@jbaehova/cic
v0.1.3
Published
Cursor-in-Codex: use Cursor subscription models from Codex while cic is running
Readme
cic
cic (Cursor-in-Codex) is a small standalone proxy that makes models from a Cursor subscription available in the Codex model picker. It changes Codex only while cic ensure is active; cic stop restores the original Codex configuration and model cache.
Requirements
- Node.js 20 or newer
- A Cursor subscription
- An installed
codexCLI - macOS, Linux, or Windows
Install
npm install -g @jbaehova/cic
cic login
cic ensureRestart already-open Codex App or CLI processes after ensure or stop, because they can retain the old model catalog in memory.
Commands
cic login
cic ensure
cic status [--json]
cic stop
cic logoutlogin prints the Cursor PKCE URL and attempts to open it in the default browser. ensure starts a detached localhost daemon without installing a boot service. stop verifies the private daemon nonce and command identity before stopping it, then reverses only CIC-owned Codex changes. The health endpoint exposes only a nonce hash. logout first completes stop, then removes only the Cursor tokens.
Model allowlist
The first successful login writes all live-discovered logical models to ~/.cic/config.toml. Later logins preserve the file. Edit the models array and run cic ensure again to resynchronize the picker.
version = 1
port = 10101
models = [
"cursor/grok-4.6",
"cursor/grok-4.6-fast",
]If an allowlisted model disappears from Cursor discovery it is reported by cic status and omitted from the picker. CIC refuses to alter Codex when none of the configured models is available.
Security boundaries
Cursor tokens are stored unencrypted in ~/.cic/auth.json, atomically written with user-only permissions. CIC does not use Keychain or another credential manager. The daemon binds only to 127.0.0.1.
The localhost Responses endpoint shares the signed-in user's Codex credentials for native passthrough, so the host account is the trust boundary: do not run CIC on a shared or untrusted OS account. The shutdown nonce is kept only in the user-private state directory and is never returned by /healthz.
Cursor-native shell, file, delete, fetch, GUI, and direct external-MCP execution are always disabled. Cursor receives only synthetic tool definitions; requested tool calls return to Codex as Responses tool-call items so Codex retains approval and sandbox control. Prompts, tool inputs/outputs, and tokens are never written to CIC logs.
CIC routes only cursor/* models to Cursor. Native models are passed through byte-for-byte to the original ChatGPT Codex or OpenAI API origin after the incoming credential type is unambiguous. Redirects cannot cross the selected credential origin.
Codex profile files that override routing, the catalog, or required multi-agent feature values are rejected before CIC changes anything. Remove those overrides or run Codex without that profile while CIC is active.
Recovery
Codex config, custom catalog, and cache changes use a write-ahead journal with preimage/postimage hashes. Symlinked Codex files remain symlinks and existing file modes are preserved. When no unrelated changes occurred, stop restores the original bytes exactly. If unrelated edits occurred, it removes only verified CIC fragments. A changed CIC-managed key is not overwritten; status reports the conflict and CIC saves a backup under ~/.cic/backups.
No OpenCodex package, process, config, authentication, or runtime dependency is used by CIC.
Verification
Run the deterministic suite with npm test. The optional live Grok 4.6 Fast xhigh end-to-end smoke test requires an explicit test token and never prints it:
CIC_CURSOR_TEST_TOKEN=... npm run smoke:cursorBefore release, manually verify login → ensure → Cursor/native model use → stop on macOS, Linux, and Windows as described in PLAN.md.
