Codex Cloud Version

Codex Web is the cloud version, letting you access Codex from any device and run tasks in an isolated environment.


Access Codex Web

Accessing Cloud Codex:

https://chatgpt.com/codex

Prerequisites

  • ChatGPT Plus / Pro / Business / Enterprise plans
  • Or use OpenAI API Key

When using an API Key, some cloud features may be unavailable.


Cloud Environments

Environment is a core concept of Codex Web; each environment is an isolated workspace.

Create environment

  1. Connecting a GitHub account
  2. Select a repository
  3. Configuring setup scripts and environment variables
  4. Selecting a network access policy

Task execution workflow

Cloud tasks are executed as follows:

  1. Create a container, clone the repository to the selected branch
  2. Run setup scripts to install dependencies
  3. Apply network access settings
  4. The agent executes the task (edits code, runs commands, verifies results)
  5. Display results and file changes

Default image

The cloud uses something calleduniversalDefault container image:

  • Pre-installed common languages: Python, Node.js, Go, Rust
  • Includes common tools: npm, pip, cargo, git
  • Runtime version can be pinned

Version pinning

Pinned version

# Environment settings

# Pin Python version
python_version = "3.11"

# Pin Node.js version
node_version = "20"

Setup scripts

Setup scripts automatically run when the container is created:

Automatic detection

Codex automatically identifies the project type and performs the corresponding installation:

  • Node.js: automatically run npm install / yarn / pnpm
  • Python: automatically run pip install / poetry install

Manual script

Custom setup scripts

# Setup Script
# Configure in environment settings

npm install
npm run build
pip install -r requirements.txt

Maintenance script

Maintenance scripts run when cached containers start:

  • Used to update dependencies or rebuild
  • Faster than a full setup

Setup scripts and the agent run in separate Bash sessions, so export commands do not persist.


Environment variables and secrets

Environment Variables

Environment variables are available throughout the task:

Set environment variables

# Environment Variables
NODE_ENV=production
DEBUG=false
API_ENDPOINT=https://api.example.com

Secrets

Secrets are used to store sensitive information:

  • Additional encrypted storage
  • Decrypted only when the task runs
  • Only available in setup scripts
  • Automatically removed during the agent phase
TypeVisibility scopePurpose
Environment VariablesSetup script + AgentGeneral configuration
SecretsSettings script onlyAPI Key, password

Network access control

Network access for cloud environments is restricted by default:

Default settings

PhaseNetwork access
Setup scriptsAllowed (required for installing dependencies)
AgentBlocked (default)

Agent network access options

SettingsDescription
OffCompletely block network access
OnAllow network access (domains can be restricted)

Domain whitelist

Domain configuration

# Network configuration

# Whitelist presets
domain_allowlist = "common-dependencies"
# Includes: github.com, npmjs.com, pypi.org, etc.

# Custom domains
domain_allowlist = [
    "github.com",
    "api.mycompany.com"
]

# Restrict HTTP methods
allowed_methods = ["GET", "HEAD", "OPTIONS"]

Security risks

Enabling Agent network access increases risks:

  • Prompt injection (obtaining instructions from malicious web pages)
  • Data leakage (sending code or keys to external parties)
  • Download malicious dependencies

Enable Agent network access only when necessary, and restrict it using a domain whitelist.


Container cache

The cloud caches container state to speed up subsequent tasks:

  • Cache for up to 12 hours
  • Automatically invalidated when setup scripts or environment variables change
  • New tasks start faster

Cloud task management

Create task

  1. Select environment
  2. Enter a task description
  3. Select model and configuration
  4. Start task

Task monitoring

  • View progress in real time
  • View file changes
  • Check command output

Result processing

  • View changes diff
  • Create Pull Request
  • Download changed files

Parallel tasks

The cloud supports running multiple tasks in parallel:

  • Handle different features simultaneously
  • Multiple environments work independently
  • Improve overall efficiency

Avoid multiple tasks modifying the same file simultaneously; otherwise, conflicts will arise.


FAQ

Q: What is the difference between Cloud and local?

Cloud runs on remote servers, making it suitable for parallel tasks and remote access; local mode directly operates on your files.

Q: How is billing handled?

Cloud tasks consume credits, and costs are calculated based on the model and usage.

Q: Can it access local files?

The cloud cannot access local files, but can sync via Git.

Q: When is network access needed?

This is only needed when the Agent requires real-time data or external APIs; setup scripts are usually sufficient.

other extensions