Codex Cloud Version
Codex Web is the cloud version, letting you access Codex from any device and run tasks in an isolated environment.
Access Codex Web
Accessing Cloud Codex:
https://chatgpt.com/codex
Prerequisites
- ChatGPT Plus / Pro / Business / Enterprise plans
- Or use OpenAI API Key
When using an API Key, some cloud features may be unavailable.
Cloud Environments
Environment is a core concept of Codex Web; each environment is an isolated workspace.
Create environment
- Connecting a GitHub account
- Select a repository
- Configuring setup scripts and environment variables
- Selecting a network access policy
Task execution workflow
Cloud tasks are executed as follows:
- Create a container, clone the repository to the selected branch
- Run setup scripts to install dependencies
- Apply network access settings
- The agent executes the task (edits code, runs commands, verifies results)
- Display results and file changes
Default image
The cloud uses something calleduniversalDefault container image:
- Pre-installed common languages: Python, Node.js, Go, Rust
- Includes common tools: npm, pip, cargo, git
- Runtime version can be pinned
Version pinning
Pinned version
# Pin Python version
python_version = "3.11"
# Pin Node.js version
node_version = "20"
Setup scripts
Setup scripts automatically run when the container is created:
Automatic detection
Codex automatically identifies the project type and performs the corresponding installation:
- Node.js: automatically run npm install / yarn / pnpm
- Python: automatically run pip install / poetry install
Manual script
Custom setup scripts
# Configure in environment settings
npm install
npm run build
pip install -r requirements.txt
Maintenance script
Maintenance scripts run when cached containers start:
- Used to update dependencies or rebuild
- Faster than a full setup
Setup scripts and the agent run in separate Bash sessions, so export commands do not persist.
Environment variables and secrets
Environment Variables
Environment variables are available throughout the task:
Set environment variables
NODE_ENV=production
DEBUG=false
API_ENDPOINT=https://api.example.com
Secrets
Secrets are used to store sensitive information:
- Additional encrypted storage
- Decrypted only when the task runs
- Only available in setup scripts
- Automatically removed during the agent phase
| Type | Visibility scope | Purpose |
|---|---|---|
| Environment Variables | Setup script + Agent | General configuration |
| Secrets | Settings script only | API Key, password |
Network access control
Network access for cloud environments is restricted by default:
Default settings
| Phase | Network access |
|---|---|
| Setup scripts | Allowed (required for installing dependencies) |
| Agent | Blocked (default) |
Agent network access options
| Settings | Description |
|---|---|
| Off | Completely block network access |
| On | Allow network access (domains can be restricted) |
Domain whitelist
Domain configuration
# Whitelist presets
domain_allowlist = "common-dependencies"
# Includes: github.com, npmjs.com, pypi.org, etc.
# Custom domains
domain_allowlist = [
"github.com",
"api.mycompany.com"
]
# Restrict HTTP methods
allowed_methods = ["GET", "HEAD", "OPTIONS"]
Security risks
Enabling Agent network access increases risks:
- Prompt injection (obtaining instructions from malicious web pages)
- Data leakage (sending code or keys to external parties)
- Download malicious dependencies
Enable Agent network access only when necessary, and restrict it using a domain whitelist.
Container cache
The cloud caches container state to speed up subsequent tasks:
- Cache for up to 12 hours
- Automatically invalidated when setup scripts or environment variables change
- New tasks start faster
Cloud task management
Create task
- Select environment
- Enter a task description
- Select model and configuration
- Start task
Task monitoring
- View progress in real time
- View file changes
- Check command output
Result processing
- View changes diff
- Create Pull Request
- Download changed files
Parallel tasks
The cloud supports running multiple tasks in parallel:
- Handle different features simultaneously
- Multiple environments work independently
- Improve overall efficiency
Avoid multiple tasks modifying the same file simultaneously; otherwise, conflicts will arise.
FAQ
Q: What is the difference between Cloud and local?
Cloud runs on remote servers, making it suitable for parallel tasks and remote access; local mode directly operates on your files.
Q: How is billing handled?
Cloud tasks consume credits, and costs are calculated based on the model and usage.
Q: Can it access local files?
The cloud cannot access local files, but can sync via Git.
Q: When is network access needed?
This is only needed when the Agent requires real-time data or external APIs; setup scripts are usually sufficient.
other extensions