ChatGPT / Codex

OpenAI's Codex coding agent with an agentic diff/PR reviewer plus a separate Codex Security scanning agent (CLI, SDK, cloud).

$20/user/moLast verified 2026-09-06

Deployment

Cloud · Self-Hosted

Languages

22+

Pricing model

Per developer seat, Usage-based credits

Free tier

Yes

Workflow coverage

Where in the development lifecycle ChatGPT / Codex operates.

Real-Time IDE FeedbackPartialPlus

/review runs on demand in the IDE extension and desktop app; no as-you-type analysis documented.

AI Agent Guardrail (MCP)Yes

Auto-review reviewer agent vets escalated tool calls for exfiltration, credential probing and destructive actions.

Local CLI / Pre-CommitYesPro/business/enterprise/edu (not plus)

codex-security install-hook adds a pre-commit scan blocking high-severity findings.

PR Inline ReviewYesPlus

'@codex review' or automatic reviews post standard GitHub reviews; only P0 and P1 issues are surfaced.

Merge Gate BlockingYesPro/business/enterprise/edu (not plus)

Codex Security --fail-on-severity fails the CI step; Codex Action can gate merges.

Full Repo ScanYesPro/business/enterprise/edu (not plus)

Codex Security scans full repos, selected paths, or org-wide bulk campaigns.

Scheduled / Continuous RescanPartialPro/business/enterprise/edu (not plus); research preview

Codex Security cloud scans connected repos commit by commit; no cron scheduling documented.

Runtime / Production MonitoringNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Analysis & detection

Every detection and code-analysis capability tracked for ChatGPT / Codex.

SASTYesPro/business/enterprise/edu (not plus)

Codex Security agent finds, validates and reports vulnerabilities with SARIF export.

Taint / Data-Flow AnalysisPartialPro/business/enterprise/edu (not plus); research preview

Cloud finding pages show call-path and data-flow context 'when available'; no taint engine.

Secrets DetectionNo

Not documented on vendor docs (security overview, FAQ, CLI reference) as of 2026-08-25.

Secrets ValidationNo

Not offered in vendor documentation reviewed as of 2026-09-05.

SCA (Dependencies)No

Not documented on vendor docs as of 2026-08-25; incident-audit use case is reactive, not a scanner.

Reachability AnalysisNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Malicious Package DetectionNo

Not offered in vendor documentation reviewed as of 2026-09-05.

License ComplianceNo

Not offered in vendor documentation reviewed as of 2026-09-05.

SBOM GenerationNo

Not offered in vendor documentation reviewed as of 2026-09-05.

IaC ScanningNo

Not documented on vendor docs (security overview, FAQ, CLI reference) as of 2026-08-25.

Container ScanningNo

Not documented on vendor docs (security overview, FAQ, CLI reference) as of 2026-08-25.

Cloud Posture (CSPM)No

Not offered in vendor documentation reviewed as of 2026-09-05.

DAST / API ScanningNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Code Smells & MaintainabilityYesPlus

Reviewer reports prioritized findings, but docs direct mechanical formatting and lint checks to CI instead.

Complexity MetricsNo

Not documented on vendor docs (code review, GitHub integration) as of 2026-08-25.

Duplication DetectionNo

Not documented on vendor docs (code review, GitHub integration) as of 2026-08-25.

Dead / Unused CodeNo

Not offered in vendor documentation reviewed as of 2026-09-05.

Test Coverage TrackingNo

Not documented on vendor docs (code review, GitHub integration) as of 2026-08-25.

Diff / New-Code CoverageNo

Not documented on vendor docs (code review, GitHub integration) as of 2026-08-25.

Architecture GovernanceNo

Not documented on vendor docs (code review, GitHub integration) as of 2026-08-25.

Technical Debt QuantificationNo

Not documented on vendor docs (code review, GitHub integration) as of 2026-08-25.

Behavioral Delivery AnalyticsNo

Not documented on vendor docs (code review, GitHub integration) as of 2026-08-25.

AI Logic Bug DetectionYesPlus

Agentic reviewer reads a selected diff and reports prioritized actionable findings without changing the working tree.

PR Summaries & WalkthroughsNo

Not documented; docs state reviews surface only P0/P1 issues, no summary or walkthrough.

Custom Rule AuthoringYesPlus

Nested AGENTS.md '## Code Review Rules', custom review instructions, --scan-prompt-file, knowledge-base docs.

Autofix SuggestionsYesPlus

Findings carry remediation guidance; '@codex fix the P1 issue' starts a cloud chat with PR context.

Autofix via Agentic PRsYesPlus

Codex can push a fix to the PR branch with permission; a PR can be opened from a finding page.

AI Triage / False-Positive FilteringYesPro/business/enterprise/edu (not plus); research preview

Cloud validates findings in isolation before surfacing; CLI accepts false-positive marks.

Monorepo SupportYesPlus

Nested per-service AGENTS.md rules and path-based severity overrides; review pane also handles multi-repo projects.

AI capabilities

AI Review EngineYesPlus

Review and scanning are agentic Codex runs; Codex Security defaults to gpt-5.6-sol at xhigh reasoning effort.

BYO Model / BYOKYes

Runs against OpenAI API, Amazon Bedrock, OpenRouter or Fireworks; review_model overrides the review model.

MCP ServerPartial

Codex consumes MCP servers (e.g. Linear); no MCP server exposing review or scan findings documented.

AI Usage GovernanceNo

No AI-generated-code inventory; opt-in OpenTelemetry logs prompts, approvals and tool results instead.

Chat With ReviewerYesPlus

Line-scoped inline comments plus follow-up turns; any '@codex' mention starts a cloud chat with PR context.

Learns From FeedbackPartial

False-positive marks are 'considered but re-checked'; editing the threat model changes future scan prioritization only.

Code Excluded From TrainingYesBusiness

Business and Enterprise business data is not trained on by default; not covered on Plus.

Models used

GPT-5.6 Sol (gpt-5.6-sol)GPT-5.6 TerraGPT-5.6 LunaGPT-5.5GPT-5.4GPT-5.4 miniGPT-5.3-Codex-SparkGPT-Daybreak-BlueGPT-Daybreak-Redanthropic/claude-sonnet-4.5 (runnable via OpenRouter in the Codex Security scan runtime)

Compliance & governance

Audit LogsYesEnterprise

ChatGPT Enterprise supports audit logging; Compliance API adds an append-only log stream for SIEM.

SSO / SAMLYesBusiness

SAML SSO and MFA are listed as included in the Business plan on the pricing page.

Role-Based Access ControlYesEnterprise

Workspace-level access controls, admin toggles, per-repo review preferences, allow-users/allow-bots in CI.

Compliance Reporting ExportsYesEnterprise

Compliance API serves audit, legal, governance and e-discovery workflows; SARIF export of scan findings.

Certifications

SOC 2 Type 2ISO 27001ISO 27017ISO 27018ISO 27701ISO 42001PCI DSSCSA STAR Level 1FedRAMP 20xTX-RAMP

Standards mapping

GDPRCCPAHIPAA (via BAA, not organizational cert)FERPA

Integrations

GitHubYes
GitHub Enterprise ServerPartial
GitLabPartial
GitLab Self-ManagedNo
BitbucketNo
Bitbucket Data CenterNo
Azure DevOpsNo
REST APIPartial
CLIYes
WebhooksPartial

CI/CD systems

GitHub ActionsGitLab CI/CD

IDEs

VS Code

Issue trackers

Linear

Chat & notifications

Slack

Pricing & plans

$20/user/month billed annually ($25/user/month if billed monthly)

Minimum seats: 2

Trial: No permanent free trial. Limited options: student/teacher offers, referral, mobile app pop-ups (all require credit card).

Free$0/monthGeneral ChatGPT users
  • Limited general ChatGPT access
  • No Codex code review
  • Image generation not available
Go$8/monthIndividuals who need more usage than Free for lightweight coding tasks
  • Codex for lightweight coding tasks
  • Everything in Free, plus more messages with tools
  • No Security Review
  • No cloud-based integrations (automatic code review, Slack) documented for this tier
Plus$20/monthIndividual developers
  • Codex cloud chats
  • Local messages and cloud chats per rate-limit table
  • Slack integration
  • Referral program with banked rate-limit resets
  • Security Review NOT available on Plus
  • Message-based usage limits
Pro (5x)$100/monthHeavy individual Codex users
  • Codex cloud chats
  • Higher local-message ceilings than Plus
  • Security Review available
  • 1-2.5 hrs ChatGPT Voice/desktop allowance
  • Codex task budget applies
Pro (20x)$200/monthHighest-volume individual users
  • Highest local-message ceilings
  • Security Review available
  • Unlimited ChatGPT Voice access
  • Codex task budget still applies
Business$25/user/month billed monthlyTeams of 2+
  • Codex cloud chats
  • Linear and Slack integrations
  • Security Review available
  • Admin controls for cloud chats and Slack posting
  • 2+ users required
  • Same per-seat usage limits as Plus unless on flexible pricing
EnterpriseNot priced (flexible/credit-based; contact sales)Large organisations
  • Full feature set including Security Review
  • Compliance API and append-only log stream
  • Admin governance and managed configuration
  • No training on business data by default
  • Per-enterprise guardian_policy_config for the auto-review reviewer
  • Quote-only
  • No named compliance certifications in source
  • HIPAA/BAA and residency coverage explicitly 'not universal'
  • A legacy rate card still applies to a small subset of Enterprise customers
EduNot priced (flexible/credit-based, similar to Enterprise)Educational institutions
  • Security Review available
  • Same integrations as Enterprise/Business
  • Compliance API access
  • Same per-seat usage limits as Plus unless on flexible pricing
  • Quote-only
API key (pay-as-you-go)Usage-based standard OpenAI API ratesCI and programmatic use
  • Local messages billed by usage
  • Codex Action proxy via OPENAI_API_KEY
  • Codex Security CLI auth in CI
  • Cloud chats NOT available
  • Code Reviews NOT available
  • ChatGPT Voice in Desktop not available

Who it's for

Notable strengths

  • Two separate review products: general Code Review (P0/P1 GitHub findings) and Codex Security with its own threat model, findings workbench and SARIF export
  • CI-native security gating: ready-made GitHub Actions and GitLab CI examples with SARIF upload and --fail-on-severity build failure
  • Org-wide bulk scanning with resumable CSV-driven campaigns, retry, concurrency control and --max-cost budget caps
  • Validation before surfacing: cloud scans validate findings in an isolated environment and expose confidence, evidence and attack path
  • Backend flexibility: local Codex and Codex Security run against OpenAI API, Amazon Bedrock, OpenRouter or Fireworks, including non-OpenAI models
  • Review rules live in version-controlled nested AGENTS.md files rather than a dashboard-only rules engine

Notable limitations

  • No compliance certifications are named anywhere in OpenAI's public documentation; buyers are directed to contact OpenAI
  • Security Review is research preview and unavailable on Plus (requires Enterprise, Business, Edu or Pro); Codex Security cloud is also research preview
  • PR review integration is GitHub-only; GitLab appears only as CI SARIF ingestion (Ultimate 19.2+), and Bitbucket and Azure DevOps are absent
  • Cloud chats and Code Reviews are not available via API key, so pure pay-as-you-go buyers cannot use the reviewer
  • No SCA, secrets, IaC, container, coverage, duplication or technical-debt capability documented, and no supported-language list
  • Cost is credit-metered across a shared ChatGPT/Codex pool with Codex Security billed separately per scan, making review spend hard to forecast
  • HIPAA/BAA, data residency and inference residency are explicitly stated as 'not universal'

Similar tools

Other Agent Coding Tool tools in the directory.

FAQ

When should you choose ChatGPT / Codex?

ChatGPT / Codex best fits Indie developers, Startups, Mid-market teams, Enterprise. Two separate review products: general Code Review (P0/P1 GitHub findings) and Codex Security with its own threat model, findings workbench and SARIF export

What languages does ChatGPT / Codex support?

ChatGPT / Codex supports 22+ languages and frameworks, including Bash, C, C++, C#, Dart, Go, GoogleSQL, Java, JavaScript, Kotlin, and 12 more.

What does ChatGPT / Codex integrate with?

ChatGPT / Codex integrates with GitHub, GitHub Enterprise Server (partial), GitLab (partial) for source control, CI systems including GitHub Actions, GitLab CI/CD, and IDEs including VS Code.

What tools are similar to ChatGPT / Codex?

Similar Agent Coding Tool tools tracked here include Claude Code, Gemini Code Assist.

What are ChatGPT / Codex's plans and pricing?

ChatGPT / Codex offers a free tier, with paid plans starting around $20/user/mo; enterprise pricing is quote-only.