# Codex CLI: four products share the name, and the newest tags include alphas

> Codex CLI is a Rust coding agent that runs on your machine, and the README for it is mostly an installation page. The engineering decisions visible in the repository are the four surfaces called Codex, an installer that pipes a shell script and can be pointed at a different download host, a local agent whose recommended identity is a ChatGPT account, and a build that needs Bazel, Nix, Cargo and pnpm at once.

**openai/codex** — Codex is a lightweight terminal coding agent that can inspect a repository, edit files, and run commands.

- Repository: https://github.com/openai/codex
- Stars: 127,113 · Forks: 19,863
- Language: Rust
- License: Apache-2.0
- Published: 2026-08-04 · Updated: 2026-08-18 · Language: en
- Canonical page: https://hysenlabs.com/projects/openai-codex

## Four surfaces are called Codex, and this repository is one of them

The opening paragraph sorts out which Codex you have, and it does it in four steps. Codex CLI is a coding agent from OpenAI that runs locally on your computer, and that is what this repository contains. If you want it inside an editor, VS Code, Cursor and Windsurf are handled by a separate install path documented at developers.openai.com/codex/ide. If you want the desktop experience, the README points at running codex app or at the Codex App page. And if you are after the cloud-based agent from OpenAI, that is Codex Web at chatgpt.com/codex. Four products, one name, and the confusion this causes is not hypothetical: someone who types codex expecting the cloud agent and installs this binary ends up with a process that edits their working tree.

## curl piped into sh, with a switch that changes the download host

The install is one line on Mac or Linux, and the Windows equivalent pipes a script into iex.

```shell
curl -fsSL https://chatgpt.com/codex/install.sh | sh
```

```shell
powershell -ExecutionPolicy ByPass -c "irm https://chatgpt.com/codex/install.ps1 | iex"
```

Both fetch a script from a chatgpt.com path and execute it immediately, which is the part to think about on a workstation that holds production credentials. The installers then download from https://releases.openai.com/codex by default and fall back to GitHub Releases if a metadata or asset download is unavailable, and there is an environment variable to force the fallback host, with false, 0 and no all accepted.

```shell
curl -fsSL https://chatgpt.com/codex/install.sh | CODEX_INSTALLER_USE_RELEASES_OPENAI_COM=false sh
```

That switch exists because the default source is a vendor-controlled host, and it is also the honest way to keep the binary auditable: point the installer at GitHub Releases and the artefact is the one attached to a public tag. The README documents no checksum to verify either way.

## Package managers avoid the script, manual installs need a rename

Two package manager routes skip the shell script entirely.

```shell
# Install using npm
npm install -g @openai/codex
```

```shell
# Install using Homebrew
brew install --cask codex
```

The manual route is the one worth understanding if you build images. Each GitHub Release contains many executables, and the four to look for are codex-aarch64-apple-darwin.tar.gz for Apple Silicon, codex-x86_64-apple-darwin.tar.gz for older Mac hardware, codex-x86_64-unknown-linux-musl.tar.gz for x86_64 Linux and codex-aarch64-unknown-linux-musl.tar.gz for arm64 Linux. Each archive holds a single entry with the platform baked into the filename, so after extracting it you rename the file to codex yourself. Nothing on macOS or Linux names the binary codex out of the box, which is a small detail that breaks container images and CI steps built from the archive rather than from a package manager.

## The recommended identity is a ChatGPT account, not a key

Authentication is where this stops being a self-contained tool. You run codex and select Sign in with ChatGPT, and the README recommends signing into your ChatGPT account to use Codex as part of a Plus, Pro, Business, Edu or Enterprise plan, with a link to what each plan includes. An API key also works, but the README describes that as requiring additional setup and sends you to the authentication documentation for it. The consequence for a team is concrete: the path of least resistance ties a local process that can read and modify a repository to an individual account, and the path that fits a company-managed key is the one the documentation treats as extra work. Decide which of the two your organisation requires before the first install rather than after.

## Four build systems, and the justfile is the only map

The top level carries Bazel files, Nix files, Cargo configuration and a pnpm workspace in one tree. There is BUILD.bazel, MODULE.bazel, MODULE.bazel.lock, .bazelrc, .bazelignore, .bazelversion, defs.bzl and rbe.bzl for remote build execution; flake.nix and flake.lock; a .cargo/ directory alongside the codex-rs/ sources; and pnpm-workspace.yaml with a package.json that requires node 22 or newer and pnpm 10.34.5 or newer. Then there is the justfile, which is where the project's own commands actually live: each recipe is a cargo invocation, a Python script or a shell script, with the shell itself defined as a Python shim so that Windows and Unix behave the same way. Four toolchains is a real cost for a new contributor, which is why docs/install.md and docs/contributing.md are the two links in the README worth opening first.

## Every codex capability is a separate cargo binary

The justfile is short enough to read as an index of the product. The alias c runs the main binary, exec runs the non-interactive entry point, file-search runs a crate called codex-file-search, code-mode-host runs codex-code-mode-host, assemble-codex-package calls scripts/build_codex_package.py, and app-server-test-client builds the codex-cli package and runs codex-app-server-test-client against a debug binary path. There is also fmt and fmt-check, both of which call ../scripts/format.py, and that one script formats the justfile, Rust, Bazel and Starlark, the Python SDK and the Python scripts, so a single command covers five languages. Two details with consequences. rust_min_stack is set to 8388608, eight mebibytes, which is a deliberate floor for the Rust thread stack. And fix runs cargo clippy --fix --tests --allow-dirty, which rewrites your working tree and will happily do it on top of uncommitted changes.

## The npm package runs prettier and one cargo command

The root package.json is called codex-monorepo, is marked private, and describes itself as tools for repo-wide maintenance, which is accurate. It has two real scripts: format and format:fix, both prettier invocations over JSON, Markdown, workflow YAML and JavaScript, and write-hooks-schema, which shells into cargo to run the codex-hooks binary and write its schema fixtures. Prettier is the only devDependency. Everything else in that file is supply-chain control: a resolutions block pinning the model context protocol SDK to 1.26.0 alongside transitive packages such as glob, minimatch at two separate ranges, picomatch, fast-uri, flatted, path-to-regexp, handlebars, hono, esbuild and braces, plus an overrides entry for punycode. For a repository whose product is Rust, that is a well-groomed JavaScript tail, and the MCP SDK pin is the tell that hooks are part of the product surface rather than an experiment.

## Two of the three newest release tags are alphas

The release list explains how carefully you need to pin. The three most recent are rust-v0.161.0-alpha.3 dated 2026-09-30, rust-v0.160.0-alpha.6.1 dated 2026-09-30, and rust-v0.159.2 dated 2026-09-29, and the last push was on 2026-09-29 with the repository not archived. The rust-v prefix is there because the tree holds more than one implementation, with codex-cli/ and codex-rs/ directories at the top level, so the Rust line versions on its own. For a team the practical rule is simple: do not install latest, because that can resolve to an alpha, and record the tag you tested in the same place you record the checksum you verified. The licensing is the friendly part by comparison, Apache-2.0 with both a LICENSE and a NOTICE file at the root, and a SECURITY.md for reporting issues.

## Conclusion

Use Codex CLI when you want a local agent that reads and edits a checkout, and pin a stable rust-v tag rather than latest, because two of the three most recent releases are alphas dated 2026-09-30. Do not install it expecting the cloud product, the desktop app or the editor extension, which are separate surfaces with their own documentation, and do not put a shared team on a personal ChatGPT sign-in without checking the plan terms, since that is the recommended path and the API key route is documented as additional setup. Before the first rollout, decide how you will obtain the binary, because the default installer executes a script fetched from a vendor host and the repository documents no checksum to verify against.

## FAQ

### Is codex separate from ChatGPT?

Codex CLI is a separate program that runs locally on your computer, but its recommended sign-in is a ChatGPT account: you run codex, choose Sign in with ChatGPT, and the README frames it as part of a Plus, Pro, Business, Edu or Enterprise plan. An API key is also supported, described as requiring additional setup, and the cloud-based Codex Web is a different surface at chatgpt.com/codex.

### Is codex an IDE like vscode?

No, the editor integration is a separate installation from the CLI. The README points VS Code, Cursor and Windsurf users to an IDE install page, while this repository is the terminal agent, and a desktop experience is a third option through codex app.

### how to install codex cli

On Mac or Linux the installer is `curl -fsSL https://chatgpt.com/codex/install.sh | sh`, and on Windows it is the PowerShell one-liner piping the install.ps1 script into iex with the execution policy bypassed. There are also `npm install -g @openai/codex` and `brew install --cask codex`, and a GitHub Release archive per platform if you would rather fetch a binary yourself.

### how to use codex cli

Run codex after installing and choose your sign-in, either Sign in with ChatGPT or an API key that needs additional setup. For scripting, the repository's justfile exposes an exec entry point run through cargo, and it also builds separate binaries for file search and for the code-mode host.

### how to use codex in vscode

The README does not describe commands for the editor; it sends VS Code, Cursor and Windsurf users to a separate IDE installation page at developers.openai.com/codex/ide. What runs in the terminal and what runs in the editor are two installations, and mixing their documentation is the usual source of confusion here.

### how to use codex in terminal

Install it, then run codex and choose your sign-in, either Sign in with ChatGPT or an API key that needs additional setup. For non-interactive use the repository's justfile exposes an exec entry point run through cargo, and it also builds separate binaries for file search and for the code-mode host.

## Sources

- [Official README](https://github.com/openai/codex#readme)
- [Project repository](https://github.com/openai/codex)
- [Release notes](https://github.com/openai/codex/releases)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/openai-codex
