langsmith-codex-plugins marketplace ships a tracing plugin that sends OpenAI Codex session data to LangSmith. Use it to inspect agent turns, model metadata, token usage, tool calls, and subagent threads from your Codex workflows.
Prerequisites
Before setting up tracing, ensure you have:- Node.js 22.x or later.
- Codex CLI v0.153.4 or later, with synchronous
UserPromptSubmitplugin hooks enabled and trusted. - A LangSmith API key.
Install and enable the plugin
Add the marketplace using the Codex CLI:~/.codex/config.toml, or only for a specific project in .codex/config.toml:
/hooks, or in Codex’s plugin UI when prompted. Enabling the plugin alone does not trust its hooks.
Configure tracing
Tracing is disabled until eitherTRACE_TO_LANGSMITH is "true" or enabled is true in a config file. Configure credentials with environment variables, a JSON config file, or both.
Environment variables
The plugin reads Codex-specific variables first, then falls back to the generic LangSmith SDK variables.
Add the variables to your shell configuration file (
~/.zshrc, ~/.bashrc, or ~/.bash_profile):
Config file
Use<project>/.codex/langsmith.json for project-level settings or ~/.codex/langsmith.json for global defaults. The global file loads first, the project file overrides it, and matching environment variables take precedence over both.
Keep config files that include API keys out of version control.
Trace to multiple destinations
Setreplicas in langsmith.json or LANGSMITH_CODEX_RUNS_ENDPOINTS to send the same trace data to additional LangSmith workspaces or projects. When set, the replica list overrides the other client settings.
Tracing to multiple replicas is useful for:
- Sending traces to both a production and staging project.
- Tracing to multiple workspaces with different API keys.
- Adding extra metadata to specific replica destinations.
- Config file (recommended)
- Shell environment variable
In
<project>/.codex/langsmith.json or ~/.codex/langsmith.json:Secret redaction
The plugin redacts detected secrets from run inputs, outputs, errors, and metadata before uploading them to LangSmith. Redaction is on by default. Redaction runs on your machine before upload, so unredacted content never reaches LangSmith. Replica destinations receive the same redacted payload. Detection covers provider API key prefixes, JSON Web Tokens, and PEM private key blocks. It also covers contextual shapes such asAPI_KEY=<value>, an Authorization header, and a password embedded in a URL. Each match is replaced with [SECRET_DETECTED]. For the rule list, see Redact secrets from traces.
Redaction matches known credential shapes, so treat it as a safety net rather than a guarantee. A credential in an unrecognized format still reaches LangSmith, and attachments, run names, and tags do not pass through the anonymizer. A redacted trace also still holds the prompts, file contents, and tool results it was built from, so restrict who can read the tracing project.
To turn redaction off, set LANGSMITH_CODEX_REDACT to false, 0, no, or off, or set "redact": false in a config file. Values are trimmed and compared case-insensitively.
To redact additional patterns, set LANGSMITH_CODEX_REDACT_EXTRA to a JSON array of { "pattern": ..., "replace": ... } rules, or set redact_extra_rules in a config file. Each pattern is a regular expression string, applied globally and case-sensitively. replace is optional and falls back to [redacted]. Extra rules run after the built-in ones.
redact_extra_rules to [] clears rules inherited from a lower-priority source. In a config file, one rule with an invalid regular expression discards every setting in that file, so verify the patterns before committing them.
Because a project-level .codex/langsmith.json or langsmith-plugins.json can set redact to false, review those files before enabling tracing in a repository you do not control.
What gets traced
Each LLM run includes:- Inputs: accumulated conversation messages.
- Outputs: assistant response content.
- Metadata: model provider, model name, stop reason, and token usage.
View traces in LangSmith
Open the configured LangSmith project and complete a Codex turn. By default traces appear in thecodex project. The plugin uploads completed Codex transcript data, including messages, tool call inputs and outputs, model metadata, token usage, and subagent thread structure.
Troubleshooting
If traces do not appear in LangSmith:- Confirm the tracing plugin is enabled in
config.tomland its hooks are trusted (/hooks).[features] hooksis on by default, so set it only to undo a local override. - Confirm
TRACE_TO_LANGSMITH=trueis visible to the Codex process. - Confirm
LANGSMITH_CODEX_API_KEYorLANGSMITH_API_KEYis set and valid. - If runs land in the wrong project, set
LANGSMITH_CODEX_PROJECTor theprojectconfig key. - If a custom endpoint is not used, set
LANGSMITH_CODEX_ENDPOINTor theapi_urlconfig key.
Connect these docs to your agent of choice via MCP for real-time answers.

