OpenAI Codex
Also known as: Codex CLI
OpenAI's agentic coding system across desktop, CLI, IDE, web, cloud and remote, with an OS-enforced sandbox and independent approval policy, Auto-review, skills and plugins, browser and computer use, and OpenTelemetry audit export.
Codex is OpenAI's agentic coding system, an umbrella for a family of surfaces that share a single account context. Relaunched in 2025 and substantially rebuilt since, it is designed not to autocomplete lines but to act as an agent: it reads a codebase, plans an approach, edits files across the project, runs shell commands and tests, and proposes finished pull requests, sustaining long autonomous sessions across many sequential tool calls.
Developers can reach Codex wherever they work. The Codex CLI is a terminal-native agent, open source and built in Rust, that runs locally, edits and runs code in a chosen directory, and ships with structured plan, execute, and review commands plus sandboxed execution and approval modes you control.
An IDE extension brings the same agent into editors like VS Code, Cursor, and Windsurf, and a cloud agent, reachable through ChatGPT, runs tasks asynchronously in isolated sandboxed containers preloaded with your repository, so many tasks proceed in parallel.
A macOS desktop app acts as a command center for running agent threads side by side, and a remote mode lets you kick off and approve work from a phone.
Around the core loop, Codex adds higher-level workflows. Skills extend it beyond code into tasks like code understanding, prototyping, and documentation aligned to a team's standards; Automations let it pick up routine work such as issue triage, alert monitoring, and CI without being asked; and a separate review agent can check changes before they are committed. An AGENTS.md file in a repository tells Codex how to navigate the code, run tests, and follow project conventions, much like a README for the agent.
Codex is powered by OpenAI's frontier GPT models, trained with an agentic focus so the model handles multi-step tool use and self-checks its work before submitting, and local clients can also be pointed at other providers' models, such as Mistral's API or a local Ollama endpoint.
It supports the Model Context Protocol for connecting external tools, including parallel tool calls, and runs work inside sandboxed environments while letting users verify output through citations, logs, and test results.
It is included with ChatGPT plans from Free and Go upward rather than sold as a separate product, can also be used through an API key billed per token, and is used by individual developers and large engineering organizations alike.
Vendor details
Canonical URL
https://learn.chatgpt.com/codex
Category
Coding agent
Company status
first party product
Use cases & customers
Target customers
Deployment options
Integrations
MCP client support with enterprise approved server lists, plus a Codex MCP Server, App Server and SDK for building on the harness. Documented third party integrations for GitHub, GitLab in beta, Slack and Linear, a GitHub Action and non-interactive mode for CI, hooks firing on lifecycle events, Site tools via WebMCP, and plugins and connectors whose destructive tool calls require approval. The agent runs shell commands under an OS enforced sandbox, uses a web search tool with cached, indexed, live or disabled modes, and has documented Browser and Computer use capabilities plus a browser extension.
In practice
You want to hand off a refactor and keep coding instead of babysitting it. Codex's cloud agent runs the task asynchronously in an isolated sandbox preloaded with your repo, then proposes a pull request for review.
You live in the terminal and don't want a browser or IDE in the loop. The open-source Codex CLI runs the agent locally, editing files and running tests in your chosen directory with approval modes you control.
You want routine work handled without prompting it each time. Codex Automations pick up issue triage, alert monitoring, and CI tasks on their own, while a separate review agent checks changes before they're committed.
Sources & related URLs
Related / legacy domains
Agentic Index coverage score
13.0 / 14 capabilities · 93%
| Integrations & Tool Calling | Full |
|---|---|
|
MCP connects external services with approved server lists under enterprise control, plugins and connectors extend the agent with side effecting tool calls that require approval when they advertise destructive annotations, and documented third party integrations cover GitHub, GitLab, Slack and Linear; the agent runs shell commands under an OS sandbox, uses a web search tool with cached, live and disabled modes, and reaches the browser and computer use surfaces. Sourcelearn.chatgpt.com/codex/extend/mcp, /codex/third-party and /codex/agent-approvals-securityread 2026-08-30 |
|
| Workflow Orchestration | Full |
|
The agent sustains long autonomous sessions across many sequential tool calls, with configurable subagents, git worktrees for parallel work, projects and chats organizing multi step work, long running work and scheduled tasks documented, and the desktop app running agent threads side by side; the cloud agent works asynchronously in isolated containers so many tasks proceed in parallel, and multi agent tooling is listed among stable CLI surfaces. Sourcelearn.chatgpt.com/codex/agent-configuration/subagents, /codex/environments/git-worktrees and /codex/long-running-workread 2026-08-30 |
|
| Knowledge Grounding & RAG | Partial |
|
Context is assembled per run: the agent reads the repository, resolves @ mentioned files, calls MCP servers for external sources and uses a web search tool whose cached mode draws on an OpenAI maintained web index. AGENTS.md and Rules are instructions the product applies rather than a knowledge source. No maintained retrieval structure over the customer's own code or documents is documented. Sourcelearn.chatgpt.com/docs/agent-configuration/agents-md, /docs/extend/mcp and the docs llms.txt indexread 2026-09-29 |
|
| Human Oversight & Guardrails | Full |
|
Two independent layers govern the agent: sandbox mode controlling what it can technically do, and approval policy controlling when it must ask, with presets from read-only through workspace-write to danger-full-access and a granular policy that keeps chosen approval categories interactive while auto rejecting others. An Auto-review reviewer agent can evaluate eligible approval requests against a published policy checking for data exfiltration, credential probing, security weakening and destructive actions, failing closed on parse or session errors. Destructive MCP and app tool calls always require approval,.git,.agents and.codex are protected read-only inside writable roots, and enterprise managed requirements override local settings. Sourcelearn.chatgpt.com/codex/agent-approvals-security and /codex/sandboxing/auto-reviewread 2026-08-30 |
|
| Security, Identity & Governance | Full |
|
trust.openai.com lists SOC 2 Type 2, SOC 3, ISO/IEC 27001, 27017, 27018, 27701 and 42001, CSA STAR and FedRAMP 20x, with the SOC 2 report scoped to the API Platform, ChatGPT Enterprise, ChatGPT Edu and ChatGPT Team, the plans and API key path Codex runs on; the portal does not name Codex separately. The access surface is documented: managed configuration that overrides local settings, roles and workspace permissions, SCIM and EKM on Enterprise, workload identity federation, service accounts, plugin, connector and skill controls, approved MCP server lists, a Compliance API with audit events, Private Link, IP allowlisting and mutual TLS. Sourcetrust.openai.com and learn.chatgpt.com/docs/enterprise/managed-configurationread 2026-09-29 |
|
| Observability & Auditability | Full |
|
Opt in OpenTelemetry export emits a documented event catalog including codex.tool_decision recording approved or denied and whether the source was configuration or the user, codex.tool_result with duration, success and output snippet, codex.api_request, codex.sse_event and codex.user_prompt, with counter and duration histogram metrics, exportable to a customer controlled collector over OTLP; enterprise adds a Compliance API and audit events, workspace analytics and an Analytics API. Telemetry is off by default and prompt text is redacted unless explicitly enabled. Sourcelearn.chatgpt.com/codex/agent-approvals-security and /codex/enterprise/compliance-apiread 2026-08-30 |
|
| Memory & State Persistence | Full |
|
Codex writes its own memories: once enabled, it turns useful context from eligible prior chats into local memory files under CODEX_HOME, redacting secrets and updating in the background after a chat goes idle. Scope is stated (the local Codex home, with /memories choosing per chat whether a chat may read existing memories or feed future ones, and managed configuration able to pin the feature on or off), lifetime is stated (memories.max_unused_days, default 30 and clamped to 365, retires unused memories from consolidation; memories.max_rollout_age_days bounds the chats considered), and the files are inspectable for review. Off by default. AGENTS.md holds rules rather than memory. Sourcelearn.chatgpt.com/docs/customization/memories and /docs/config-file/config-referenceread 2026-09-29 |
|
| Deployment & Data Residency | Full |
|
Local environments run entirely on the developer's machine through the CLI, IDE extension and desktop app under an OS enforced sandbox using Seatbelt on macOS, bwrap and seccomp on Linux and a native Windows sandbox or WSL2, with dev container support and a published secure devcontainer reference; cloud environments run in isolated OpenAI managed containers with configurable internet access and domain allow lists. Enterprise adds Private Link, IP allowlisting, mutual TLS, IP egress ranges and Amazon Bedrock as a model provider. Sourcelearn.chatgpt.com/codex/environments/modes, /codex/agent-approvals-security and /codex/amazon-bedrockread 2026-08-30 |
|
| Prebuilt Agents, Templates & Packs | Full |
|
Skills and plugins are first class extensibility surfaces with dedicated build guides, a plugin architecture and submission path, enterprise plugin management, plugin controls and skill controls for administering approved catalogs, and documented support for submitting a Claude Code plugin; subagents are configurable per project and Codex Micro ships as a packaged capability. Sourcelearn.chatgpt.com/codex/skills-and-plugins, /codex/build-plugins and /codex/enterprise/plugin-managementread 2026-08-30 |
|
| Triggers & Channel Coverage | Full |
|
Codex runs in the ChatGPT desktop app, a Codex CLI, an IDE extension, ChatGPT on the web, Codex cloud, and a Remote mode driven from a phone, with scheduled tasks running work on a timetable, long running work supported, a GitHub Action and non-interactive mode for CI, and documented third party integrations for GitHub, GitLab in beta, Slack and Linear; notifications close the loop. Sourcelearn.chatgpt.com/codex/automations, /codex/github-action and /codex/third-partyread 2026-08-30 |
|
| Model Flexibility & Routing | Full |
|
The customer chooses the model maker. Local Codex clients accept custom model providers in config.toml, each defined by base URL, wire API and authentication, and the vendor's own example configures Mistral's API and a local Ollama endpoint beside an OpenAI proxy; OSS mode runs Codex against a local open source provider, Ollama or LM Studio, chosen per run with --local-provider or set as the default. Within OpenAI's own family the model is selectable per session and per workspace. Amazon Bedrock is a built-in provider serving OpenAI models on AWS, which is a hosting choice rather than a different model maker. Sourcelearn.chatgpt.com/docs/config-file/config-advanced (Custom model providers, OSS mode) and /docs/modelsread 2026-09-29 |
|
| APIs, SDKs & MCP Extensibility | Full |
|
A Codex SDK, an App Server, an MCP Server, a GitHub Action and a non-interactive mode are all documented build surfaces, alongside MCP client support with approved server lists, hooks firing on lifecycle events, Site tools via WebMCP, Record and Replay, and a Python SDK with auth; the CLI is open source in Rust at github.com/openai/codex with a published default reviewer policy, and the docs expose an llms.txt index and markdown versions of every page. Sourcelearn.chatgpt.com/codex/codex-sdk, /codex/mcp-server and /codex/open-sourceread 2026-08-30 |
|
| Testing, Debugging & Optimization | Partial |
|
Codex reviews code changes before commit, a Codex Security plugin and CLI run scans, deep scans and bulk scans in CI with a security workbench and finding export, and the agent runs tests and iterates on failures; Auto-review evaluates individual agent actions against a risk policy at runtime. These verify the customer's code and gate the agent's actions rather than providing a harness to evaluate, replay or regression test agent behavior itself. Sourcelearn.chatgpt.com/codex/code-review and /codex/securityread 2026-08-30 |
|
| Browser & Computer Use | Full |
|
Browser and Computer use are documented capabilities with dedicated pages, alongside a browser extension for signed in browser workflows and Appshots; the security documentation treats browser and Computer Use activity as a distinct traffic surface outside the command network proxy, requiring its own feature settings and workspace policies, and managed configuration lets administrators set feature requirements for browsers and Computer Use. Sourcelearn.chatgpt.com/codex/computer-use, /codex/browser and /codex/agent-approvals-securityread 2026-08-30 |
|
The Agentic Index coverage score grades every vendor Full, Partial or Not documented against the same 14 buyer facing capabilities, from public evidence only. Each capability links to how all vendors in the index score on it. How this evidence is graded
Recent platform changes
OpenAI shipped GPT-6.1 Sol into Codex on desktop and CLI, describing it as near top tier performance at lower cost for long running work, and made it the default model in the CLI. It is also available through Amazon Bedrock, and is off by default for Enterprise and Edu until an admin turns it on.
Bears on: Agent capability
View sourceCodex CLI 0.156.0 added worktree session creation and task status filtering in the agent command center, with worktree support enabled by default. Its new /usage dashboard shows account consumption and plugin and skill activity, including credit and token reports for Business and Enterprise accounts. The release also enables voice conversations by default and bundles audio runtimes for Linux and Windows.
Bears on: Observability / auditability
View sourceOpenAI released Codex 0.155.0 with experimental voice conversations, live reasoning summaries and task management for agents. It also adds Touch ID verification for MCP requests on supported Macs.
Bears on: Agent capability
View sourcePricing
Included in ChatGPT plans: Free $0 and Go $8 a month (GPT-6 Luna in the desktop app, subject to rollout), Plus $20, Pro from $100 ($100, $200 or $500), Business $20 per user a month billed annually ($25 monthly); Enterprise and Edu through sales; or pay per token with an API key
quota + usage beyond quota
Included quota
Included Codex usage scales with the ChatGPT plan tier (Plus vs Pro vs Business); exact task/credit allowances vary by plan and OpenAI's current rate card.
What is public
The Codex pricing page lists every plan: Free $0 and Go $8 a month with GPT-6 Luna in the desktop app subject to rollout; Plus $20 with Codex on the web, CLI, IDE extension and iOS; Pro from $100 a month in $100, $200 and $500 tiers, the top tier adding Astra Ultrafast; Business $20 per user a month billed annually for two or more users, $25 monthly; Enterprise and Edu through sales with SCIM and EKM; and an API key path billed at API pricing. Plus and Business extend usage with ChatGPT credits, and ChatGPT Work shares the same pricing, credits and limits as Codex.
Billing mechanics
Bundled-subscription plus usage. A ChatGPT plan includes a quota of Codex usage; beyond that, usage is metered against the plan's credits or OpenAI's API rate card. The Codex CLI is open-source and can run BYO-key against the API.
Cost watchouts
Agent-heavy or long-running tasks can drive metered usage well above the base ChatGPT plan cost.
Variable cost rationale
Bundled subscription plus metered/API usage with no hard cap makes spend highly usage-dependent.
Additional watchouts
There's no clean per-seat 'Codex price' - effective cost is the ChatGPT plan you're on plus whatever metered/API usage your agent workloads incur.
Overage / add-ons
Beyond plan-included usage, additional Codex/agent usage is metered (plan credits or API pay-as-you-go).
Sales call required
No, self serve available
Free / trial
ChatGPT Free includes Codex in the desktop app on GPT-6 Luna at Standard speed, subject to rollout
Lowest paid plan
ChatGPT Go $8 a month
Commercial notes
No standalone Codex plan; access rides on ChatGPT Free, Go, Plus, Pro, Business, Enterprise or Edu, or an API key billed per token. Pro is now three tiers from $100.
Key ambiguities
Codex's included quota and credit behavior change by ChatGPT plan and OpenAI's evolving rate card, so a single entry price isn't representative.
Cancellation / refund
Billed via the underlying ChatGPT subscription; standard OpenAI subscription terms.
Missing data
Per-plan Codex quotas and exact metered rates are not transparently consolidated in one public figure.
Related vendors
- Cognition — Maker of Devin, an autonomous AI software engineer
- 10Web — Agentic website platform whose specialized AI agents build, host,…
- AgentUI — Managed AI app builder for operations teams that generates and hosts…
- Aider — Open source, model agnostic terminal coding agent that edits your…
- Anthropic Claude Code — Anthropic's agentic coding system across terminal, desktop, IDE, web…
- AppFactor — Agentic platform that runs persistent agents across an enterprise…
Alternatives to OpenAI Codex
The closest documented capability profiles to OpenAI Codex among coding agents tracked by Agentic Index, ordered by similarity on the same 14 point evidence the rankings use. No vendor pays for placement.
- Cursor12.5 / 14A lighter documented profile than OpenAI CodexOpenAI Codex vs Cursor →
- GitHub Copilot13.5 / 14Fuller documented coverage on Knowledge Grounding & RAGOpenAI Codex vs GitHub Copilot →
- Google Antigravity12.5 / 14A lighter documented profile than OpenAI Codex
- OpenHands13.5 / 14Fuller documented coverage on Testing, Debugging & Optimization
- Cline12.0 / 14A lighter documented profile than OpenAI Codex
- Cognition13.0 / 14Fuller documented coverage on Knowledge Grounding & RAGOpenAI Codex vs Cognition →
Similarity is computed from each vendor's Agentic Index coverage score evidence, axis by axis, not from the totals. How this evidence is graded