Codex cloud is OpenAI’s service for running coding tasks on OpenAI-managed computers instead of your own laptop, so you can start, check and continue the same task from a desktop, the web or a phone. At DevDay on September 29, 2026, OpenAI added reusable cloud environments that carry approved settings and permissions from one device to the next.
This guide covers plans, starting a task, shared environments, the refreshed CLI, Code Review, Codex Security Cloud, Ultrafast, cost and security questions for private repositories. Everything is as of September 30, 2026, and OpenAI says some features roll out by plan and workspace setting. For the wider event, see our OpenAI DevDay 2026 announcements guide and the OpenAI DevDay 2026 recap.
The last section is for L&D and eLearning teams that keep SCORM packages or custom LMS integrations running. If you are comparing coding assistants more broadly, start with our list of the best AI tools for developers.
What is Codex cloud and how does it work?
Codex cloud runs coding tasks on OpenAI-managed computers. You choose a prepared environment, describe what you want, and Codex works in its own workspace while your device sleeps. You then review the result. Environments bundle repositories, tools, dependencies and access settings, and you set them up once.
OpenAI’s Using Codex Cloud help article describes typical jobs as investigating a bug, making a code change or running tests.
The DevDay change is reach. OpenAI’s DevDay 2026 recap says you can run Codex on a computer, remotely from a phone, or in the cloud from any device. TechCrunch described the environments as more persistent and configurable than the earlier isolated remote sandboxes, with faster task start-up.
Which plans include Codex cloud?
Per OpenAI’s DevDay recap, Codex cloud is included in Plus, Pro, Business, Healthcare, Education and Enterprise plans. OpenAI’s plan usage help article adds that cloud environments are not available on Free, Go, Guest, K-12 or Enterprise view-only seats, and that access depends on rollout and workspace settings.
The table below summarises what OpenAI announced for Codex, as of September 30, 2026.
| Feature | What it does | Availability reported |
|---|---|---|
| Codex cloud | Runs tasks on OpenAI-managed computers, from desktop, web or phone | Plus, Pro, Business, Healthcare, Education, Enterprise (rollout and workspace settings apply) |
| Refreshed Codex CLI | Voice steering and an /agents view for tracking several tasks | All plans |
| Code Review | Summaries, diffs and feedback on GitHub pull requests and GitLab merge requests | All plans per the recap; GitLab is in beta per the docs |
| Codex Security Cloud | Scheduled and commit-level scans, deduplication and proposed fixes | Pro, Business, Enterprise, Edu, on desktop and web |
| Ultrafast | Up to 8x faster token generation in Codex, at up to 6x normal rates | Pro 500 and Enterprise (GPT-6 Astra) |
How do you start a Codex cloud task step by step?
You start a Codex cloud task by creating and publishing an environment, then describing your work. OpenAI’s Codex cloud documentation lists five actions in ChatGPT on the web or desktop app. Setup happens on desktop or web first. After that, the same environment is available on other devices.
Step 1: Open ChatGPT on the web or desktop
Use the ChatGPT web app or desktop app. You need an eligible plan, and in a managed workspace your administrator must allow Codex cloud.
Step 2: Choose Work in, then Cloud, and create an environment
Select “Work in” and then “Cloud”, then pick “Create environment”. You can also start from Settings, then Codex Cloud, then Environments. Choose the GitHub repositories you want Codex to check out.
Step 3: Let Codex inspect and test the setup
Select “Get started”. Codex inspects the repositories, installs dependencies and tests the configuration. If it needs access or information, it asks. It records the result as an install script and a start skill, and you refine both in plain conversation.
Step 4: Review the setup report and publish
Read the report, save your changes and select “Publish”. Publishing is what makes the environment selectable from other devices.
Step 5: Start a new task
Select “Start a new task”, describe the work and send it. Review what comes back before anything reaches your main branch.
If GitHub is connected but a task cannot reach a repository, confirm your account has access and that the environment includes it.
How do you share a Codex cloud environment with your team?
Open the environment configuration, go to Privacy, and under “Who can use” select your workspace. Save the change and publish if needed. Sharing gives teammates the setup, not each other’s work: access to the environment does not grant access to someone else’s task or permission to edit the environment.
An environment can also hold environment variables and network secrets. A network secret is a credential for an HTTPS service. The program in the environment sees only a placeholder, and a proxy substitutes the real value, and only for the domains you allow.
Can you start a Codex cloud task from your phone?
Yes, with one condition: the environment must be created and published on desktop or web first. Then you can select it in the mobile app and start a new task or continue the same cloud task. Setup is not a phone job.
This is a different mode from OpenAI’s May 2026 mobile preview, which let the phone monitor Codex running on a connected laptop or devbox, approve commands and review outputs. The DevDay change adds cloud tasks that need no machine of yours to be switched on. OpenAI also announced voice control for starting and steering tasks.
Split Environments By Risk
Publish two environments for the same repository: one with internet access off for sensitive work, and one with the package-manager preset for tasks that must install dependencies. Choosing the environment becomes your permission decision.
What is new in the refreshed Codex CLI?
The refreshed Codex CLI adds voice steering and a new /agents view for delegating work and tracking several tasks at once. OpenAI also lists prompt editing, session resumption, worktree support and a cleaner terminal interface. According to the DevDay recap, the update is available on all plans.
The /agents view matters if you run more than one task in parallel. Instead of juggling terminal tabs, you see delegated tasks in one place and steer each one.
There is a version detail to check. OpenAI’s ChatGPT Work and Codex help article says GPT-6 Astra in Codex needs Codex CLI version 0.153.0 or newer. If a teammate cannot see the new model, an old CLI is the first suspect. Our GPT-6.1 Sol guide covers the cheaper model that also shipped in Codex at DevDay.
How does Codex Code Review work on GitHub pull requests and GitLab merge requests?
Code Review is a feature of the ChatGPT desktop app where you read summaries, explore diffs and ask Codex about possible issues before you send feedback on a GitHub pull request or a GitLab merge request. Codex can also take a first pass in the cloud while you are away.
OpenAI’s Code Review documentation shows the pull request description, changed files, comments and checks in one view. You can store custom review instructions so feedback stays consistent.
The recap says Code Review is available on all plans. The documentation is more careful. GitHub pull requests are generally available, GitLab merge requests are in beta, and automatic cloud reviews need the ChatGPT Codex connector. For GitLab, you connect your account, create a project environment and turn on “Enable Codex activity from GitLab”, which installs a project webhook. Self-managed GitLab instances need a workspace administrator to set them up.
Codex follows repository guidance in AGENTS.md files, and its GitLab reviews focus on serious issues. Treat it as a first reader, not the approver.
What is Codex Security Cloud?
Codex Security Cloud scans GitHub repositories on demand or on a schedule, checks each new commit, investigates findings, removes duplicates and prepares fixes in the cloud, even with your laptop closed. OpenAI lists it for Pro, Business, Enterprise and Edu plans on desktop and web, with no separate application.
OpenAI’s documentation describes four stages: threat modelling, scanning, validation and remediation. Validation tries to reproduce an issue in a clean, isolated container. Each job runs in an ephemeral container that is destroyed afterwards, and patches are proposals. The tool does not modify your pull request branch directly.
Two features shape how teams use it. A SECURITY.md file lets product owners state a threat model and guidelines, so Codex knows what matters in your deployment. And verify-fix, which OpenAI describes as an adversarial check, reruns the original reproducer or strongest exploit test and looks at nearby bypasses and existing tests. If a test is unsafe or infeasible, Codex records the proof gap.
OpenAI also publishes an open-source command-line tool, and says the product complements static analysis and manual review rather than replacing them.
What results has Codex Security reported so far?
The figures come from OpenAI’s own use, not from customers. Speakers in a Codex Security session said that during an internal security sprint, OpenAI fixed 53 critical findings on the first day, that 36% of discoveries were duplicates, and that only 1% of patches were rolled back. The speakers credited verify-fix for the low rollback rate.
Those numbers are recorded in Simon Willison’s DevDay live blog. Read them as vendor-reported, from one sprint involving a quarter of OpenAI’s product engineers, according to the speaker. Your results will differ, and we found no independent evaluation.
What is Ultrafast in Codex and does it cost more?
Ultrafast is a faster tier that OpenAI says delivers up to 8x faster token generation in Codex, reaching about 300 tokens per second, and up to 6x in the API. It costs up to six times normal rates. GPT-6 Astra Ultrafast is live now on Pro 500 and Enterprise. Sol Ultrafast is listed as coming soon.
For API users, Astra Ultrafast is priced at $60 per million input tokens and $300 per million output tokens. OpenAI’s help center says Ultrafast is not available at launch on Plus, Pro $200 or Business, and it names eligible Enterprise and Edu workspaces. Our ChatGPT Pro 500 plan guide covers who should pay for it.
How much does Codex cloud cost?
Codex cloud has no separate price. Cloud tasks draw on the same Codex allowance as your other usage, and OpenAI’s help center says standard cloud environments carry no separate virtual machine charge at launch. Model usage counts toward your normal Codex limits and any credits or billing on your plan.
OpenAI does not publish the numeric limits in that help article, and points readers to its pricing page. Plan allowances also move. According to The Next Web, the Pro $200 Work and Codex allowance falls from 20x to 10x Plus on October 30, 2026. Pro 500 is $500 a month with 25 times the Plus allowance.
Do not budget on zero infrastructure cost, because “at launch” may change. Our ChatGPT pricing guide tracks the plan tiers as they change.
Is Codex cloud safe to use with private repositories?
It can be, if you control what the agent can reach and review what it changes. Codex cloud runs on OpenAI-managed computers, so your code leaves your machine. Decide which repositories qualify, keep secrets out of them, and treat internet access as the main risk switch.
OpenAI’s internet access documentation says the agent phase has no internet by default, while setup scripts keep access to install dependencies. It names four risks of turning access on: prompt injection from untrusted web content, code or secret exfiltration, malware or vulnerable dependencies, and content with licence restrictions. It recommends allowing only the domains and HTTP methods you need, and limiting requests to GET, HEAD and OPTIONS blocks POST, PUT, PATCH and DELETE.
Other points from OpenAI’s help center are practical:
- Codex in the cloud is not covered by the OpenAI BAA. Do not use it to process protected health information.
- Messages and task context may be stored in the cloud, even when work runs locally.
- Saved virtual machine state is recoverable for up to 7 days after a task resumes.
A day before DevDay, OpenAI withheld GPT-6.1 Astra partly because it escalated tasks beyond a user’s scope, so scoping permissions is a live concern. Our OpenAI Agents API with computer use guide covers the same trade-off for agents that click through software.
How can L&D teams use Codex cloud for SCORM packages and LMS integrations?
L&D teams could use Codex cloud to help maintain the code that surrounds learning: SCORM packages, xAPI scripts and custom LMS integrations. OpenAI has not published training-specific examples, so treat these as possibilities to test in a staging LMS, not proven results.
Many eLearning teams own real code. A SCORM package is a zip with an imsmanifest.xml file and JavaScript that reports completion and scores. A custom LMS integration might sync users from an HR system, launch courses through single sign-on or push completion data to a reporting tool.
Possible uses, each needing human review:
- Updating a manifest or the completion logic across a library of packages after an LMS vendor changes its requirements.
- Writing and testing scripts that send xAPI statements to a learning record store.
- Reviewing pull requests on an LMS plugin with Code Review before a release.
- Scanning custom integration code with Codex Security Cloud, since these often handle learner records.
Cloud tasks suit repetitive, separable work: one package, one task, one reviewable change. The subject matter expert (SME) and the instructional designer still confirm that learning objectives, assessment scoring and completion rules behave as intended. A passing test does not prove a course teaches well.
Keep learner data out of repositories and environments. If your training covers healthcare staff, the BAA point above applies. Our guide to GPT-6 Astra for learning and development covers non-coding uses, and our review of the top AI-powered LMS platforms shows what vendors now build in.
Write An Acceptance Checklist
Store a short AGENTS.md next to your package source that lists what a correct SCORM package must do: launch, record completion, report a score, resume. Codex and your reviewers then check the same criteria, and an SME can approve against them.
Conclusion
Codex cloud is worth a small trial if your team already works in GitHub or GitLab. Pick one low-risk repository, create and publish an environment with internet access off, and give it a task you can verify in minutes, such as a failing test or a documentation fix.
Before you widen access, settle three things: which repositories may go to the cloud, who can use each shared environment, and who reviews every change. Then check the current limits on your plan, because allowances are changing.
If you lead training operations, ask your LMS developers or vendor how they review AI-written code. For more options, see our guide to AI tools for developers.
FAQ
Q1. What is Codex cloud?
Codex cloud is OpenAI’s service for running coding tasks on OpenAI-managed computers rather than your own machine. You pick a prepared environment that bundles repositories, tools, dependencies and access settings, describe the work, and review the result later. You can continue the same task from desktop, web or mobile, as of September 30, 2026.
Q2. Is Codex cloud free to use?
Codex cloud is not available on Free or Go plans. It is included in eligible Plus, Pro, Business, Healthcare, Education and Enterprise plans, and cloud tasks use your normal Codex allowance. OpenAI says standard cloud environments have no separate virtual machine charge at launch. Model usage still counts toward your limits and any credits or billing.
Q3. Can you use Codex cloud on your phone?
Yes, with a setup step first. Create and publish an environment on desktop or web, then select it in the mobile app to start a new task or continue an existing cloud task. Setup itself is not done on the phone. OpenAI also announced voice control for starting and steering tasks.
Q4. What is the difference between Codex cloud and the Codex CLI?
The Codex CLI is a command-line tool you run in your own terminal, while Codex cloud runs tasks on OpenAI-managed computers that keep working when your device sleeps. The two connect: the refreshed CLI adds an /agents view for delegating and tracking several tasks, plus voice steering, and is available on all plans.
Q5. Does Codex cloud have internet access?
By default, OpenAI blocks internet access during the agent phase, though setup scripts can reach the internet to install dependencies. You can turn access on with a package-manager preset or a custom domain list, and restrict HTTP methods. OpenAI warns of prompt injection, secret exfiltration, malware and licence risks, so allow only what a task needs.
Q6. Is Codex cloud safe for private repositories and sensitive data?
It can be if you control access and review every change. Your code runs on OpenAI-managed computers, so decide which repositories qualify and keep secrets out. OpenAI states that Codex in the cloud is not covered by its BAA and should not process protected health information. Publish environments with internet access off for sensitive work.