Explainer

OpenAI Codex explained: where it runs, which models and limits you get, and how its sandbox works

What Codex is in October 2026, from OpenAI's docs and pricing pages: where it runs, which plans get which models, how far the allowance goes, and what its sandbox enforces.

By ShajanthanUpdated 7 min read
ByShajanthanFounder & Editor
Published
Reading7 MIN
Diagram of Codex surfaces around a shared harness, with the sandbox and approval layer shown as a ring
In 20 seconds
  1. Codex is OpenAI's coding agent. It runs as an open-source CLI, an IDE extension, a desktop and mobile app, and a cloud service that opens pull requests. All of them share one harness and one usage allowance with ChatGPT Work.
  2. Every ChatGPT plan includes some Codex. OpenAI recommends GPT-6.1 Sol for coding. Plus users get an estimated 15–160 GPT-6.1 Sol messages per five hours.
  3. By default, Codex can only write inside your project, has no network access, and asks before going further. A single flag, --yolo, removes all of that.
Contents

Codex is OpenAI's coding agent. You give it a task, such as fixing a bug, adding a feature or reviewing a pull request. It reads your code, runs commands, edits files and reports back, either on your machine or in an OpenAI-hosted container. In October 2026 Codex isn't a single app. It is one agent "harness" that runs in several places, uses the GPT-6 models, and draws on the same usage allowance as ChatGPT's Work tab. If you're choosing between coding agents, our Claude Code vs Codex vs Cursor comparison puts it side by side with the alternatives.

This explainer is based on OpenAI's documentation, pricing and help pages, the open-source repository, and clearly labeled user reports, checked October 8–9, 2026.

Where Codex runs

According to OpenAI's documentation and the project's README, Codex is available in these forms:

  • Codex CLI. A terminal agent, open source under Apache-2.0 at github.com/openai/codex. The repository had about 128,000 GitHub stars on October 8, 2026. You install it with npm install -g @openai/codex, brew install --cask codex, or OpenAI's install script. The latest stable release on npm is 0.162.0, published October 8, 2026 (Last verified: October 9, 2026). Commands include codex exec for scripts and CI, codex resume and codex cloud. In a session you can use slash commands such as /permissions, /model and /review.
  • IDE extension. The README lists VS Code, Cursor and Windsurf.
  • ChatGPT desktop, mobile and web apps. Since DevDay on September 29, 2026, you can start and steer Codex tasks from your phone.
  • Codex Cloud. You build an "environment" from selected repositories, with an install script, network settings and secrets. Codex then runs tasks in it, each in its own workspace, and they keep going while your computer sleeps. When a task finishes you review the diff and test results, then commit or open a pull request.
  • Code review. Automatic cloud reviews of GitHub pull requests and GitLab merge requests (GitLab is in beta).
  • Integrations and SDK. Slack and Linear integrations, a GitHub Action, the Codex SDK and an App Server. OpenAI's new Agents API rents the same harness out to other developers.

Which models power it

OpenAI's Codex model page, as of October 8, 2026:

  • GPT-6.1 Sol (gpt-6.1-sol) is recommended for complex coding and agentic work. It isn't available to Free and Go at launch, and it's off by default on Enterprise and Edu until an admin turns it on.
  • GPT-6 Astra (gpt-6-astra) is OpenAI's most capable model, and it costs much more of your allowance.
  • GPT-6 Luna (gpt-6-luna) is for "focused, repeatable tasks."
  • GPT-6 Sol and the older GPT-5.6 Sol, Terra and Luna are still available during the rollout.
  • GPT-5.5 retires from Codex, ChatGPT and ChatGPT Work on October 14, 2026, on all plans. This doesn't affect API-key users. OpenAI points paid plans to GPT-6 Sol and Free and Go users to GPT-6 Luna. There is no longer a separate Codex-branded model: gpt-5.3-codex is deprecated for ChatGPT sign-in, and GPT-5.3-Codex-Spark retired on September 14, 2026.

Plans, limits and pricing

Last verified: October 8, 2026

Every ChatGPT plan includes Codex: Free, Go ($8/month), Plus ($20), Pro ($100, $200 or $500), Business ($20 per user per month billed annually, or $25 monthly), Edu and Enterprise. Codex and ChatGPT Work share the same usage, credits and limits. Free and Go users get GPT-6 Luna in the desktop app, "subject to rollout."

OpenAI publishes estimated five-hour limits for local messages on Plus and Standard Business:

ModelPlus / Standard Business, local messages per 5 hours (OpenAI estimate)
GPT-6 Astra5–45
GPT-6.1 Sol15–160
GPT-6 Sol15–150
GPT-6 Luna350–3,000

OpenAI attaches several caveats and related rules:

  • These are estimates. Cloud tasks may use more of the allowance, and weekly limits may also apply.
  • Pro has no five-hour limit for now. Pro plans "currently have no five-hour limit," but allowances differ by Pro tier.
  • Faster speeds use the allowance faster. Fast mode uses your included allowance at 2.5x the normal rate. GPT-6 Astra Ultrafast uses it at 8x and is limited to Pro 500 and eligible Enterprise and Edu plans.
  • Credits. Once the allowance runs out, you can buy credits. OpenAI publishes per-model credit rates but says credit prices "depend on your plan or agreement."
  • API keys. If you sign in with an API key instead of ChatGPT, you pay standard API token prices. For example, gpt-6.1-sol costs $2 per million input tokens and $10 per million output tokens.

How the sandbox and approvals work

This is the part of Codex worth understanding before you let it touch a real repository. Two separate settings control what it can do.

1. Sandbox mode: what Codex is technically able to do.

ModeWhat it allows
read-onlyRead files and run commands that can't write; anything else needs approval
workspace-writeRead, edit and run commands inside the project folder and temporary directories; network off unless enabled
danger-full-accessNo sandbox at all

2. Approval policy: when Codex has to ask you.

  • on-request: actions inside the sandbox run freely. Codex asks before leaving the sandbox or using network access that isn't allowed.
  • never: Codex never asks, but it's still confined to the sandbox.
  • Granular: keeps chosen categories interactive and automatically rejects the rest. The categories are sandbox_approval, rules, mcp_elicitations, request_permissions and skill_approval.
  • The old untrusted policy is retired, and OpenAI warns that leaving it in your config can stop Codex from starting. Mark a project trust_level = "untrusted" instead.

Defaults. In a folder under version control, Codex starts in "Auto," which is workspace-write plus on-request. Outside version control it starts read-only. Network access is off. Even in workspace-write, the .git, .agents and .codex folders stay read-only, so the agent can't rewrite your Git history or its own configuration.

How it's enforced. The restrictions come from the operating system, not just from the model's instructions:

  • macOS: Seatbelt profiles, run through sandbox-exec.
  • Linux: bwrap plus seccomp.
  • Windows: a native sandbox. Under WSL2, Codex uses the Linux implementation. WSL1 is unsupported from version 0.115.
  • Containers: inside a container that blocks these mechanisms, OpenAI says to run danger-full-access and treat the container itself as the boundary.

Escape hatches and guardrails.

  • Full bypass. --dangerously-bypass-approvals-and-sandbox, also known as --yolo, removes both the sandbox and the approvals, and OpenAI advises against it. The older --full-auto flag survives only as a deprecated path for codex exec.
  • Auto-review. Setting approvals_reviewer = "auto_review" hands approval requests to a reviewer agent. It checks for data exfiltration, credential probing and destructive actions, and it "fails closed": if the review errors out or times out, the action is blocked. Each review is an extra model call, so it uses more of your allowance.
  • Network allowlists. An optional network proxy filters command traffic to allowlisted domains. OpenAI notes that DNS checks don't fully prevent DNS-rebinding attacks. The proxy also doesn't filter web search, MCP connections, browser activity or the model requests themselves.
  • Codex Cloud. OpenAI's internet-access documentation says that "by default, Codex blocks internet access during the agent phase," while setup scripts still run with internet access so they can install dependencies. You can turn agent access on with an empty allowlist, a preset list of common dependency domains, or unrestricted access, and limit requests to GET, HEAD and OPTIONS. OpenAI lists prompt injection and code or secret exfiltration as the risks of turning it on (Last verified: October 9, 2026).

Why this matters is the subject of our case against unattended agents. The sandbox limits what a mistake can damage. It doesn't prevent mistakes.

What users report

On September 29, 2026, OpenAI reopened its $200 Pro tier. Its help center says new subscriptions that aren't eligible for grandfathering "include a lower usage allowance." Subscribers who had an active Pro 200 plan between September 22 and 10 a.m. Pacific on September 29 "can use the previous included allowance through October 29, 2026," after which they move to the lower allowance at the same $200 price (Last verified: October 9, 2026).

The rest of this section describes user reports from OpenAI's community forum. They have not been independently verified.

In a community thread opened on September 29, users quoted an OpenAI email. They said existing Pro 200 usage would drop from 20x to 10x the Plus allowance, with a one-time credit grant expiring December 31, 2026. OpenAI's help page doesn't give a multiplier or mention a credit grant. Heavy Codex users in the thread said the old allowance already ran out within days of professional use. Some said they would cancel or switch to a competitor. No OpenAI staff member had replied in the thread as of October 8, 2026.

The general point holds beyond this complaint. Codex is metered, and how far a plan goes depends on the model, the speed mode and whether you use cloud tasks.

Known limitations

  • Limits are estimates. OpenAI gives ranges, not guarantees. Heavy users can hit weekly caps.
  • Model availability varies by plan and admin settings. On Enterprise and Edu, GPT-6.1 Sol stays off until an admin enables it. OpenAI's own model page names GPT-6.1 Sol as recommended, but its retirement notice points GPT-5.5 users to GPT-6 Sol.
  • Some setups weaken the sandbox. It can fail in locked-down containers, it doesn't work on WSL1, and it can't filter every kind of traffic.
  • Custom model providers need a Responses-compatible API. Current releases don't support Chat Completions-only endpoints.
  • Approvals only help if you read them. Repeated prompts encourage people to approve everything, which is what never, auto-review and --yolo are designed around.

What to do next

About this storyBased on the sources linked below. Editorial standards

Was this useful?Report an error
Comments
0

More on Codex & agents

The Week in AI

New guides and explainers, every Friday.

0