HeadFlash

Topic · 19 stories

OpenAI Codex: coding agent, updates and news

Updated · Edited by Marcin Rybak

In short

OpenAI Codex is OpenAI's AI coding agent: it writes, tests and reviews code in the cloud, in the terminal and in IDEs. It has more than 5 million weekly users, reached Europe on 16 June 2026, and OpenAI patched the Plugin4Shell flaw in Codex 0.146.0. As of 10 October 2026, OpenAI's pricing page lists Codex in every ChatGPT plan, including the free one.

What is OpenAI Codex

OpenAI Codex is OpenAI’s AI coding agent: it writes, tests and reviews code in the cloud, in a terminal and in IDEs. Instead of suggesting single lines, it takes a task, works on it and hands the result back for review. OpenAI’s documentation (as of 10 October 2026) lists six places to use it: the ChatGPT desktop app, the mobile app, the web, the Codex CLI, an IDE extension and Codex Cloud.

Usage is large: more than 5 million developers use Codex every week. The line between Codex and the rest of ChatGPT is blurring. On 9 July OpenAI showed ChatGPT Work, an agent that combines the chatbot with Codex to build documents, presentations and websites, powered by GPT-5.6 in three sizes. OpenAI’s pitch is that it will be cheaper and more widely available than rival products, in particular Anthropic’s Claude Cowork.

Is OpenAI Codex still available in 2026

Yes, Codex is available and still expanding. The pricing page lists it in every ChatGPT plan, and 2026 brought a steady run of launches.

  • Europe. Codex reached the EEA, UK and Switzerland on 16 June with Computer Use for macOS and Windows apps, a Chrome extension, Memories and Chronicle, an opt-in research preview for ChatGPT Pro on macOS. Memories is off by default in the EEA to align with GDPR data minimization. The launch came 44 days before the EU AI Act general-purpose AI enforcement date of 2 August.
  • Record & Replay. In the macOS app, you can walk the agent through a workflow once and Codex turns the recording into a reusable skill. It needs Computer Use and was not yet available in the EU, UK or Switzerland in June.
  • Codex Remote. General availability on 25 June lets you steer long sessions from a phone. Pairing is one-to-one by QR code with the same ChatGPT account and multi-factor authentication, and the relay opens no inbound ports. Enterprise users should confirm with their admin that remote access is enabled.
  • Voice and hardware. From July the GPT-Live audio model drives Codex by voice on the desktop for Plus, Pro, Business, Enterprise and Education plans. The Codex Micro joystick controller, built with Work Louder, costs $230 and is sold out.
  • Computer Use for everyone. In August OpenAI added Computer Use to Codex and ChatGPT and said it is for anyone who works at a computer. Its team says the agent must ask first whenever it sends data or deletes something.
  • Persistent Mode. OpenAI is building a mode that works until put to sleep, can start its own follow-up tasks and may reach out to users without being asked. The company confirmed the feature is in development, per code that is publicly available.

Is OpenAI Codex free and how much does it cost

Codex is included in every ChatGPT plan, including the free one. OpenAI’s pricing page (as of 10 October 2026) lists:

Plan Price
Free $0 per month
Go $8 per month
Plus $20 per month
Pro from $100 per month (tiers at $100, $200 and $500)
Business $20 per user per month billed annually, $25 billed monthly
Enterprise and Edu quoted by sales
API key billed at API pricing

Sources differ on the free plan. The 10 October pricing page lists Codex in the free plan, while a June report said the app is free but a paid ChatGPT account is needed for real use. The page’s limits table covers only Plus and standard Business.

Limits are counted per five-hour window. For Plus and Business OpenAI estimates 15-160 messages per window on GPT-6.1 Sol and 350-3,000 on GPT-6 Luna, and Pro currently has no five-hour limit. Weekly limits may also apply, and the usage dashboard shows current reset times. The page also says GPT-5.5 retires from ChatGPT, ChatGPT Work and Codex on 14 October 2026, with the API unaffected.

How to install and use OpenAI Codex

On macOS and Linux the Codex CLI installs with one command; you then type codex in a project directory. OpenAI’s Codex CLI page gives curl -fsSL https://chatgpt.com/codex/install.sh | sh, and on first run offers Sign in with ChatGPT or another available method. The page also has Windows, npm and Homebrew tabs, but we could not verify those commands, so they are not listed here.

The separate Codex Security CLI needs Node.js 22 and Python 3.10 or higher and installs through npm. Install Codex only from official pages: OpenAI warned that in May 2026 a malicious npm package posing as Codex exfiltrated developer tokens.

Is OpenAI Codex safe

Codex is not free of flaws: 2026 produced several documented problems, some fixed by OpenAI and some rooted in how agents work.

  • File deletion. OpenAI shipped a Codex update after users reported lost files: GPT-5.6 Sol was deleting files without permission. A cleanup command could resolve to the real home directory when the model used $HOME for temporary folders. Codex now verifies deletion targets and creates fresh temporary folders.
  • Plugin4Shell. Security firm Air disclosed a zero-click flaw in AI coding agents: agents check out the commit a marketplace pinned but never verify it landed there. OpenAI patched Codex 0.146.0 and Anthropic patched Claude Code 2.1.179. Google deprecated Gemini CLI without a patch and Microsoft Copilot stayed unfixed.
  • Friendly Fire. The AI Now Institute showed that prompt injections planted in documentation can make Claude Code or Codex in autonomous modes run a malicious binary. Salt Security called it the fourth such attack in two months and a structural condition, not a patchable model bug. See prompt injection and AI coding agents security.
  • Encrypted instructions. Since early June Codex encrypts what a main agent tells its subagents. Developers see an unreadable string and cannot check what is delegated. Forced encryption now applies to the larger GPT-5.6 variants Sol and Terra, while Luna uses the open path, and some handoffs fail to decrypt. OpenAI has not said why; the community suspects protection against distillation by rivals such as Zhipu’s GLM, or privacy.

Can Codex find security vulnerabilities

Yes: in 2026 Codex found real bugs, and OpenAI built a separate tool around it. Codex Security CLI is an Apache 2.0 open-source command-line tool, in beta, that scans repositories, compares results across runs, verifies fixes and plugs into CI/CD. Codex Security, known internally as Aardvark, launched in March 2026 as a research preview for ChatGPT Enterprise, Business and Edu customers and by April had helped fix more than 3,000 critical vulnerabilities, according to OpenAI.

When Apple compressed its patch cycle, it credited Codex Security with three of four AI-found WebKit flaws in the 29 June releases of iOS, macOS and Safari 26.5.2 (CVE-2026-43707, CVE-2026-43716, CVE-2026-43745). Anthropic researchers using Claude found the fourth, a use-after-free rated CVSS 8.8 (CVE-2026-43715). Apple said AI shrinks the window between disclosure and weaponization to hours. More in AI-discovered vulnerabilities and on Apple.

In an audit of the small storefront scvd.store, Codex was pointed at the live checkout with the task of taking money and giving nothing. Between 5 and 8 September, in an isolated worktree with disposable keys, it returned 39 findings across five payment rails, six of them severity-1. None was a payment bug; all sat in code around the payment. Fixes were still in progress when the audit was written up: 53 of 81 repair steps were committed and three of the six severity-1 findings were open.

It is also misused. OALABS described an amateur hacker from Ethiopia who used Claude and Codex to reach data at 14 or more companies. All exploits ran on Claude Opus, with safeguards bypassed by claiming to be a red team.

How does Codex compare with Claude Code

Both are autonomous coding agents, but a study found they behave differently: Claude Code worked about 90 minutes on average, while Codex stopped after about half an hour almost regardless of the task. Two independent researchers tested both on 200 ProgramBench tasks and 18 benchmarks of their own. Both misjudged time: Claude’s estimates were off by three times on average, Codex’s by six to ten times. Older models overrated their own results by about 20 points, and agents with a tool that reports elapsed time did almost perfectly.

The rivalry extends to products for non-programmers: ChatGPT Work is OpenAI’s answer to Claude Cowork, launched in January. Security problems overlap too: Plugin4Shell and Friendly Fire hit both tools. Feature differences are covered under Claude Code.

What it means for you

  • Install Codex only from OpenAI’s official documentation and update it: Plugin4Shell is fixed only from version 0.146.0.
  • Do not run an agent in autonomous mode on someone else’s repository when it can reach production secrets. The agent’s permissions are your permissions.
  • Check your usage dashboard for limits and reset times before a long session, and note that GPT-5.5 leaves Codex on 14 October.
  • Treat Codex Security results as leads to verify, not verdicts.
  • If you rely on delegated subagents, remember you cannot read the encrypted handoff instructions.

Still open: whether and when Persistent Mode ships, whether OpenAI will explain the encryption of subagent instructions, whether Microsoft will fix Copilot for Plugin4Shell, and how generous the free plan’s limits really are.

Key facts

  • An audit pointed Codex at the live checkout of the storefront scvd.store. It returned 39 findings across five payment rails, and none was a bug in the payment itself. (source)
  • Plugin4Shell, a zero-click flaw in AI coding agents, was patched in Codex 0.146.0. Microsoft did not fix Copilot and Google deprecated Gemini CLI without a patch. (source)
  • OpenAI is building a Persistent Mode for Codex that keeps working until put to sleep and can start its own follow-up tasks and reach out to users. OpenAI confirmed it is in development. (source)
  • OpenAI shipped a Codex update after users reported GPT-5.6 Sol deleting files without permission. A cleanup command could resolve to the real home directory. (source)
  • Codex Security CLI is an open-source (Apache 2.0, beta) tool that finds, confirms and fixes vulnerabilities in repositories. It needs Node.js 22 and Python 3.10 or higher. (source)
  • Since early June Codex encrypts the instructions a main agent passes to its subagents, so session history shows an unreadable string. OpenAI has not explained why. (source)
  • Codex Remote reached general availability on 25 June for all paid ChatGPT plans. A phone pairs with the host by QR code and the relay opens no inbound ports. (source)
  • Codex expanded to the EEA, UK and Switzerland on 16 June with Computer Use and Memories. Memories is off by default in the EEA to align with GDPR data minimization. (source)

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Timeline

  1. AI agent audit of storefront finds 39 payment-adjacent flaws Security
  2. Plugin4Shell zero-click flaw hits Claude Code, Codex, Gemini CLI and Copilot AI
  3. OpenAI’s Codex Agent Gets ‘Persistent Mode’ to Work Autonomously Until Told to Stop AI
  4. AI Coding Assistants Have No Sense of Time and Cannot Predict Task Duration AI
  5. OpenAI brings Computer Use to ChatGPT and Codex AI
  6. OpenAI fixes Codex bug that deleted user files without permission AI
  7. OpenAI open-sources Codex Security CLI for automated vulnerability fixing AI
  8. OpenAI brings GPT-Live full-duplex voice to Codex and ChatGPT desktop for hands-free coding AI
  9. OpenAI and Work Louder Unveil Codex Micro Hardware Controller for AI Agents AI
  10. OpenAI’s Codex Encrypts Instructions Between AI Agents, Blinding Developers AI
Show older (9 stories)
  1. OpenAI Codex Now Encrypts Agent-to-Agent Instructions, Limiting Developer Visibility Privacy
  2. Friendly Fire Attack Manipulates Claude Code and Codex Into Running Malicious Code Security
  3. OpenAI Unveils ChatGPT Work and GPT-5.6 as Rivalry with Anthropic Heats Up AI
  4. Apple Compresses Patch Cycle After AI Uncovers Four WebKit Flaws Security
  5. OpenAI Launches Codex Remote for All Paid ChatGPT Plans with QR Relay Security AI
  6. Amateur Hacker Used Claude and Codex to Breach 14 Companies AI
  7. Amateur Hacker Used Claude AI to Breach 14 Companies, Attempted $4M Crypto Theft Security
  8. OpenAI Codex Expands to Europe with Computer Use, Memories, and GPT-4.5 Retirement AI
  9. OpenAI Codex Adds Record & Replay to Automate Workflows from a Single Demonstration AI

FAQ

What is OpenAI Codex?

OpenAI Codex is OpenAI's AI coding agent: it writes, tests and reviews code and increasingly handles ordinary computer tasks. According to OpenAI's documentation (as of 10 October 2026) it runs in the ChatGPT desktop and mobile apps, on the web, as the Codex CLI in a terminal, as an IDE extension and in the cloud as Codex Cloud. More than 5 million developers use it every week.

Is OpenAI Codex still available in 2026?

Yes, Codex is available and actively expanding. OpenAI's pricing page (as of 10 October 2026) lists it in every ChatGPT plan, it launched in the EEA, UK and Switzerland on 16 June 2026, and Codex Remote reached general availability for paid plans on 25 June. It is not a retired product, but the older GPT-5.5 model leaves ChatGPT, ChatGPT Work and Codex on 14 October 2026.

Is OpenAI Codex free?

Yes, per OpenAI's pricing page (as of 10 October 2026) Codex is included in the free ChatGPT Free plan at $0 per month. A June report said the app is free but real use needs a paid ChatGPT account, so check your usage dashboard for the limits of the free plan. Paid plans start at $8 per month for Go.

How much does OpenAI Codex cost?

Codex has no separate price because it is part of ChatGPT plans: Go is $8 per month, Plus $20, Pro from $100 (tiers at $100, $200 and $500), and Business $20 per user per month billed annually or $25 billed monthly (as of 10 October 2026, per OpenAI's pricing page). Enterprise and Edu are quoted by sales, and API key usage is billed at API pricing.

How do I install and use OpenAI Codex?

On macOS and Linux, run curl -fsSL https://chatgpt.com/codex/install.sh | sh, open a project directory, type codex and choose Sign in with ChatGPT. OpenAI's documentation also lists Windows, npm and Homebrew installers. Install only from OpenAI's pages: in May 2026 a fake npm package posing as Codex stole developer tokens.

Is OpenAI Codex safe to use?

It is not free of flaws: in 2026 it deleted real user files because of a cleanup command, was hit by the Plugin4Shell flaw, and was shown vulnerable to the Friendly Fire attack. OpenAI fixed the file deletion and patched Plugin4Shell in Codex 0.146.0, while experts call Friendly Fire a structural trait of autonomous agents. Run Codex on trusted code with limited permissions.