codex-desktop-linux: a community repackaging of OpenAI's Linux ChatGPT app
Unofficial ChatGPT desktop app for Linux (formerly the Codex app), built locally from OpenAI’s official macOS app. Includes Chat, Work, and Codex. Packages for Debian/Ubuntu (.deb), Fedora/openSUSE (.rpm), Arch (pacman), Nix/NixOS, and AppImage, with Wayland and X11 support.
At a glance
- What is it?
- The project rebuilds OpenAI's signed Linux .deb into deb, RPM, pacman, AppImage and Nix outputs, and adds Linux features that are off by default. It is for Linux users who want the official Electron payload without hand-converting packages.
- Who is it for?
- Adopt it if you want the official signed payload in a native package on Debian, Fedora, openSUSE, Arch or Nix, and you are willing to build from a clone. Skip it if you need a hosted download, an aarch64 AppImage, or you want to run it alongside the official ChatGPT package, since both share the upstream Codex profile and the single-instance lock.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly JavaScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What codex-desktop-linux actually ships
OpenAI publishes a signed Linux .deb of its ChatGPT desktop application. That is the only upstream source this project accepts. codex-desktop-linux takes that payload, verifies it, and repackages it for Debian and Ubuntu, Fedora, openSUSE, Arch, Nix and NixOS, plus an AppImage for atomic desktops and other distributions. It is unofficial and community-maintained; the README describes it as a distribution of the official Linux application rather than a fork of the app itself.
The identity split is deliberate. The application appears in desktop menus as ChatGPT Community with an icon marked with a blue C, while the package name, command and install prefix stay codex-desktop and /opt/codex-desktop. That makes it distinguishable from OpenAI's own ChatGPT package on the same machine, which matters because both can be installed at once.
Who this is for: Linux users who want the official Electron runtime, native modules, bundled codex and rg binaries, code-mode host, plugins, libraries, locales and Owl metadata, but do not want to convert a .deb by hand or run an unpacked tree. The README states that with no ASAR-changing feature enabled, resources/app.asar stays byte-for-byte identical to the official package. That is the strongest claim in the repository, and it is the reason to trust the repackaging more than a random third-party build.
How the build turns one .deb into five package formats
The Makefile drives everything. It resolves the current package through OpenAI's signed stable APT metadata for amd64 or arm64, stages it into codex-app/, then produces the native artifact for the detected distribution into dist/. Distribution detection reads /etc/os-release and matches ID and ID_LIKE tokens against arch, manjaro and endeavouros for pacman; fedora, rhel, centos, suse and opensuse for RPM; debian, ubuntu, linuxmint and pop for deb. If os-release gives nothing, it falls back to the presence of dpkg-deb, rpmbuild or makepkg.
The Rust side is a Cargo workspace with four members: computer-use-linux, read-aloud-linux, updater and record-replay-linux. Those are the optional Linux features and the update manager, not the application core. The README says Rust is used for the updater and for enabled native feature helpers, so a build without those features does not need the same toolchain depth.
You can bypass repository discovery by pointing the build at a local package you already trust. The README notes the local file is still checked for package name, architecture, control metadata, payload completeness and SHA-256 recording, but because signed repository discovery is skipped, the caller is responsible for its origin. Old .dmg, DMG= and CODEX_DMG_* inputs are intentionally unsupported, which is a leftover from the project's earlier macOS-derived approach.
Installing the Codex desktop app on Linux with make bootstrap-native
The README's recommended path is a clone followed by one make target. Clone first, because the native package and AppImage builds run from the checkout:
git clone https://github.com/ilysenko/codex-desktop-linux.git
cd codex-desktop-linuxThen run the bootstrap target. According to the README it installs build dependencies, resolves the current package through OpenAI's signed stable APT metadata, builds codex-app/, creates the native package for the detected distribution, and installs the newest artifact from dist/:
make bootstrap-nativeIf the dependencies are already present, the shorter target skips the dependency step:
make install-nativeTo pick optional features before installing, run setup first. The README is explicit that this only writes the local feature selection and does not build or install anything, so it must be followed by install-native:
make setup-native
make install-nativeOn NixOS or another Nix system the README gives a flake command instead of the Makefile path:
nix run github:ilysenko/codex-desktop-linuxFor atomic desktops or an unsupported distribution, build an AppImage without the native updater:
make build-app && make appimageIf repository resolution is not what you want, supply a local package. The README warns that signed repository discovery is skipped in this mode, so you own the provenance question:
UPSTREAM_DEB=/path/to/chatgpt_<version>_<arch>.deb make build-appWhat you should see: a package in dist/ matching the detected format (codex-desktop_*.deb, codex-desktop-*.rpm or codex-desktop-[0-9]*.pkg.tar.*), and, after install, a ChatGPT Community entry in your desktop menu that launches codex-desktop from /opt/codex-desktop.
The anonymous launch counter, and how to switch it off
The launcher sends at most one anonymous usage event per UTC day to a public GoatCounter dashboard. The README says the event contains only the fixed path /app-launch, that GoatCounter derives an aggregate country from the network request, and that no application activity, account or machine identifier, version, architecture, package format, language, screen size or referrer is sent. Every installation sends the same fixed, non-identifying User-Agent so GoatCounter does not discard the request as a bot.
This is telemetry in a desktop app, and it is worth saying plainly rather than burying. The payload is minimal and the stated purpose is to help the community decide whether maintaining the distribution is useful, but a network request on every launch is still a network request. The request runs in the background; a missing curl, a blocked request or any other error never delays the application and produces no output, which means you cannot detect it by watching startup time.
Disabling it takes one environment variable, documented in the README:
CODEX_LINUX_DISABLE_USAGE_REPORTING=1 codex-desktopIf you want that permanent, you would set it in the desktop entry or a wrapper, and the README does not document that step. That is a gap: the variable is documented, the persistent configuration is not.
Where codex-desktop-linux breaks down
The single-instance lock is the sharpest limitation. The README states that the official chatgpt package and the custom codex-desktop package may coexist, but both intentionally use the upstream Codex user profile, and you must not run them at the same time because the upstream single-instance lock may route the second launch into the process that is already running. So coexistence is a packaging property, not a usage property. If you planned to keep both installed and compare them side by side, the upstream lock decides which one you actually get.
Only the latest signed stable OpenAI Linux package is supported, on amd64 and arm64. There is no channel for pinning an older upstream version, and no documented rollback if a new upstream build regresses. The README does not document rollback. If you need to hold a specific version, this project does not give you a supported way to do it.
AppImage is the other weak spot. The README says AppImage never adds --no-sandbox automatically, and that if your distribution disables unprivileged user namespaces you should use the native package or follow the sandbox guidance in docs/troubleshooting.md. On hardened kernels where unprivileged user namespaces are off, the AppImage is the wrong tool and the native package is the answer.
Finally, there is no hosted download. Every path starts with a clone or a flake reference, and the build needs Node.js 20 or newer, npm, Python 3, curl, gpgv, dpkg-deb, tar, make and a C/C++ toolchain, with Rust for the updater and native feature helpers. On a machine where you cannot install those, this project has nothing to offer.
How it differs from building the official .deb yourself
The obvious alternative is downloading OpenAI's signed Linux .deb and installing it directly with apt or dpkg. That approach is simpler and has no third party in the chain at all. The difference is scope: the official .deb targets Debian-derived systems, so on Fedora, openSUSE, Arch or NixOS you either convert it, unpack it by hand, or run it outside the package manager. codex-desktop-linux exists to close that gap, and it does so by reusing the official payload rather than rebuilding the application.
The trade is provenance. Installing the official .deb means trusting one vendor. Installing this project means trusting the maintainer's verification and repackaging steps in addition to OpenAI, and accepting that upstream changes can break the build until the maintainer catches up. The README's byte-for-byte claim about resources/app.asar when no ASAR-changing feature is enabled is the project's own answer to that concern, and it is checkable by anyone who wants to diff the staged tree against the upstream package.
A second alternative is a distribution-maintained package. Those tend to lag upstream releases and often ship a different feature set. This project tracks the latest signed stable upstream package by design, which is both its selling point and the reason it has no version-pinning story.
Maintenance, licensing and what removal involves
The repository is not archived and the last push was on 2026-09-14, three days before this writing, so the project is being worked on right now. The README points contributors at CONTRIBUTING.md and AGENTS.md, and there is a CI workflow plus a separate upstream-build-app workflow, which suggests upstream changes are pulled in on a schedule rather than only on demand. The release history is not retrievable from the repository listing, so there is no way to judge cadence from releases alone.
Upgrade cost is mostly the rebuild. Because the build resolves the current package from the signed stable index each time, staying current means re-running the build and reinstalling the artifact. The native package installs a user update service, and removal disables it. If a service from an older or manual installation lingers, the README gives explicit cleanup:
systemctl --user disable --now codex-update-manager.service
systemctl --user daemon-reloadUninstalling uses the package manager that installed it: apt remove codex-desktop, dnf remove codex-desktop, zypper remove codex-desktop or pacman -R codex-desktop. For an AppImage you delete the file you built. The README says to close both ChatGPT Community and the official ChatGPT application before removing.
The project is MIT licensed, and the README does not describe any additional terms on the repackaged payload. That is worth checking yourself: the licence here covers this repository's build tooling, while the upstream application carries its own terms, and nothing in the README resolves how those interact for redistribution. That is a question for your own review, not a settled point.
Editorial conclusion
Adopt it if you want the official signed payload in a native package on Debian, Fedora, openSUSE, Arch or Nix, and you are willing to build from a clone. Skip it if you need a hosted download, an aarch64 AppImage, or you want to run it alongside the official ChatGPT package, since both share the upstream Codex profile and the single-instance lock. Verify first that Node.js 20 or newer, npm, Python 3, curl, gpgv, dpkg-deb, tar, make and a C/C++ toolchain are present, and decide whether the anonymous daily launch event is acceptable or you will set CODEX_LINUX_DISABLE_USAGE_REPORTING=1.
Frequently asked questions
What does the Codex desktop app do?
This project distributes OpenAI's official Linux ChatGPT desktop application, which the README describes as including Chat, Work and Codex, along with the bundled codex and rg binaries, code-mode host, plugins, libraries and locales. codex-desktop-linux repackages that signed payload rather than reimplementing it.
Can Codex access my computer?
The README does not describe the application's permissions or what the Codex features can reach on your machine. What it does document is a launcher that sends at most one anonymous launch event per UTC day to a public GoatCounter dashboard, carrying only the fixed path /app-launch, and an environment variable to disable it.
What do people use codex for?
The README does not describe typical usage. It documents the packaging: the official Electron runtime, native modules, bundled codex and rg, code-mode host, plugins, libraries, locales and Owl metadata are reused directly from OpenAI's signed Linux package.
How to remove codex from Linux?
Close both ChatGPT Community and the official ChatGPT application first, then remove the package with the manager that installed it: apt remove codex-desktop, dnf remove codex-desktop, zypper remove codex-desktop or pacman -R codex-desktop. If a leftover update service remains, the README gives systemctl --user disable --now codex-update-manager.service followed by systemctl --user daemon-reload.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/ilysenko-codex-desktop-linux)