connect) [WhatsApp](https://sealgate.ai/connect/whatsapp) [iMessage](https://sealgate.ai/connect/imessage) [Telegram](https://sealgate.ai/connect/telegram) [LinkedIn DMs](https://sealgate.ai/connect/linkedin) [Signal](https://sealgate.ai/connect/signal) [Instagram DMs](https://sealgate.ai/connect/instagram) [Messenger](https://sealgate.ai/connect/messenger) [X DMs](https://sealgate.ai/connect/x) [Discord DMs](https://sealgate.ai/connect/discord) [LINE](https://sealgate.ai/connect/line) [Beeper](https://sealgate.ai/beeper)

### Follow Us
