Codex
by OpenAI
OpenAI's coding agent, running across terminal, IDE, desktop, web, GitHub and Slack
Codex is OpenAI's agentic software-engineering product: an AI agent that reads a repository, plans, edits files, runs commands and tests, and opens pull requests. It runs from an open-source terminal CLI, IDE extensions, desktop and web apps, a GitHub code-review integration and Slack, sharing one account and task history across all of them.
Codex is OpenAI's agentic software-engineering product: a coding agent that reads a repository, plans a change, edits files, runs commands and tests, and opens pull requests, rather than an autocomplete model. The name is reused from OpenAI's 2021 code model; the current product dates from the Codex CLI released on 16 April 2025 and the cloud agent powered by codex-1, an o3 derivative tuned for software engineering, in May 2025. It now runs across a deliberately wide set of surfaces that share one account and one task history: an Apache-2.0 terminal CLI written largely in Rust, which is one of the most-starred repositories on GitHub at roughly 106,000 stars; extensions for Visual Studio Code, JetBrains and Xcode; desktop applications for macOS, Windows and Linux; a web interface; a GitHub code-review integration; and a Slack integration. Model support has moved quickly, through GPT-5.3-Codex in February 2026, the roughly fifteen-times-faster GPT-5.3-Codex-Spark, and on to GPT-5.4 and GPT-5.5. For enterprise deployment, OpenAI has published its security architecture: execution is isolated in container-based sandboxes, outbound networking is default-deny with pre-approved endpoint allowlists, every suggested command passes an approval layer, and agent-native telemetry logs every action into queryable audit trails, with administrators able to allow or block plugins across teams. A dedicated Codex Security agent shipped in March 2026 for vulnerability hunting, reportedly surfacing nearly 800 critical and over 10,000 high-severity issues in testing across major projects. Adoption passed two million weekly active developers in March 2026, and in July 2026 OpenAI merged Codex into the ChatGPT desktop application, signalling a pivot from developer tool toward a general enterprise agent surface.
An engineering leader standardising a coding agent across a team already on ChatGPT Business or Enterprise, who needs documented sandboxing, approval and audit controls rather than a developer-expensed IDE plugin.
One agent with shared task history across terminal, IDE, desktop, web, GitHub reviews and Slack, governed by admin-managed policy instead of per-developer configuration.
At a Glance
- Category
- Developer Tools
- Pricing
- Subscription, Usage-based, Freemium, Contact for pricing
- Target Market
- CTOs, VP Engineering, Enterprise Developers, Platform Engineers, Security Engineers
- Deployment
- Cloud-first, API-based, Open-source
- Founded
- 2015
- Headquarters
- San Francisco, United States
- Team Size
- 500+
- Customers
- 2M+ weekly active developers (March 2026)
Key Features
- ✓Multi-surface agent
The same agent and task history run from CLI, VS Code, JetBrains, Xcode, macOS/Windows/Linux desktop apps, web, GitHub and Slack.
- ✓Open-source Apache-2.0 CLI
The terminal client is Rust, public on GitHub at roughly 106,000 stars, so teams can inspect, build and pin it themselves.
- ✓Sandboxed execution with approvals
Container-based isolation from the host plus a per-command approval layer, so no change reaches a repository without a human gate.
- ✓Default-deny network policy
Outbound connections are blocked unless the endpoint is pre-approved, which limits data exfiltration and blast radius from a compromised dependency.
- ✓Agent-native telemetry
Every action the agent takes is logged into queryable audit trails, giving the evidence trail compliance reviews actually ask for.
- ✓Codex Security agent
A dedicated application-security agent shipped March 2026 that hunts vulnerabilities, reportedly finding nearly 800 critical issues in testing.
- ✓MCP plugin ecosystem
Reported at over 9,000 Model Context Protocol plugins, the largest in agentic coding, with admin allowlists and private marketplaces for enterprises.
Capabilities
Use Cases
- •Delegated feature implementation
Hand the agent a well-specified ticket and receive a pull request, with tests run in the sandbox before review.
- •Automated pull-request review
The GitHub integration reviews incoming changes and flags issues, adding a consistent first-pass reviewer on every PR.
- •Infrastructure and CI/CD maintenance
Terminal-shaped work such as pipeline fixes, IaC edits and dependency upgrades, which reviewers rate as its clearest strength.
- •Application-security triage
The Codex Security agent scans repositories for vulnerabilities and ranks findings, reducing the manual sweep before a release.
- •Codebase exploration and onboarding
New engineers ask the agent to trace how a subsystem works instead of reading through unfamiliar repositories unaided.
Ideal For
Best For
- ✓DevOps, infrastructure and CI/CD work, where reviewers consistently rate it strongest
- ✓Delegating well-specified implementation tasks to a cloud agent that returns a pull request
- ✓Automated pull-request review via the GitHub integration
- ✓Teams that want an inspectable, self-buildable open-source client rather than a closed IDE
- ✓Application-security triage using the dedicated Codex Security agent
Not Ideal For
- ✗Frontend and UI-heavy work — reviewers repeatedly report it struggling with React and UI optimisation where Anthropic's Opus models one-shot the same task
- ✗Large multi-file architectural refactors, where independent reviews say code quality trails Claude and behaviour becomes erratic in long sessions
- ✗Teams that need predictable monthly cost: billing moved from per-message caps to token credits on 2 April 2026, and even $200/month Pro users report hitting weekly limits
- ✗Organisations that cannot route source code to a third-party cloud, since there is no self-hosted or air-gapped deployment of the hosted models
Integrations
Deployment
Market & Ratings
2M+ weekly active developers (March 2026)
Market Analysis
Pros
- ✓One agent across CLI, IDEs, desktop, web, GitHub and Slack sharing account and task history — few competitors cover that many surfaces
- ✓Open-source Apache-2.0 client with very high release velocity (one review counted 553 releases in ten months) and the largest MCP plugin ecosystem, reported above 9,000
- ✓Measurably token-efficient: independent reviews put it 2-3x below Claude Code for comparable work, so the $20 tier stretches further
- ✓Strongest on terminal-shaped work — DevOps, infrastructure, CI/CD and straightforward implementation
- ✓Enterprise controls are documented rather than assumed: container sandboxing, default-deny egress with endpoint allowlists, per-command approval, queryable audit trails and admin-managed plugin allowlists
Cons
- ✗Weak on frontend and UI work — reviewers and community consensus put it clearly behind Claude's Opus models for React and UI optimisation
- ✗Instruction adherence is the standing complaint, summarised in one review as writing what it thinks you meant rather than what you actually said
- ✗Rate limits still bite: even $200/month Pro users report hitting weekly caps on GPT-5.4, and the earlier five-hour framing was widely reported as exhaustible in about an hour of real repository work
- ✗Code quality trails Claude on complex multi-file architectural changes, with behaviour described as erratic in extended sessions
- ✗The published controls do not stop a careless full-access run, a prompt injection, a malicious npm package stealing the Codex token, or a large autonomous change nobody fully reviews — and OpenAI's own framing concedes the approval layer is a velocity bottleneck, not a replacement for human oversight
- ✗Pricing has churned: per-message caps became token credits on 2 April 2026, making cost forecasting harder for finance teams
Pricing
Free
$0
- ✓Apache-2.0 Codex CLI
- ✓Trial-level cloud task access
- ✓No code reviews
Go
From $8/mo
- ✓Limited cloud tasks
- ✓Codex CLI and IDE extensions
Plus
From $20/mo
- ✓10-60 cloud tasks per 5-hour window
- ✓20-50 code reviews per 5-hour window
Pro
From $100/mo
- ✓5x Plus usage at $100, roughly 20x at $200
- ✓50-1,200 cloud tasks per 5-hour window
- ✓100-1,000 code reviews per 5-hour window
Business
From $20/user/mo
- ✓SSO and MFA
- ✓Dedicated workspace
- ✓No training on your data
- ✓Purchasable workspace credit add-ons
Enterprise
Contact for pricing
- ✓Shared credit pool with no fixed rate limits
- ✓SCIM provisioning
- ✓Role-based access control
- ✓Data residency controls
The Codex client itself is free and Apache-2.0; what you pay for is model access, and it is bundled into every ChatGPT plan rather than sold separately — Free $0, Go $8, Plus $20, Pro $100 for roughly 5x Plus usage or $200 for roughly 20x, Business per seat, Enterprise custom. Since 2 April 2026 OpenAI meters Plus, Pro and Business on token-based credits instead of per-message caps, with a typical task consuming roughly 5-45 credits depending on context size and mode, which makes forecasting harder than the old fixed limits. Business adds SSO, MFA, a dedicated workspace and a no-training-on-your-data guarantee; Enterprise replaces fixed limits with a shared credit pool and adds SCIM, RBAC and data-residency controls. Calling the Codex models directly through the API is billed separately per token. Rate limits remain the standing cost complaint: independent reviews report even $200/month Pro users hitting weekly caps on GPT-5.4.
Security & Compliance
Connect
Sources
This page was written from 6 sources, 6 on domains other than openai.com.
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Raindrop
AI agent monitoring that catches silent production failures: Sentry for AI agents
GitLab Duo Agent Platform
Agentic AI across the whole GitLab DevSecOps lifecycle: planning, coding, code review, CI/CD and security agents under one governance model
CodeRabbit
AI code review and agentic change management for teams shipping human- and machine-written code
Qodo
Agentic code review and governance layer for teams shipping AI-generated code at scale
Mentioned In
GPT-5.4 vs Claude Opus: Which Actually Saves You Money?
GPT-5.4 vs Claude Opus 4.6: cost analysis, performance benchmarks, and ROI calculations. Find out which saves your team 40% on AI infrastructure spend.
March 7, 2026AI AgentsNVIDIA NemoClaw: Enterprise AI Agents With Security Built In
NVIDIA NemoClaw brings enterprise-grade security to AI agents. For platform teams: built-in compliance, audit trails, and sovereignty controls out of box.
March 12, 2026Enterprise AILocal AI Deployment Is Turnkey Now. Cloud Bills at Risk
Local AI Deployment Is Turnkey Now. Cloud Bills at Risk. For CISOs and security teams: risk assessment, compliance requirements, and security architecture fo...
March 13, 2026AI Models & PlatformsGPT-5.4 Pricing Guide 2026: Hidden Costs Every Enterprise Buyer Needs to Know
Enterprise AI analysis: GPT-5.4 Pricing Guide 2026. Strategic insights, ROI considerations, and implementation guidance for technical and business leaders ev...
March 13, 2026AI Models & PlatformsGPT-5.4 vs Claude Opus 4.6 Benchmarks: Every Number That Actually Matters
GPT-5.4 vs Claude Opus 4.6: latency, throughput, and accuracy benchmarks. For engineering leaders: which model delivers better performance per dollar spent.
March 13, 2026Enterprise AIAnthropic Wins 70% of Enterprise Deals—OpenAI's Losing Grip
70% of enterprise AI deals go to Anthropic, not OpenAI. For CFOs: the cost model shift driving vendor consolidation and what it means for 2026 budgets.
March 14, 2026IT ProcurementOpenAI Merges ChatGPT, Codex, and Atlas Into Desktop Super App: What It Means for Enterprise IT Budgets
OpenAI Merges ChatGPT, Codex, and Atlas Into Desktop Super App. For enterprise decision-makers: strategic analysis, cost implications, and implementation gui...
March 22, 2026Enterprise AIOpenAI Doubles Workforce to 8,000: What Enterprise Buyers Should Watch
OpenAI's 77% headcount expansion signals enterprise-first strategy. Technical ambassadors, product consolidation, and faster roadmap velocity.
March 21, 2026Enterprise AIWhy High-ROI AI Teams Are 7X Faster: The Smartcat Report
Enterprise AI analysis: Why High-ROI AI Teams Are 7X Faster. Strategic insights, ROI considerations, and implementation guidance for technical and business l...
March 11, 2026MCPMCP vs LangChain vs OpenAI Functions: Which for Enterprise?
Choosing between MCP, LangChain Tools, and OpenAI Functions isn't an either/or decision—many teams use MCP for standardized data access alongside LangChain for orchestration. The real question is which to prioritize for your enterprise use case.
March 22, 2026Enterprise AICresta Knowledge Agent: Why Augmentation Beats Automation for Contact Centers in 2026
Cresta Knowledge Agent uses augmentation over full automation for contact centers. For COOs managing support: productivity gains while maintaining human over...
March 22, 2026Cloud InfrastructureMicrosoft Loses OpenAI Exclusivity as AWS Pays $50B: What Enterprise AI Buyers Should Do Now
Microsoft Loses OpenAI Exclusivity as AWS Pays $50B. For enterprise decision-makers: strategic analysis, cost implications, and implementation guidance for A...
March 22, 2026OpenAIOpenAI's 17 Acquisitions: Vendor Lock-In and $207B Funding Gap
OpenAI's 17 Acquisitions in 3 Years Signal Vendor Lock-In Risk as $207B Funding Gap Looms. For enterprise decision-makers: strategic analysis, cost implicati...
March 25, 2026AnthropicAnthropic Leaks Claude Mythos in CMS Failure: The Most Capable AI Model—And Biggest Cyber Risk—They've Ever Built
Anthropic's CMS misconfiguration exposed Claude Mythos—a new AI model tier called Capybara that's 'far ahead of any other AI model in cyber capabilities.' The leak revealed draft launch plans, cybersecurity risk assessments, and an invite-only CEO summit. Enterprise security teams need to understand what ' unprecedented cybersecurity risks' means for their threat models.
March 29, 2026Developer ToolsCodex Pay-As-You-Go: 6x Growth Proves Seat Fees Kill Adoption
OpenAI eliminates Codex seat fees after 6x usage surge since January. 2M+ weekly builders show pay-as-you-go beats fixed pricing for engineering tools.
April 3, 2026OpenAIOpenAI Codex Pricing: $0.006/Request vs GitHub Copilot's $19/Month
OpenAI just killed seat fees for Codex. Pay $0.006 per request instead of $19/month fixed. CFOs get predictable token billing, CTOs skip budget approvals for pilots.
April 3, 2026OpenAIOpenAI's $852B Valuation: What It Means for Enterprise AI
OpenAI closed a $122B funding round at an $852B valuation. For enterprise leaders, the story is infrastructure strategy and unit economics.
April 4, 2026