endueendue

Codex keeps working after you close the laptop: the DevDay 2026 updates

At DevDay 2026, OpenAI reworked Codex with shared cloud environments, a CLI with voice and an agents view, code review in the ChatGPT desktop app, and Codex Security Cloud for GitHub repositories. What changed, who can use it, and what to check first.

Colored lines of indented code sit between two large angle brackets, with a green cursor on the last line.

OpenAI made more than 20 announcements at DevDay 2026 on September 29. The Codex updates are the ones most likely to change a developer’s day. Work stops being tied to your laptop, and Codex now takes a first pass at code review and security checks.

Four things changed: cloud environments a team can share, a refreshed CLI with voice and a view for tracking agents, code review in the ChatGPT desktop app, and Codex Security Cloud, which scans GitHub repositories. On the same day the Agents API, which exposes the machinery behind Codex, gained computer use.

Below is how each piece works, which plans get it, and what to check before you rely on it.

At a glance

Announcement What changes Plans Status
Codex cloud environments Prepare repositories, dependencies and access once, reuse them for every task, share them with your team Plus, Pro, Business, Healthcare, Education, Enterprise Launched
Refreshed Codex CLI Start and steer tasks by voice, a new /agents view, better prompt editing, session resume and worktrees All plans Launched
Code review PR summaries, diffs and questions in the desktop app, plus automatic reviews while you’re away All plans GitHub generally available, GitLab in preview
Codex Security Cloud Scans GitHub repositories, watches new commits, prepares fixes Pro, Business, Enterprise, Edu Research preview
Agents API computer use Agents operate a browser hosted by OpenAI API, and Codex and ChatGPT Work on Pro 500 and Enterprise Agents API in public beta
Bedrock Managed Agents OpenAI agents that run inside AWS AWS customers Limited preview

Work leaves the laptop

OpenAI now describes three places to run Codex: your computer, your phone and the cloud.

  • Your computer: the CLI, the desktop app and the IDE extension work on your local repository.
  • Your phone: with Codex Remote, the ChatGPT iOS app can start tasks on a connected Mac or Windows PC, follow their progress, approve commands and review changed files. The work itself runs on the connected computer.
  • The cloud: tasks in Codex Cloud keep going while your computer sleeps, and you can pick up the results on the web, on mobile or in the desktop app.

The third one is the heart of this release. TechCrunch put it as cloud tasks becoming more persistent and configurable, instead of each one being an isolated remote sandbox.

Set up an environment once, then reuse it

A cloud environment is the shared setup your tasks start from: repositories, dependencies, tools and access settings. Creating one goes like this:

  1. In a new task on the ChatGPT web or desktop app, choose Work in > Cloud and select Create environment.
  2. Pick the GitHub repositories to check out.
  3. Codex inspects them, installs dependencies and tools, and runs the workflow to test it. It asks when access or information is missing.
  4. Review the result and select Publish.

You don’t write the installation script yourself. Codex records the setup it tested as an install script and a start skill, the instructions for starting services and checking they’re ready. After publishing, every new task gets its own isolated workspace from the environment, while a task already underway keeps its own files, uncommitted changes included. The documentation is clear that saved state doesn’t replace source control, so commit anything you need.

The handling of secrets is worth a look. Values a program reads directly go in as environment variables. Credentials for a specific HTTPS service go in as network secrets: programs only see a placeholder, and a proxy swaps in the real value for requests to the domains you allowed. Each person keeps their own tokens in a Personal vault.

In an Enterprise workspace you can share a prepared environment with colleagues. Everyone still gets separate working files, and editing the environment is a separate permission. In practice, an admin can prepare one environment with the right domains and secrets, and the whole team starts from it.

What changed in the CLI

OpenAI lists four CLI changes: starting and steering tasks by voice, a new /agents view for delegating and tracking several tasks at once, improvements to prompt editing, session resume and worktrees, and a cleaner terminal UI for long sessions. The CLI is available on all plans.

Here is a flow you can try with commands that are in the public documentation today:

npm install -g @openai/codex   # install or update (Homebrew: brew install --cask codex)
codex resume                   # pick up the last chat in this repository
codex cloud                    # open your cloud chats and hand a task to an environment

Inside a session:

  • Ctrl+G opens a long prompt in the editor set by VISUAL or EDITOR.
  • /agent or /subagents switches to a subagent’s thread so you can see what it is doing.
  • /review reviews your branch against its base, your uncommitted changes, or a specific commit, without touching the working tree.
  • /fork copies the current chat so you can try another approach.

CLI 0.159.0, released on the day of the event, adds an opt-in instant_interrupt setting that lets new input steer Codex while it is still responding. As of September 30, the command reference did not yet describe voice use or the /agents view in detail, so check the new features in the app after you update.

Code review in the desktop app

The ChatGPT desktop app now has Code Review. A pull request’s description, changed files, comments and CI checks sit on one screen. An inbox separates reviews requested from you, reviews requested from your team and PRs you authored, and you can mark files as viewed. Stack lets you move through a chain of dependent PRs.

Review with Codex starts a review in a new chat. You write review instructions once in settings and they apply across repositories. The documentation’s example asks for a short summary first, then a focus on behavior changes, data loss and missing edge-case tests.

One detail matters: reviewing in chat doesn’t post comments, approve or merge anything. You choose which findings to share, then use Submit review to comment, approve or request changes.

Automatic reviews while you’re away

Turn on Automatic review for a GitHub repository and Codex reviews new pull requests in the cloud before you open them. No cloud environment is needed for this. Its comments appear on GitHub and in Code Review. You can also ask for a review by writing @codex review in a PR comment. On GitHub, Codex only flags P0 and P1 issues, which keeps the comments focused.

To give a repository its own review rules, write them in AGENTS.md. For example:

## Code Review Rules

### Payments

- Money is computed in integers (the smallest currency unit). Flag any floating-point arithmetic.

GitLab is supported, at an earlier stage. Merge request support in Code Review is in preview, and the GitLab integration is in beta on all plans. On GitLab.com you need a project environment before you can turn on Codex reviews.

Codex Security Cloud

Codex Security Cloud is a plugin that scans connected GitHub repositories in Codex cloud. It is a research preview on the web and in the desktop app, for Pro, Business, Enterprise and Edu users.

It works in four steps:

  1. Analysis reads the code and builds a threat model: where outside input enters, the trust boundaries, the authentication assumptions.
  2. Scanning reviews the whole repository once (Repository) or watches each new commit (Commit changes).
  3. Validation tries to reproduce each likely issue in an isolated container. Findings that reproduce are marked validated, with logs as evidence.
  4. Remediation proposes a minimal patch where it can. A pull request is only created when a person reviews it and selects Create draft pull request.

Patches are never applied automatically. OpenAI presents the tool as a complement to existing static analysis (SAST) and says human security review is still needed.

The announcement mentions Daybreak Blue, one of OpenAI’s cybersecurity access programs. It grants approved access for defensive security work, and using it through the API normally takes organization approval and project setup. The point of this launch is that Codex Security Cloud gives you the models offered through Daybreak Blue without that separate application.

Two pieces of agent news for developers

Computer use in the Agents API. The Agents API opens up the harness and infrastructure that run Codex. It entered public beta on September 10, and there is no charge beyond the tokens and tools your agents use. Agents can now operate a browser hosted by OpenAI: add { "type": "computer_use" } to the tools and turn on the desktop in the hosted environment. The documentation spells out the guardrails. The browser asks the user before it opens each new website, and sign-in supports email, passwords and verification codes only. It also notes that approving a website doesn’t mean each individual action, such as a purchase, gets confirmed.

Bedrock Managed Agents. AWS first announced this service as a limited preview in April. OpenAI says it has now brought the core capabilities of the Agents API to it, adapted to work natively in AWS. The harness and model inference both run inside Amazon Bedrock, and authentication uses AWS IAM. The AWS page still lists it as a limited preview.

Pricing and access

Plan Monthly price What you get in Codex
Free, Go $0, $8 GPT-6 Luna in the desktop app (rolling out)
Plus $20 Codex on the web, CLI, IDE and iOS, plus cloud integrations such as automatic code review and Slack
Pro $100, $200 or $500 Everything in Plus, with Astra Ultrafast on the $500 plan
Business $20 per user billed annually (2+ users), $25 billed monthly Larger cloud VMs and admin controls
Enterprise, Edu Contact sales Data retention and residency controls, audit logs
API key sign-in API pricing CLI, SDK and IDE, without cloud features such as GitHub code review or Slack

ChatGPT Work and Codex share the same pricing, credits and usage limits. The conditions and billing multipliers for Ultrafast are covered in our post on GPT-6.1 Sol and Ultrafast.

What to keep in mind

  • GitLab is early. GitLab support in Code Review is in preview and the integration is in beta. If your team is on GitLab, start with a small repository.
  • Plan to move old cloud environments. The legacy experience (Codex Cloud Legacy) still supports code review and the Linear and GitHub integrations for now, but OpenAI says it plans to deprecate it.
  • Security scans cover GitHub repositories only. For a local repository, use the separate Codex Security plugin or its CLI.
  • GPT-5.5 is leaving. On October 14, GPT-5.5 retires from ChatGPT, ChatGPT Work and Codex on all plans. The API is not affected. If you pinned GPT-5.5 in your settings, switch before then.
  • A lot changed at once. Every, which tested the products before the event, warned that adding so much at once risks losing the simplicity and coherence that made Codex good. For features whose documentation is still thin, like voice and the /agents view, try them yourself before making them a team standard.

Sources