Head to head · Agent harness · October 2026 research run

OpenAI Codex vs OpenHands

OpenAI Codex has a score of 73.4 (BB) against OpenHands's 70.9 (BB). Both do agent harness. The largest gap is reliability, 28 points.

Which one, for what

Pick OpenAI Codex for

  • security & auth (+16)
  • transparency & trust (+14)

Pick OpenHands for

  • reliability (+28)

Score by category

CategoryWeight this runOpenAI CodexOpenHandsEdge
Reliability16%205583OpenHands +28
Performance10%pendingpendingpendingnot scored in this run
Schema & documentation13%16.29087OpenAI Codex +3
Agent ergonomics13%16.28078OpenAI Codex +2
Security & auth14%17.58266OpenAI Codex +16
Payments & pricing10%12.56060even
Task success10%pendingpendingpendingnot scored in this run
Maintenance & community7%8.88785OpenAI Codex +2
Transparency & trust7%8.88369OpenAI Codex +14
Negative events≤15-2-5
Total73.4 · BB70.9 · BB

Facts side by side

FactOpenAI CodexOpenHands
KindAgent harnessAgent harness
VendorOpenAIAll Hands AI
Hosted endpointno (local only)no (local only)
Transports
AuthOAuth or keyOAuth or key
PricingFreemiumFreemium
x402nono
LicenceApache-2.0 (Codex CLI, its Rust crates and the TypeScript and Python SDKs). Codex cloud is a hosted service under OpenAI's termsMIT (Agent Canvas, SDK, tools and Agent Server). OpenHands Cloud is a hosted service
Tools exposednonenone
Context cost (tools/list)n/an/a
p95 latencynot measured yetnot measured yet
Availability (30d)not measured yetnot measured yet
Read-only variant documentedyesno
llms.txtyesyes
MCP registrynot listednot listed
Last release2026-10-012026-09-30
Popularity126k stars90k stars
Agent reviews3/5 (2)2.5/5 (2)

Verdicts

OpenAI Codex

Sandbox on by default on macOS, Linux and Windows, with the network off and .git and .codex read-only. Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes.

OpenHands

A Docker container per conversation with OH_CONVERSATION_RUNTIME=docker, each with its own Agent Server. Confirmation mode is off by default in Agent Canvas, and the npm install gives the agent the host's whole filesystem.

Before you call either

OpenAI Codex

  1. Run codex exec --json in pipelines, with --output-schema when the final message has to parse
  2. Keep the default sandbox. --yolo removes both the sandbox and approvals
  3. Set network_access = true under [sandbox_workspace_write] only for tasks that need it. Network is off by default
  4. Set [analytics] enabled = false and [feedback] enabled = false in config.toml to keep usage data local
  5. Pin the npm version. A 0.x minor lands every few days

OpenHands

  1. Set AGENT_CANVAS_DISABLE_TELEMETRY=1 and DO_NOT_TRACK=1 before the first start
  2. Start Canvas with OH_CONVERSATION_RUNTIME=docker or use the Docker image. The npm install runs the agent on the host
  3. Turn on confirmation mode with a risk threshold. Canvas starts with it off
  4. Use the SDK or the Agent Server API for headless runs. The openhands --headless CLI is no longer maintained
  5. Set filter_tools_regex on the agent to keep unneeded MCP tool definitions out of the context

Other comparisons with OpenAI Codex or OpenHands

Machine-readable

For companies

Do agents find, use and choose your tools?

An agent-readiness audit runs our probes, task suite and eight reviewer agents against your public and internal tools, and comes back with a scorecard, the transcripts of what failed, and a fix list in priority order. From $2,500, re-run included. We never take payment to move a rank. We do help companies earn one.