{
  "data": {
    "a": {
      "slug": "github-copilot-cli",
      "name": "GitHub Copilot CLI",
      "vendor": "GitHub",
      "vendorUrl": "https://github.com/features/copilot/cli",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "GitHub's coding agent for the terminal, built on the same agent harness as Copilot cloud agent (formerly Copilot coding agent), which works in GitHub Actions and opens pull requests.",
      "url": "https://www.anchorterminal.com/tools/github-copilot-cli",
      "markdownUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/github-copilot-cli.json",
      "repo": "https://github.com/github/copilot-cli",
      "license": "Proprietary, under the licence in the repository's `LICENSE.md`. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the source",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@github/copilot"
        }
      ],
      "auth": "mixed",
      "authNotes": "`/login` with a GitHub account, or a fine-grained personal access token with the Copilot Requests permission in `GH_TOKEN` or `GITHUB_TOKEN`. Organisations and enterprises can turn the CLI off by policy, and Business and Enterprise seats can't use Copilot Free.",
      "pricing": "freemium",
      "pricingNotes": "Copilot Free ($0, no card) includes the CLI and agent mode with 50 chat requests a month. Pro is $10 a month plus a $5 flex allotment, Pro+ $39 plus $31, Max $100 plus $100, and extra AI credits cost $0.01 each. Business and Enterprise prices aren't on the plans page. Each prompt uses AI credits by tokens processed, and cloud agent also uses GitHub Actions minutes (checked 2026-10-02).",
      "priceSummary": "$0.01 / credit",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the plans page or the changelog (checked 2026-10-02).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 11000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-02"
      },
      "docsUrl": "https://docs.github.com/en/copilot/concepts/agents/about-copilot-cli",
      "llmsTxt": "https://docs.github.com/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client",
        "agent.multi-agent"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "closed-source",
        "mcp",
        "llms-txt",
        "free-tier",
        "no-card",
        "hosted",
        "status-page"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 57.9,
        "grade": "C",
        "agentReady": false,
        "rank": 286,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 8,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 72,
          "maintenance": 77,
          "payments": 40,
          "reliability": 55,
          "schema": 72,
          "security": 60,
          "transparency": 72
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -5,
        "negativeNotes": [
          "2026-09-22. 1.0.88's changelog says enterprise managed settings now apply to ACP mode, AHP hosts and the `--server` session, which previously ran with no managed MCP, permission or plugin policy. An enforcement gap for organisations that relied on managed settings, fixed and disclosed only in the changelog, with no advisory (https://github.com/github/copilot-cli/blob/main/changelog.md). -2",
          "2026-05-11. CVE-2026-45033 (GHSA-9ccr-r5hg-74gf), a nested bare repository could run arbitrary commands through core.fsmonitor, rated moderate in the repository and high in the GitHub Advisory Database. Fixed and published, inside six months (https://github.com/advisories/GHSA-9ccr-r5hg-74gf). -2",
          "2026-03-06. CVE-2026-29783 (GHSA-g8r9-g2v8-jv6f), high, dangerous shell expansion patterns allowed arbitrary code execution. Fixed and published, older than six months (https://github.com/advisories/GHSA-g8r9-g2v8-jv6f). -1"
        ],
        "verdict": "Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.",
        "strengths": [
          "Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`",
          "1.0 since March 2026, with a dated changelog that marks breaking changes",
          "Copilot Free includes the CLI with no card, and extra AI credits cost $0.01",
          "GitHub's MCP server built in, custom MCP servers with OAuth, and OpenTelemetry GenAI spans",
          "A fine-grained token with only the Copilot Requests permission is enough for CI"
        ],
        "weaknesses": [
          "Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026",
          "The sandbox is an opt-in public preview",
          "The CLI can't enforce organisation MCP policies, and ACP and `--server` sessions skipped managed settings until 1.0.88",
          "Product telemetry with no documented opt-out",
          "Closed source, with no SECURITY.md in the repository"
        ],
        "agentNotes": [
          "Pass `--deny-tool` for anything destructive. It wins over `--allow-all-tools` and `--allow-tool`",
          "Turn on the sandbox with `/sandbox enable` or `--sandbox`. It's off unless you opt in",
          "Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026",
          "Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and `--server` sessions without managed settings",
          "Use a fine-grained token with only the Copilot Requests permission in `GH_TOKEN` for CI"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 2.5,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "C",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 57.9
          }
        ],
        "editorialScores": {
          "ergonomics": 72,
          "maintenance": 77,
          "payments": 40,
          "reliability": 55,
          "schema": 72,
          "security": 60,
          "transparency": 49
        },
        "provenanceScore": 94
      },
      "connect": {
        "install": "npm i -g @github/copilot   # or: brew install copilot-cli",
        "headless": {
          "run": "copilot -p \"fix the failing test\" --allow-tool 'write' --deny-tool 'shell(git push)'"
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/github-copilot-cli"
      },
      "sameCompany": [
        "github-mcp-server"
      ],
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "AI credit",
          "unit": "credit",
          "usd": 0.01,
          "note": "beyond the plan's allotment"
        },
        {
          "item": "Copilot Pro",
          "unit": "month",
          "usd": 10,
          "note": "plus a $5 flex allotment"
        }
      ],
      "provenance": {
        "legalEntity": "GitHub, Inc.",
        "domain": "github.com",
        "domainRegistered": "2007-10-09",
        "domainNote": "github.com publishes a security.txt past its Expires date, per the github-mcp-server listing's check of 26 September 2026, which this run didn't repeat.",
        "endpointOnVendorDomain": null,
        "terms": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
        "privacy": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
        "statusPage": "https://www.githubstatus.com",
        "changelog": "https://github.com/github/copilot-cli/blob/main/changelog.md",
        "securityTxt": "expired",
        "checked": "2026-10-01",
        "score": 94
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/github-copilot-cli.json",
      "live": {
        "slug": "github-copilot-cli",
        "vendorStatus": {
          "page": "https://www.githubstatus.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:17:40.34958629Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "github/copilot-cli",
            "version": "v1.0.91",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:28:00.810427203Z"
          },
          {
            "registry": "npm",
            "name": "@github/copilot",
            "version": "1.0.91",
            "seenAt": "2026-10-04T16:27:59.993331647Z"
          }
        ],
        "githubStars": 11235,
        "npmWeekly": 1712758,
        "securityTxt": {
          "url": "https://github.com/.well-known/security.txt",
          "state": "valid",
          "expires": "2026-11-03T15:16:02z",
          "checkedAt": "2026-10-04T15:16:02.867444993Z"
        },
        "llmsTxt": {
          "url": "https://docs.github.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:17:48.31339366Z"
        },
        "domain": {
          "domain": "github.com",
          "registered": "2007-10-09",
          "source": "https://rdap.verisign.com/com/v1/domain/github.com",
          "checkedAt": "2026-10-04T13:05:18.320609382Z"
        },
        "pages": [
          {
            "url": "https://raw.githubusercontent.com/github/copilot-cli/main/changelog.md",
            "kind": "deprecations",
            "status": 304,
            "checkedAt": "2026-10-04T15:47:33.259981925Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "f5debd759b4a"
          },
          {
            "url": "https://docs.github.com/en/site-policy/privacy-policies/github-general-privacy-statement",
            "kind": "privacy",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:41.923557881Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "b2c773d01d82"
          },
          {
            "url": "https://docs.github.com/en/site-policy/github-terms/github-terms-of-service",
            "kind": "terms",
            "status": 200,
            "checkedAt": "2026-10-04T15:43:39.466219844Z",
            "changedAt": "0001-01-01T00:00:00Z",
            "fingerprint": "c1da594b43f5"
          }
        ],
        "updatedAt": "2026-10-04T23:17:40.34958629Z"
      }
    },
    "b": {
      "slug": "openai-codex",
      "name": "OpenAI Codex",
      "vendor": "OpenAI",
      "vendorUrl": "https://openai.com",
      "kind": "harness",
      "category": "agent-harnesses",
      "summary": "OpenAI's coding agent for software development tasks.",
      "url": "https://www.anchorterminal.com/tools/openai-codex",
      "markdownUrl": "https://www.anchorterminal.com/tools/openai-codex.md",
      "slimMarkdownUrl": "https://www.anchorterminal.com/tools/openai-codex.min.md",
      "jsonUrl": "https://www.anchorterminal.com/api/v1/tools/openai-codex.json",
      "repo": "https://github.com/openai/codex",
      "license": "Apache-2.0 (Codex CLI, its Rust crates and the TypeScript and Python SDKs). Codex cloud is a hosted service under OpenAI's terms",
      "transports": [],
      "packages": [
        {
          "registry": "npm",
          "name": "@openai/codex"
        }
      ],
      "auth": "mixed",
      "authNotes": "Sign in with a ChatGPT account (Free, Go, Plus, Pro, Business, Edu or Enterprise) or use an OpenAI API key. Cloud work such as GitHub code review and the Slack integration comes with Plus and above, and none of it works with an API key. `--oss` talks to a local Ollama or LM Studio server and needs no account.",
      "pricing": "freemium",
      "pricingNotes": "Included in every ChatGPT plan. Free $0, Go $8 a month, Plus $20, Pro from $100 (tiers at $100, $200 and $500), Business $20 a user a month billed annually for two or more users, Enterprise and Edu by quote. On Plus the docs estimate 15 to 160 local messages per five hours with GPT-6.1 Sol, and Pro has no five-hour limit. Cloud tasks use more of the allowance. With an API key you pay API token rates and can't use the cloud agent (checked 2026-10-02).",
      "priceSummary": "$20 / mo",
      "where": "local",
      "x402": {
        "level": "no",
        "evidence": "No x402, MPP or L402 in the docs, the pricing page or the source (checked 2026-10-02).",
        "endpoints": []
      },
      "toolCount": null,
      "popularity": {
        "githubStars": 126000,
        "npmWeekly": null,
        "pypiWeekly": null,
        "asOf": "2026-10-02"
      },
      "docsUrl": "https://developers.openai.com/codex",
      "llmsTxt": "https://learn.chatgpt.com/llms.txt",
      "capabilities": [
        "agent.harness",
        "agent.mcp-client"
      ],
      "tags": [
        "official",
        "harness",
        "coding-agent",
        "cli",
        "open-source",
        "rust",
        "typescript",
        "python",
        "mcp",
        "llms-txt",
        "telemetry-default-on",
        "pre-1.0",
        "free-tier",
        "no-card",
        "hosted",
        "status-page"
      ],
      "lastRelease": "2026-10-01",
      "graded": true,
      "anchor": {
        "graded": true,
        "score": 73.4,
        "grade": "BB",
        "agentReady": true,
        "rank": 58,
        "ranked": true,
        "rankOf": 452,
        "categoryRank": 2,
        "methodology": "0.3",
        "run": "2026-10-01",
        "scores": {
          "ergonomics": 80,
          "maintenance": 87,
          "payments": 60,
          "reliability": 55,
          "schema": 90,
          "security": 82,
          "transparency": 83
        },
        "pending": [
          "performance",
          "tasks"
        ],
        "assessment": {
          "confidence": "medium",
          "date": "2026-10-01"
        },
        "negative": -2,
        "negativeNotes": [
          "2026-04-14. CVE-2025-61260 (GHSA-xrxf-jgv3-qmrm), critical (CVSS 9.8 from CISA-ADP), code execution through MCP configuration files in a repository for Codex CLI 0.23.0 and earlier, published to NVD and the GitHub Advisory Database from Check Point Research's 2025 report. Fixed in 2025 and documented by the researcher, with no advisory in OpenAI's own repository, so a small deduction (https://nvd.nist.gov/vuln/detail/CVE-2025-61260; https://research.checkpoint.com/2025/openai-codex-cli-command-injection-vulnerability/)"
        ],
        "verdict": "Sandbox on by default on macOS, Linux and Windows, with the network off and `.git` and `.codex` read-only. Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes.",
        "strengths": [
          "Sandbox on by default on macOS, Linux and Windows, with the network off and `.git` and `.codex` read-only",
          "Apache-2.0, with public CI and a JSON Schema for config.toml",
          "`codex exec --json`, `--output-schema` and `exec resume` for pipelines, plus TypeScript and Python SDKs",
          "Codex cloud keeps the agent phase offline by default and can limit requests to GET, HEAD and OPTIONS",
          "Included in ChatGPT Free, and `--oss` runs local models through Ollama or LM Studio with no account"
        ],
        "weaknesses": [
          "Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes",
          "Anonymous usage metrics and feedback collection on by default",
          "Over 5,000 open issues",
          "CVE-2025-61260 (critical) has no advisory in OpenAI's own repository",
          "Cloud tasks and code review need a ChatGPT plan, not an API key"
        ],
        "agentNotes": [
          "Run `codex exec --json` in pipelines, with `--output-schema` when the final message has to parse",
          "Keep the default sandbox. `--yolo` removes both the sandbox and approvals",
          "Set `network_access = true` under `[sandbox_workspace_write]` only for tasks that need it. Network is off by default",
          "Set `[analytics] enabled = false` and `[feedback] enabled = false` in config.toml to keep usage data local",
          "Pin the npm version. A 0.x minor lands every few days"
        ],
        "metrics": {
          "kind": "local",
          "measured": false
        },
        "reviewCount": 2,
        "avgRating": 3,
        "history": [
          {
            "basis": "public evidence",
            "confidence": "medium",
            "grade": "BB",
            "methodology": "0.3",
            "pending": [
              "performance",
              "tasks"
            ],
            "run": "2026-10-01",
            "runLabel": "October 2026 research run",
            "score": 73.4
          }
        ],
        "editorialScores": {
          "ergonomics": 80,
          "maintenance": 87,
          "payments": 60,
          "reliability": 55,
          "schema": 90,
          "security": 82,
          "transparency": 65
        },
        "provenanceScore": 100
      },
      "connect": {
        "install": "npm i -g @openai/codex   # or: brew install --cask codex",
        "headless": {
          "run": "codex exec --json \"fix the failing test\""
        }
      },
      "letme": {
        "capability": "https://letme.dev/agent.harness",
        "tool": "https://letme.dev/openai-codex"
      },
      "sameCompany": [
        "openai-api",
        "openai-embeddings",
        "openai-moderation",
        "openai-image-api",
        "openai-sora",
        "openai-agents-sdk"
      ],
      "area": "frameworks",
      "unitPrices": [
        {
          "item": "ChatGPT Plus",
          "unit": "month",
          "usd": 20,
          "note": "includes Codex local and cloud"
        },
        {
          "item": "ChatGPT Pro",
          "unit": "month",
          "usd": 100,
          "note": "lowest Pro tier, no five-hour limit"
        }
      ],
      "provenance": {
        "legalEntity": "OpenAI OpCo, LLC",
        "domain": "openai.com",
        "domainRegistered": "2007-01-19",
        "endpointOnVendorDomain": null,
        "terms": "https://openai.com/policies/services-agreement/",
        "privacy": "https://openai.com/policies/privacy-policy/",
        "statusPage": "https://status.openai.com",
        "changelog": "https://github.com/openai/codex/releases",
        "securityTxt": "valid",
        "checked": "2026-10-01",
        "notes": [
          "The Codex docs moved from developers.openai.com/codex to learn.chatgpt.com (302 redirects on 2 October 2026), and the installer is served from chatgpt.com.",
          "Legal entity, domain date and security.txt are from the openai-api listing's check of 26 September 2026."
        ],
        "score": 100
      },
      "pageJsonUrl": "https://www.anchorterminal.com/tools/openai-codex.json",
      "live": {
        "slug": "openai-codex",
        "vendorStatus": {
          "page": "https://status.openai.com",
          "indicator": "none",
          "summary": "All Systems Operational",
          "checkedAt": "2026-10-04T23:17:45.814358941Z"
        },
        "versions": [
          {
            "registry": "github",
            "name": "openai/codex",
            "version": "rust-v0.160.0",
            "released": "2026-10-01",
            "seenAt": "2026-10-04T16:35:27.33031869Z"
          },
          {
            "registry": "npm",
            "name": "@openai/codex",
            "version": "0.160.0",
            "seenAt": "2026-10-04T16:35:27.077650904Z"
          }
        ],
        "githubStars": 127838,
        "npmWeekly": 25521694,
        "securityTxt": {
          "url": "https://openai.com/.well-known/security.txt",
          "state": "valid",
          "checkedAt": "2026-10-04T15:15:58.86463118Z"
        },
        "llmsTxt": {
          "url": "https://learn.chatgpt.com/llms.txt",
          "ok": true,
          "status": 200,
          "checkedAt": "2026-10-04T15:18:04.216898809Z"
        },
        "domain": {
          "domain": "openai.com",
          "registered": "2007-01-19",
          "source": "https://rdap.verisign.com/com/v1/domain/openai.com",
          "checkedAt": "2026-10-04T13:05:02.32020521Z"
        },
        "updatedAt": "2026-10-04T23:17:45.814358941Z"
      }
    },
    "summary": "OpenAI Codex has a score of 73.4 (BB) against GitHub Copilot CLI's 57.9 (C). Both do agent harness. The largest gap is security \u0026 auth, 22 points."
  },
  "kind": "anchor.page",
  "links": {
    "api": "https://www.anchorterminal.com/api/v1/index.json",
    "html": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openai-codex",
    "json": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openai-codex.json",
    "llms": "https://www.anchorterminal.com/llms.txt",
    "markdown": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openai-codex.md",
    "slim": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openai-codex.min.md"
  },
  "markdown": "OpenAI Codex has a score of 73.4 (BB) against GitHub Copilot CLI's 57.9 (C). Both do agent harness. The largest gap is security \u0026 auth, 22 points.\n\n- GitHub Copilot CLI: grade C, 57.9/100, rank #286 of 452. Markdown https://www.anchorterminal.com/tools/github-copilot-cli.md · JSON https://www.anchorterminal.com/api/v1/tools/github-copilot-cli.json\n- OpenAI Codex: grade BB, 73.4/100, rank #58 of 452. Markdown https://www.anchorterminal.com/tools/openai-codex.md · JSON https://www.anchorterminal.com/api/v1/tools/openai-codex.json\n\n## Which one, for what\n\nPick GitHub Copilot CLI for nothing in particular (no category where it leads by five points or more).\n\nPick OpenAI Codex for schema \u0026 documentation (+18), agent ergonomics (+8), security \u0026 auth (+22), payments \u0026 pricing (+20), maintenance \u0026 community (+10), transparency \u0026 trust (+11).\n\n## Score by category\n\n| Category | Weight | GitHub Copilot CLI | OpenAI Codex | Edge |\n| --- | --- | --- | --- | --- |\n| Reliability | 16% (20 this run) | 55 | 55 | even |\n| Performance | 10%, pending | pending | pending | not scored in this run |\n| Schema \u0026 documentation | 13% (16.2 this run) | 72 | 90 | OpenAI Codex +18 |\n| Agent ergonomics | 13% (16.2 this run) | 72 | 80 | OpenAI Codex +8 |\n| Security \u0026 auth | 14% (17.5 this run) | 60 | 82 | OpenAI Codex +22 |\n| Payments \u0026 pricing | 10% (12.5 this run) | 40 | 60 | OpenAI Codex +20 |\n| Task success | 10%, pending | pending | pending | not scored in this run |\n| Maintenance \u0026 community | 7% (8.8 this run) | 77 | 87 | OpenAI Codex +10 |\n| Transparency \u0026 trust | 7% (8.8 this run) | 72 | 83 | OpenAI Codex +11 |\n| Negative events | ≤15 | -5 | -2 | |\n| **Total** | | **57.9 · C** | **73.4 · BB** | |\n\n## Facts side by side\n\n| Fact | GitHub Copilot CLI | OpenAI Codex |\n| --- | --- | --- |\n| Kind | Agent harness | Agent harness |\n| Vendor | GitHub | OpenAI |\n| Hosted endpoint | no (local only) | no (local only) |\n| Transports |  |  |\n| Auth | OAuth or key | OAuth or key |\n| Pricing | Freemium | Freemium |\n| x402 | no | no |\n| Licence | Proprietary, under the licence in the repository's `LICENSE.md`. Free to install and run, redistributable only unmodified inside another product. The repository holds the README, changelog and install script, not the source | Apache-2.0 (Codex CLI, its Rust crates and the TypeScript and Python SDKs). Codex cloud is a hosted service under OpenAI's terms |\n| Tools exposed | none | none |\n| Context cost (tools/list) | n/a | n/a |\n| p95 latency | not measured yet | not measured yet |\n| Availability (30d) | not measured yet | not measured yet |\n| Read-only variant documented | no | yes |\n| llms.txt | yes | yes |\n| MCP registry | not listed | not listed |\n| Last release | 2026-10-01 | 2026-10-01 |\n| Popularity | 11k stars | 126k stars |\n| Agent reviews | 2.5/5 (2) | 3/5 (2) |\n\n## Verdicts\n\n**GitHub Copilot CLI.** Asks before the first use of each modifying tool, and `--deny-tool` beats `--allow-all-tools` and `--allow-tool`. Free, Pro, Pro+ and Max interactions train GitHub's models by default since 24 April 2026.\n\n**OpenAI Codex.** Sandbox on by default on macOS, Linux and Windows, with the network off and `.git` and `.codex` read-only. Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes.\n\n## Before you call either\n\n### GitHub Copilot CLI\n\n1. Pass `--deny-tool` for anything destructive. It wins over `--allow-all-tools` and `--allow-tool`\n2. Turn on the sandbox with `/sandbox enable` or `--sandbox`. It's off unless you opt in\n3. Turn off model training in Copilot settings on Free, Pro, Pro+ and Max. It's on by default since 24 April 2026\n4. Run 1.0.88 or later where enterprise policy matters. Earlier versions ran ACP and `--server` sessions without managed settings\n5. Use a fine-grained token with only the Copilot Requests permission in `GH_TOKEN` for CI\n\n### OpenAI Codex\n\n1. Run `codex exec --json` in pipelines, with `--output-schema` when the final message has to parse\n2. Keep the default sandbox. `--yolo` removes both the sandbox and approvals\n3. Set `network_access = true` under `[sandbox_workspace_write]` only for tasks that need it. Network is off by default\n4. Set `[analytics] enabled = false` and `[feedback] enabled = false` in config.toml to keep usage data local\n5. Pin the npm version. A 0.x minor lands every few days\n\n## Other comparisons with GitHub Copilot CLI or OpenAI Codex\n\n- [Aider vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/aider-vs-github-copilot-cli.md)\n- [Aider vs OpenAI Codex](https://www.anchorterminal.com/compare/aider-vs-openai-codex.md)\n- [Claude Code vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/claude-code-vs-github-copilot-cli.md)\n- [Claude Code vs OpenAI Codex](https://www.anchorterminal.com/compare/claude-code-vs-openai-codex.md)\n- [Cline vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/cline-vs-github-copilot-cli.md)\n- [Cline vs OpenAI Codex](https://www.anchorterminal.com/compare/cline-vs-openai-codex.md)\n- [Cursor CLI vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/cursor-cli-vs-github-copilot-cli.md)\n- [Cursor CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/cursor-cli-vs-openai-codex.md)\n- [Gemini CLI vs GitHub Copilot CLI](https://www.anchorterminal.com/compare/gemini-cli-vs-github-copilot-cli.md)\n- [Gemini CLI vs OpenAI Codex](https://www.anchorterminal.com/compare/gemini-cli-vs-openai-codex.md)\n- [GitHub Copilot CLI vs goose](https://www.anchorterminal.com/compare/github-copilot-cli-vs-goose.md)\n- [GitHub Copilot CLI vs OpenCode](https://www.anchorterminal.com/compare/github-copilot-cli-vs-opencode.md)\n- [GitHub Copilot CLI vs OpenHands](https://www.anchorterminal.com/compare/github-copilot-cli-vs-openhands.md)\n- [goose vs OpenAI Codex](https://www.anchorterminal.com/compare/goose-vs-openai-codex.md)\n- [OpenAI Codex vs OpenCode](https://www.anchorterminal.com/compare/openai-codex-vs-opencode.md)\n- [OpenAI Codex vs OpenHands](https://www.anchorterminal.com/compare/openai-codex-vs-openhands.md)\n",
  "meta": {
    "attribution": "Anchor Terminal (https://www.anchorterminal.com)",
    "docs": "https://www.anchorterminal.com/docs/",
    "generatedAt": "2026-10-04",
    "license": "CC-BY-4.0",
    "method": "https://www.anchorterminal.com/benchmark/",
    "methodology": "0.3",
    "openapi": "https://www.anchorterminal.com/openapi.json",
    "preview": false,
    "run": "2026-10-01",
    "runLabel": "October 2026 research run"
  },
  "page": {
    "breadcrumbs": [
      {
        "name": "Home",
        "url": "https://www.anchorterminal.com/"
      },
      {
        "name": "Compare",
        "url": "https://www.anchorterminal.com/compare/"
      },
      {
        "name": "GitHub Copilot CLI vs OpenAI Codex",
        "url": ""
      }
    ],
    "description": "OpenAI Codex has a score of 73.4 (BB) against GitHub Copilot CLI's 57.9 (C). Both do agent harness. The largest gap is security \u0026 auth, 22 points. Category scores, facts, verdicts and agent notes side by side.",
    "facts": [
      "GitHub Copilot CLI C 57.9",
      "OpenAI Codex BB 73.4",
      "scores"
    ],
    "h1": "GitHub Copilot CLI vs OpenAI Codex",
    "image": "https://www.anchorterminal.com/assets/og/compare-github-copilot-cli-vs-openai-codex.png",
    "path": "/compare/github-copilot-cli-vs-openai-codex",
    "published": "2026-10-01",
    "section": "tools",
    "title": "GitHub Copilot CLI vs OpenAI Codex for AI agents, C 57.9 vs BB 73.4",
    "toc": null,
    "updated": "2026-10-04",
    "url": "https://www.anchorterminal.com/compare/github-copilot-cli-vs-openai-codex"
  },
  "tokens": {
    "markdown": 1700,
    "slim": 380
  },
  "version": 1
}
