- Codex is OpenAI's coding agent. It runs as an open-source CLI, an IDE extension, a desktop and mobile app, and a cloud service that opens pull requests. All of them share one harness and one usage allowance with ChatGPT Work.
- Every ChatGPT plan includes some Codex. OpenAI recommends GPT-6.1 Sol for coding. Plus users get an estimated 15–160 GPT-6.1 Sol messages per five hours.
- By default, Codex can only write inside your project, has no network access, and asks before going further. A single flag, --yolo, removes all of that.
Contents
Codex is OpenAI's coding agent. You give it a task, such as fixing a bug, adding a feature or reviewing a pull request. It reads your code, runs commands, edits files and reports back, either on your machine or in an OpenAI-hosted container. In October 2026 Codex isn't a single app. It is one agent "harness" that runs in several places, uses the GPT-6 models, and draws on the same usage allowance as ChatGPT's Work tab. If you're choosing between coding agents, our Claude Code vs Codex vs Cursor comparison puts it side by side with the alternatives.
This explainer is based on OpenAI's documentation, pricing and help pages, the open-source repository, and clearly labeled user reports, checked October 8–9, 2026.
Where Codex runs
According to OpenAI's documentation and the project's README, Codex is available in these forms:
- Codex CLI. A terminal agent, open source under Apache-2.0 at github.com/openai/codex. The repository had about 128,000 GitHub stars on October 8, 2026. You install it with
npm install -g @openai/codex,brew install --cask codex, or OpenAI's install script. The latest stable release on npm is 0.162.0, published October 8, 2026 (Last verified: October 9, 2026). Commands includecodex execfor scripts and CI,codex resumeandcodex cloud. In a session you can use slash commands such as/permissions,/modeland/review. - IDE extension. The README lists VS Code, Cursor and Windsurf.
- ChatGPT desktop, mobile and web apps. Since DevDay on September 29, 2026, you can start and steer Codex tasks from your phone.
- Codex Cloud. You build an "environment" from selected repositories, with an install script, network settings and secrets. Codex then runs tasks in it, each in its own workspace, and they keep going while your computer sleeps. When a task finishes you review the diff and test results, then commit or open a pull request.
- Code review. Automatic cloud reviews of GitHub pull requests and GitLab merge requests (GitLab is in beta).
- Integrations and SDK. Slack and Linear integrations, a GitHub Action, the Codex SDK and an App Server. OpenAI's new Agents API rents the same harness out to other developers.
Which models power it
OpenAI's Codex model page, as of October 8, 2026:
- GPT-6.1 Sol (
gpt-6.1-sol) is recommended for complex coding and agentic work. It isn't available to Free and Go at launch, and it's off by default on Enterprise and Edu until an admin turns it on. - GPT-6 Astra (
gpt-6-astra) is OpenAI's most capable model, and it costs much more of your allowance. - GPT-6 Luna (
gpt-6-luna) is for "focused, repeatable tasks." - GPT-6 Sol and the older GPT-5.6 Sol, Terra and Luna are still available during the rollout.
- GPT-5.5 retires from Codex, ChatGPT and ChatGPT Work on October 14, 2026, on all plans. This doesn't affect API-key users. OpenAI points paid plans to GPT-6 Sol and Free and Go users to GPT-6 Luna. There is no longer a separate Codex-branded model:
gpt-5.3-codexis deprecated for ChatGPT sign-in, and GPT-5.3-Codex-Spark retired on September 14, 2026.
Plans, limits and pricing
Last verified: October 8, 2026
Every ChatGPT plan includes Codex: Free, Go ($8/month), Plus ($20), Pro ($100, $200 or $500), Business ($20 per user per month billed annually, or $25 monthly), Edu and Enterprise. Codex and ChatGPT Work share the same usage, credits and limits. Free and Go users get GPT-6 Luna in the desktop app, "subject to rollout."
OpenAI publishes estimated five-hour limits for local messages on Plus and Standard Business:
| Model | Plus / Standard Business, local messages per 5 hours (OpenAI estimate) |
|---|---|
| GPT-6 Astra | 5–45 |
| GPT-6.1 Sol | 15–160 |
| GPT-6 Sol | 15–150 |
| GPT-6 Luna | 350–3,000 |
OpenAI attaches several caveats and related rules:
- These are estimates. Cloud tasks may use more of the allowance, and weekly limits may also apply.
- Pro has no five-hour limit for now. Pro plans "currently have no five-hour limit," but allowances differ by Pro tier.
- Faster speeds use the allowance faster. Fast mode uses your included allowance at 2.5x the normal rate. GPT-6 Astra Ultrafast uses it at 8x and is limited to Pro 500 and eligible Enterprise and Edu plans.
- Credits. Once the allowance runs out, you can buy credits. OpenAI publishes per-model credit rates but says credit prices "depend on your plan or agreement."
- API keys. If you sign in with an API key instead of ChatGPT, you pay standard API token prices. For example,
gpt-6.1-solcosts $2 per million input tokens and $10 per million output tokens.
How the sandbox and approvals work
This is the part of Codex worth understanding before you let it touch a real repository. Two separate settings control what it can do.
1. Sandbox mode: what Codex is technically able to do.
| Mode | What it allows |
|---|---|
read-only | Read files and run commands that can't write; anything else needs approval |
workspace-write | Read, edit and run commands inside the project folder and temporary directories; network off unless enabled |
danger-full-access | No sandbox at all |
2. Approval policy: when Codex has to ask you.
on-request: actions inside the sandbox run freely. Codex asks before leaving the sandbox or using network access that isn't allowed.never: Codex never asks, but it's still confined to the sandbox.- Granular: keeps chosen categories interactive and automatically rejects the rest. The categories are
sandbox_approval,rules,mcp_elicitations,request_permissionsandskill_approval. - The old
untrustedpolicy is retired, and OpenAI warns that leaving it in your config can stop Codex from starting. Mark a projecttrust_level = "untrusted"instead.
Defaults. In a folder under version control, Codex starts in "Auto," which is workspace-write plus on-request. Outside version control it starts read-only. Network access is off. Even in workspace-write, the .git, .agents and .codex folders stay read-only, so the agent can't rewrite your Git history or its own configuration.
How it's enforced. The restrictions come from the operating system, not just from the model's instructions:
- macOS: Seatbelt profiles, run through
sandbox-exec. - Linux:
bwrapplusseccomp. - Windows: a native sandbox. Under WSL2, Codex uses the Linux implementation. WSL1 is unsupported from version 0.115.
- Containers: inside a container that blocks these mechanisms, OpenAI says to run
danger-full-accessand treat the container itself as the boundary.
Escape hatches and guardrails.
- Full bypass.
--dangerously-bypass-approvals-and-sandbox, also known as--yolo, removes both the sandbox and the approvals, and OpenAI advises against it. The older--full-autoflag survives only as a deprecated path forcodex exec. - Auto-review. Setting
approvals_reviewer = "auto_review"hands approval requests to a reviewer agent. It checks for data exfiltration, credential probing and destructive actions, and it "fails closed": if the review errors out or times out, the action is blocked. Each review is an extra model call, so it uses more of your allowance. - Network allowlists. An optional network proxy filters command traffic to allowlisted domains. OpenAI notes that DNS checks don't fully prevent DNS-rebinding attacks. The proxy also doesn't filter web search, MCP connections, browser activity or the model requests themselves.
- Codex Cloud. OpenAI's internet-access documentation says that "by default, Codex blocks internet access during the agent phase," while setup scripts still run with internet access so they can install dependencies. You can turn agent access on with an empty allowlist, a preset list of common dependency domains, or unrestricted access, and limit requests to
GET,HEADandOPTIONS. OpenAI lists prompt injection and code or secret exfiltration as the risks of turning it on (Last verified: October 9, 2026).
Why this matters is the subject of our case against unattended agents. The sandbox limits what a mistake can damage. It doesn't prevent mistakes.
What users report
On September 29, 2026, OpenAI reopened its $200 Pro tier. Its help center says new subscriptions that aren't eligible for grandfathering "include a lower usage allowance." Subscribers who had an active Pro 200 plan between September 22 and 10 a.m. Pacific on September 29 "can use the previous included allowance through October 29, 2026," after which they move to the lower allowance at the same $200 price (Last verified: October 9, 2026).
The rest of this section describes user reports from OpenAI's community forum. They have not been independently verified.
In a community thread opened on September 29, users quoted an OpenAI email. They said existing Pro 200 usage would drop from 20x to 10x the Plus allowance, with a one-time credit grant expiring December 31, 2026. OpenAI's help page doesn't give a multiplier or mention a credit grant. Heavy Codex users in the thread said the old allowance already ran out within days of professional use. Some said they would cancel or switch to a competitor. No OpenAI staff member had replied in the thread as of October 8, 2026.
The general point holds beyond this complaint. Codex is metered, and how far a plan goes depends on the model, the speed mode and whether you use cloud tasks.
Known limitations
- Limits are estimates. OpenAI gives ranges, not guarantees. Heavy users can hit weekly caps.
- Model availability varies by plan and admin settings. On Enterprise and Edu, GPT-6.1 Sol stays off until an admin enables it. OpenAI's own model page names GPT-6.1 Sol as recommended, but its retirement notice points GPT-5.5 users to GPT-6 Sol.
- Some setups weaken the sandbox. It can fail in locked-down containers, it doesn't work on WSL1, and it can't filter every kind of traffic.
- Custom model providers need a Responses-compatible API. Current releases don't support Chat Completions-only endpoints.
- Approvals only help if you read them. Repeated prompts encourage people to approve everything, which is what
never, auto-review and--yoloare designed around.
What to do next
- Trying Codex: start in a Git repository, keep the default Auto mode, and add an
AGENTS.mdfile with your build and test commands. - Comparing it with Claude Code or Cursor: see our comparison.
- Reading coding-agent benchmark scores: see what SWE-bench, Terminal-Bench and METR measure, and what their results don't prove.
About this storyBased on the sources linked below. Editorial standards




