Codex 0.160.0 resumes queued messages after reconnect: Sume key rule
Codex 0.160.0 resumes unsent queued messages after a reconnect without duplicates. A paid Sume call still needs its own idempotency_key to be safe.

Codex 0.160.0 does not remove the need for an idempotency_key on Sume paid calls. Its changelog entry for October 1-2, 2026 says unsent queued messages resume after reconnection once uncertain submissions resolve, avoiding duplicates. That protects the message queue in the client. A tool call that already left the machine and reached Sume is a separate event, and only a key on the call can make Sume treat a repeat as the same request.
What each layer covers
The Codex fact comes from the Codex changelog (read 2026-10-07). The Sume rules come from MCP tools and gates and Jobs and results.
A dropped connection
The table walks through a dropped connection in the middle of a paid call.
| Layer | What it knows | What it can stop |
|---|---|---|
| Client message queue | Which messages were sent | A repeated chat message |
| Tool call already sent to Sume | Nothing, if the reply was lost | Needs the key on the call |
Sume idempotency_key | The key and the original job | A second paid job for the same intent |
After a reconnect
After a reconnect, the safe sequence is:
- Do not make the paid call again from a fresh prompt. Look up the job first with
jobs_listorjobs_statusif you kept an id. - If you have no id, repeat the call with the same
idempotency_key. Sume returns the original job and reports a hit instead of billing twice. - If the key matches but the body is different, expect a 409 conflict. Fix the body or use a new key on purpose.
Where the key should come from
Make the key from the business event, such as an order id plus a version, so that a fresh session produces the same key for the same intent. A random value made inside the model turn will differ after a resume.
Sources
Related posts
More in Agents
- Codex keeps your computer on reconnect: find Sume jobs first
Codex CLI 0.161.0 keeps a new task on the selected computer while it reconnects or is offline. After a gap, list Sume jobs before you resubmit any paid call.
- Cursor iOS remote control for local agents: keep paid Sume calls safe
Cursor can now show and answer local agents from its iOS app. If one holds Sume MCP, grant read-only, send dry_run first, and cap max_spend_usd.
- Build a run status chip from the Format events phase timeline
Sume has no SSE stream for Format runs. Poll status_url and events_url to show queued, preparing, running and finalizing in your UI without faking progress.
- Stop an AI video agent overspending: the four Sume spend gates
An unattended Sume agent can only spend what four gates allow: the wallet, a per-run cap, a schedule ceiling, and a Format cap. Values and failure codes inside.
Written by Sume