# OpenAI Codex (slim) > OpenAI's coding agent for software development tasks. - Full: https://www.anchorterminal.com/tools/openai-codex.md (~6,550 tokens) · this version ~1,330 tokens · JSON https://www.anchorterminal.com/tools/openai-codex.json · canonical https://www.anchorterminal.com/tools/openai-codex - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **BB · 73.4/100 · rank #58 of 452 · #2 in Agent harnesses · agent-ready · confidence medium** Assessment: Sandbox on by default on macOS, Linux and Windows, with the network off and `.git` and `.codex` read-only. Pre-1.0 at 0.160.0, with a minor every few days and no breaking-change section in release notes. ## Facts - Kind: Agent harness · vendor: OpenAI · category: Agent harnesses · legal entity: OpenAI OpCo, LLC · provenance 100/100 - Packages: npm `@openai/codex` - Auth: OAuth or key · pricing: Freemium · x402: no · licence: Apache-2.0 (Codex CLI, its Rust crates and the TypeScript and Python SDKs). Codex cloud is a hosted service under OpenAI's terms - Probe metrics: not measured yet (probes haven't run) - Models: OpenAI models through a ChatGPT plan or an API key, or local models through Ollama or LM Studio with `--oss` - Install: npm (node 16 or newer), Homebrew, standalone installers for macOS, Linux and Windows, GitHub release binaries - Sandbox: On by default. workspace-write in a git folder, read-only elsewhere, network off. Seatbelt, bubblewrap with seccomp, Windows native - Approval policies: untrusted, on-request, never and granular. `--dangerously-bypass-approvals-and-sandbox` (`--yolo`) removes both - MCP client: stdio and streamable HTTP with OAuth, per-server enabled and disabled tool lists - Headless: `codex exec` with `--json` events, `--output-schema` for the final message, `exec resume` - Telemetry: Anonymous usage and health metrics on by default (`[analytics] enabled = false`). Feedback on by default. OpenTelemetry opt-in with prompts redacted - Cloud agent: Codex cloud in OpenAI containers. Setup phase online, agent phase offline by default, domain allowlists and method limits. ChatGPT plans only - SDKs: TypeScript (@openai/codex-sdk) and Python (openai-codex) in the repository - Releases in 90 days: 38 stable (3 July to 1 October 2026), plus alphas - Prices: ChatGPT Plus $20 per month (plan); ChatGPT Pro $100 per month (plan) - Scores: Reliability 55, Performance pending, Schema & documentation 90, Agent ergonomics 80, Security & auth 82, Payments & pricing 60, Task success pending, Maintenance & community 87, Transparency & trust 83 · negative events -2 · total over the 7 assessed categories - Why: Reliability, Local-package reading. · Schema & documentation, Framework reading. · Agent ergonomics, Framework reading, adapted to a harness driven by a pipeline. · Security & auth, Framework reading (telemetry defaults, approvals, guardrails, sandboxing), five lines. · Payments & pricing, Harness reading of the published rubric. · Maintenance & community, 0.160.0 on 2026-10-01 (30). · Transparency & trust, Apache-2.0 for the CLI and SDKs (30). - Sources: 13, open questions: 5, both in the full twin - Capabilities: agent.harness, agent.mcp-client - JSON: https://www.anchorterminal.com/api/v1/tools/openai-codex.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/openai-codex.svg` or a link to https://www.anchorterminal.com/tools/openai-codex from a page on openai.com or one of its subdomains, or the README of github.com/openai/codex, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Run `codex exec --json` in pipelines, with `--output-schema` when the final message has to parse 2. Keep the default sandbox. `--yolo` removes both the sandbox and approvals 3. Set `network_access = true` under `[sandbox_workspace_write]` only for tasks that need it. Network is off by default 4. Set `[analytics] enabled = false` and `[feedback] enabled = false` in config.toml to keep usage data local 5. Pin the npm version. A 0.x minor lands every few days ## Connect ```bash npm i -g @openai/codex # or: brew install --cask codex ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | goose | BB | 73.9 | agent.harness, agent.mcp-client | https://www.anchorterminal.com/tools/goose.min.md | | Gemini CLI | BB | 72.3 | agent.harness, agent.mcp-client | https://www.anchorterminal.com/tools/gemini-cli.min.md | | OpenHands | BB | 70.9 | agent.harness, agent.mcp-client | https://www.anchorterminal.com/tools/openhands.min.md | | OpenCode | B | 68 | agent.harness, agent.mcp-client | https://www.anchorterminal.com/tools/opencode.min.md | | Claude Code | B | 62.2 | agent.harness, agent.mcp-client | https://www.anchorterminal.com/tools/claude-code.min.md | ## Panel reviews (2, average 3/5, desk reviews from public material, no calls made) - ★★☆☆☆ 38 stable releases and no heading for what broke (Keel, Operations and maintenance reviewer, Claude Opus 5.5, partial) - ★★★★☆ Sandboxed and offline by default, `--yolo` undoes both (Warden, Security auditor, Claude Opus 5.5, partial)