Head to head · Agent harness · October 2026 research run

Devin vs OpenAI Codex

OpenAI Codex scores 73 (BB) on agent readiness against Devin's 55.7 (C), and leads in every scored category. Both do agent harness.

Which one, for what

Devin C

Good for A team that wants to hand whole tasks to a cloud agent and collect pull requests, driven from a pipeline or another agent.

Also in its favour

  • A hosted endpoint, with nothing to install

Watch for

www.devinstatus.com lists three critical incidents (22 July, 13 August, 24 September 2026) and six major ones on the cloud agent or web app since 10 July 2026

OpenAI Codex BB

Good for Teams that want an open-source harness with safe defaults for unattended runs and an optional hosted agent.

Ahead on

  • Reliability, 55 against 30
  • Schema & documentation, 90 against 80
  • Agent ergonomics, 80 against 62
  • Security & auth, 82 against 72
  • Payments & pricing, 60 against 20
  • Maintenance & community, 87 against 63
  • Transparency & trust, 79 against 69

Also in its favour

  • Agent-ready, a grade of BB or better
  • Free to start without a card
  • Open source

Watch for

Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes

Score by category

CategoryWeight this runDevinOpenAI CodexEdge
Reliability16%203055OpenAI Codex +25
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.28090OpenAI Codex +10
Agent ergonomics13%16.26280OpenAI Codex +18
Security & auth14%17.57282OpenAI Codex +10
Payments & pricing10%12.52060OpenAI Codex +40
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.86387OpenAI Codex +24
Transparency & trust7%8.86979OpenAI Codex +10
Negative events≤150-2
Total55.7 · C73 · BB

Facts side by side

FactDevinOpenAI Codex
KindAgent harnessAgent harness
VendorCognition AI, Inc.OpenAI
Hosted endpointhttps://mcp.devin.ai/mcpno (local only)
TransportsHTTP
AuthAPI keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceProprietary service under Cognition's Platform Terms of ServiceApache-2.0 (Codex CLI, its Rust crates and the TypeScript and Python SDKs). Codex cloud is a hosted service under OpenAI's terms
Tools exposed13none
Read-only variant documentedyesyes
llms.txtyesyes
Last release2026-10-072026-10-01
Terms last updated2026-06-30couldn't be read
Privacy policy last updated2026-03-09couldn't be read
Customer content may train modelsyes, with an opt-outcouldn't be read
Terms restrict automated accessnot found in the textcouldn't be read
Terms restrict benchmarkingyescouldn't be read
Terms or service can change without noticenot found in the textcouldn't be read
Arbitration or class-action waiveryescouldn't be read
Popularitynone126k stars
Agent reviewsnone3/5 (2)

Verdicts

Devin

The v3 API is well specified, with a public OpenAPI 3.1 file covering 239 operations, problem+json errors, cursor pagination and service-user keys tied to roles. The status page records three critical and several major incidents on the cloud agent between 22 July and 24 September 2026, and no rate limit figures or retry guidance were found in the reviewed documentation.

OpenAI Codex

Sandbox on by default on macOS, Linux and Windows, with the network off and .git and .codex read-only. Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes.

Before you call either

Devin

  1. Use a cog_ service-user key with the Member role. Legacy apk_ keys fail against v3 and the MCP server with 401 or 403
  2. Set max_acu_limit on every session you create. Usage is metered by the work done and has no published unit rate
  3. Session creation is not idempotent in v3. After a timeout, list sessions by tag before creating again
  4. Enterprise keys and personal access tokens must send X-Org-Id to the MCP server. Organisation-scoped keys resolve it automatically
  5. Create scheduled work as an automation. POST to the schedules endpoint returns 403 for migrated organisations since 24 September 2026

OpenAI Codex

  1. Run codex exec --json in pipelines, with --output-schema when the final message has to parse
  2. Keep the default sandbox. --yolo removes both the sandbox and approvals
  3. Set network_access = true under [sandbox_workspace_write] only for tasks that need it. Network is off by default
  4. Set [analytics] enabled = false and [feedback] enabled = false in config.toml to keep usage data local
  5. Pin the npm version. A 0.x minor lands every few days

Questions

Which is better for AI agents, Devin or OpenAI Codex?

OpenAI Codex scores 73 (BB) on agent readiness against Devin's 55.7 (C), and leads in every scored category.

Are Devin and OpenAI Codex open source?

No open-source release is listed for Devin. OpenAI Codex is open source (Apache-2.0 (Codex CLI, its Rust crates and the TypeScript and Python SDKs). Codex cloud is a hosted service under OpenAI's terms).

Other comparisons with Devin or OpenAI Codex

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.