Codex App Manager: install, update and cleanly remove the official Codex desktop app
跨平台官方 Codex 桌面应用的安装 / 增量更新 / 干净卸载管理器,内置国内可达的镜像自更新。Cross-platform installer & updater for the official Codex desktop app — incremental updates, clean uninstall, China-reachable self-update.
At a glance
- What is it?
- A Tauri v2 desktop client that manages the official OpenAI Codex desktop app on macOS and Windows, with Sparkle delta updates on macOS and a mirror-based self-update path reachable from mainland China. The catch is Windows code signing, which the project says is still pending.
- Who is it for?
- Adopt it if you want the official Codex desktop app installed, updated and removed through one client, and especially if you are on a mainland China network where the project's R2 plus IHEP S3 mirror is the point. Skip it if you need a signed Windows installer today, since the README states the setup executables carry no Authenticode signature and the SignPath Foundation application is still under review, or if you would rather manage Codex yourself.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository received new commits within the last day.
- What is it written in?
- Mainly Rust, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
What Codex App Manager actually manages
The official Codex desktop app is a separate product from this repository. Codex App Manager is the layer above it: it detects whether Codex is already installed on the machine, plans an install, update or uninstall, and offers a one-click launch. The README is explicit that the manager does not build or modify Codex. It consumes the payload produced by an upstream mirror repository, codex-app-mirror, and a Sparkle update feed.
The audience is narrow but real. You want the official Codex desktop application, not a reimplementation, and you want to stop thinking about where the installer came from. The second audience is anyone on a mainland China network, because the manager's own update path does not depend on GitHub being reachable. The README states that self-update and payload download share one mirror short link that routes by region, IHEP S3 for mainland China and R2 elsewhere, and that the routing is transparent to the user.
One thing this project does not do is act as a package manager for anything else. It manages Codex and itself. If you were looking for a general tool that also handles other desktop applications, this is not that.
How the update pipeline works: Sparkle deltas, MSIX staging, signature checks
On macOS the mechanism is spelled out in the README. The manager reads the mirror's Sparkle appcast for both arm64 and x64, compares the published version against the version installed locally, and prefers a delta package that contains only the difference between the two versions. After download it verifies the Sparkle signature, replaces the application in place, and rolls back if that fails. When no matching delta exists it falls back to the full package. The README describes the signature check as byte-level EdDSA verification.
Windows takes a different route. The manager fetches an MSIX or portable build from the mirror, stages the update, and supports a custom install directory. After installation it runs an MSIX health check and warns when the system has been trimmed. The README does not describe a delta mechanism for Windows, so treat the two platforms as having different update economics: small downloads on macOS when a delta exists, larger staged packages on Windows.
The self-update path is architecturally separate and worth understanding because it explains why the mirrors work at all. The manager ships the Tauri updater and checks two endpoints in order: its own mirror's latest.json, then the GitHub release's latest.json as a fallback. The README's argument is that the signature in latest.json covers the installer bytes rather than a URL, so a mirror can copy the artifact byte for byte and rewrite only the download address while the signature stays valid. Versioned installer paths sit under a version directory for long caching, while latest.json stays at a fixed root path with a short cache. The README states that CI syncs both mirrors on every release, which is what makes updating without GitHub possible.
Installing Codex App Manager and running it for the first time
macOS has a Homebrew cask, which the README marks as the recommended route. This pulls the manager from the author's tap:
brew install --cask wangnov/tap/codex-app-managerAfter the cask finishes, the application appears in your Applications folder. The README notes the macOS build is Developer ID signed and notarized by Apple, so the first launch should not be blocked by Gatekeeper.
If you prefer a direct download, the README points at the latest GitHub release for global users and at mirror links for users in mainland China. The mirror links are stable and always resolve to the newest release, because a Cloudflare Worker resolves the /manager/latest/ path to the current publication. The file names are platform specific, for example CodexAppManager_aarch64.dmg for Apple Silicon, CodexAppManager_x86_64.dmg for Intel, and CodexAppManager_x64-setup.exe or CodexAppManager_arm64-setup.exe for Windows.
Before running the Windows setup executable, verify the download against the SHA256SUMS file published in the same release. The README gives the PowerShell form:
Get-FileHash .\CodexAppManager_x64-setup.exe -Algorithm SHA256
# 或 ARM64:
Get-FileHash .\CodexAppManager_arm64-setup.exe -Algorithm SHA256On macOS the equivalent check uses shasum:
shasum -a 256 CodexAppManager_aarch64.dmgCompare the printed digest to the value in SHA256SUMS. On Windows, expect a SmartScreen prompt on first run; the README attributes it to the absence of Authenticode signing on the installer. Once the manager is open, the README's guidance is that you do not download Codex separately: the manager installs and updates the Codex desktop app for you. The repository also ships an .env.example containing a single VITE_MIRROR_BASE_URL variable set to https://codexapp.agentsmirror.com, which matters only if you build the frontend yourself.
The Windows signing gap is the main limitation
The README is unusually direct about this, and it should shape your decision. The Windows installers CodexAppManager_x64-setup.exe and CodexAppManager_arm64-setup.exe currently have no Authenticode code signing. The README states that the Tauri updater signature used for in-app self-update verifies downloaded bytes and does not represent Windows publisher trust. It also states that a SignPath Foundation application has been submitted and is still under review, and that current downloads must not be described as approved or signed.
In practice that means a SmartScreen warning on first run, and a certificate-based trust chain that stops at your own hash comparison. If your environment requires signed installers as a policy matter, this project does not satisfy that requirement today, regardless of how well the update logic works. The README points to docs/code-signing-policy.md and docs/windows-signing.md for the details.
A second limitation is platform coverage. The download table lists macOS arm64 and x64 and Windows x64 and ARM64. There is no Linux artifact in the README's download table, even though the project describes itself as cross-platform. Treat it as a macOS and Windows tool.
A third is that the manager inherits upstream availability. It reads the mirror's appcast and MSIX payloads; if that upstream mirror stops publishing, the manager has nothing to install from. The README does not document a fallback payload source the way it documents a GitHub fallback for the manager's own latest.json.
How it differs from Homebrew alone or the official installer
The nearest alternative for macOS users is the Homebrew cask for the Codex desktop app itself, if one exists in the upstream tap, or simply downloading the official installer and rerunning it when a new version appears. The difference is in what happens between versions. A plain reinstall downloads the whole application every time. Codex App Manager reads a Sparkle appcast, picks the delta between your installed version and the target, verifies it, and swaps in place with a rollback path if verification or replacement fails. That is a different update model, not a different download button.
On Windows the alternative is the MSIX package and the system's own app installer. The manager adds staging, a custom install directory, and a post-install health check that warns on trimmed systems. Whether that is worth an extra layer depends on whether you reinstall Windows images often or want the uninstall to be clean, which is one of the three verbs in the project's description and something the README presents as a first-class capability rather than a side effect.
The third comparison is against doing nothing and letting Codex update itself. The README does not describe Codex's own update behavior, so the honest position is that this project exists because the author wanted a specific install and update experience, including reachability from mainland China. If you already have a working update path you trust, the manager's value is mainly the uninstall and the mirror routing.
Maintenance, licence and what an upgrade costs you
The repository is MIT licensed, which permits commercial and private use, modification and redistribution provided the licence text is preserved. That is a permissive arrangement and it applies to the manager itself, not to the Codex desktop application it installs, whose terms come from OpenAI. The README does not discuss the Codex licence, so do not read the MIT badge as covering the payload.
The last push to the default branch was on 2026-09-13, and the most recent releases listed are v0.5.6, v0.5.5 and v0.5.4, all published on 2026-09-04. The package.json version is 0.5.6, matching the latest tag. The repository is not archived.
Upgrade cost has two parts. For the manager, the README states that CI syncs artifacts and a rewritten latest.json to both mirrors on every release, so upgrading is the in-app updater or a fresh cask install; there is no migration step described. For the Codex payload, cost depends on whether a delta exists for your version pair. When it does not, the README says the manager falls back to the full package, which restores the download size you were trying to avoid. The README does not document a rollback for the manager's own self-update, only for the macOS payload replacement.
Editorial conclusion
Adopt it if you want the official Codex desktop app installed, updated and removed through one client, and especially if you are on a mainland China network where the project's R2 plus IHEP S3 mirror is the point. Skip it if you need a signed Windows installer today, since the README states the setup executables carry no Authenticode signature and the SignPath Foundation application is still under review, or if you would rather manage Codex yourself. Before installing, fetch the release's SHA256SUMS and compare it against your download with Get-FileHash on Windows or shasum -a 256 on macOS, and read docs/code-signing-policy.md and docs/windows-signing.md so the SmartScreen prompt is expected rather than surprising.
Frequently asked questions
How do I remove the Codex app with Codex App Manager?
Clean uninstall is one of the three operations the manager performs, alongside install and incremental update, and the README lists it as part of the core capability set. The README does not document the exact uninstall steps or which files are removed.
What is the Codex app that Codex App Manager installs?
It is the official OpenAI Codex desktop application. Codex App Manager does not build or modify it; it consumes the payload published by the upstream codex-app-mirror repository and handles installing, updating and uninstalling it.
What is the difference between Codex and the Codex app?
The README treats the Codex desktop app as the payload and Codex App Manager as the client that installs and updates it. The README does not draw a comparison between Codex and the Codex app themselves.
Can I control my Codex agents from my phone with Codex App Manager?
No. Codex App Manager is a desktop client for macOS and Windows, and the README lists no mobile platform, phone client or remote control feature.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/wangnov-codex-app-manager)