Codex with ChatGPT: routing planning to the web subscription and execution to Codex
ChatGPT thinks. Codex works. Use ChatGPT as the planning brain while keeping the Codex harness.
At a glance
- What is it?
- XiaoDuoYa/codex-with-chatgpt bridges the ChatGPT web app into a Codex session over a read-only MCP connection, so planning and review spend subscription quota instead of API tokens. The trade-off is that the bridge is only as stable as its tunnel.
- Who is it for?
- Adopt it if you already pay for ChatGPT Plus, Pro, Business or Enterprise and want planning and review to stop consuming API or Codex tokens, and you can accept a bridge that depends on a Cloudflare tunnel. Skip it if you need a hermetic or offline environment, if nobody on the team can debug a tunnel or an OAuth flow, or if your workspace cannot be exposed through a Cloudflare hostname even in read-only form.
- Can I use it commercially?
- Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
- Is it still maintained?
- Yes. The repository last received commits 17 days ago.
- What is it written in?
- Mainly TypeScript, according to GitHub's language statistics.
Answers come from the project's GitHub data, last synced on September 29, 2026, and from our analysis. They are not legal advice.
Editorial analysis
The idle-subscription problem this project targets
The README states the problem plainly: a paid ChatGPT web subscription sits largely unused while the coding agent burns scarce API or Codex tokens on planning and review. The project's answer is to move the thinking to the subscription you already pay for and leave Codex as the executor. Its own one-line summary is "ChatGPT thinks. Codex works."
The intended user is not a platform engineer. The README ships a one-paste install paragraph addressed to people who, in its words, do not know git, Node or terminals, and it explicitly tells the agent not to explain MCP, OAuth, tunnels or ports to them. That framing is the clearest statement of scope: this is aimed at individual developers and small teams who already hold a ChatGPT subscription and want their agent's planning turns billed to it rather than to metered API usage.
One claim deserves scrutiny before you build anything on it. The project says no API keys and no reverse proxy, and that the repository is never uploaded. Those are design statements, not measured guarantees. The mechanism behind them is a read-only MCP connection, described in the next section. Whether read-only is enforced strongly enough for your codebase is a question you have to answer yourself; the README asserts the property but does not document an audit of the tool surface.
Two planes: a read-only MCP data path and a tiny control path
The architecture diagram in the README splits traffic into two planes. The data plane is MCP, read-only, and carries code context from your local workspace up to ChatGPT. The control plane is labelled Computer Use and carries messages the README describes as under 1 KB, exchanging structured `[C2C]` state messages through the sequence `INIT → PLAN → EXECUTED → REVIEW`.
Sitting between them is the C2C Bridge, which the README describes as a loopback-only HTTP server with three responsibilities: serving a read-only MCP endpoint, handling OAuth 2.1 plus a one-time pairing code, and managing a Cloudflare Quick Tunnel. The tunnel is what makes a loopback-only server reachable from the ChatGPT web app. Codex never gives up execution: the diagram shows the Codex harness still owning shell, tests, edits and git against the local workspace.
That split is the interesting design decision. Rather than proxying model calls, the project keeps ChatGPT in the web UI and gives it a narrow read channel into the workspace, while the agent loop stays local. It also means the bridge is a single point of failure with three moving parts: the loopback server, the OAuth handshake, and the tunnel. The README's own troubleshooting advice reflects that. Before anything else, it tells you to ask Codex to "Update Codex with ChatGPT" and retry, because updating resolves most known issues.
Installing Codex with ChatGPT and running a first read test
There are two paths. The README's one-paste flow hands the whole job to your coding agent: it checks for git and Node.js >= 20, installs cloudflared, clones the repository into `~/codex-with-chatgpt`, builds it, copies the Skill into place, and runs first-time setup. The manual path is shorter and is what the README calls the whole manual.
First, install the Skill by copying the `skill/` directory into the Codex skills path:
cp -r skill/ ~/.codex/skills/codex-with-chatgpt/Then tell Codex to run first-time setup. The README gives the English trigger phrase "Set up Codex with ChatGPT." and the Chinese equivalent "使用 Codex with ChatGPT 完成首次配置。" Under the hood this runs the `c2c` binary, which package.json maps to `./bin/c2c.js`, and opens the built-in browser so you can configure the ChatGPT connector and enter the pairing code. The README is explicit that you should never open a third-party browser for this step.
After that, use Codex as you normally would, with the trigger "Use Codex with ChatGPT to implement XXX." The README shows the checklist you should see once the bridge is up:
Codex with ChatGPT
✓ Project detected
✓ Workspace Bridge started
✓ Secure connection established
✓ ChatGPT connected
✓ File read test passed
Ready.If the file read test does not pass, the connection is not usable regardless of what the earlier checkmarks say. The README also notes that a new workspace asks you once to create a ChatGPT Project, choosing project-only memory and naming it after the workspace, and that if the sidebar has no Projects row you hover Chats, open the … menu, and choose Organize by project.
The tunnel is the weakest link, and the README says so
The default public address is a temporary Cloudflare URL. The README states it changes when the bridge restarts, and that when it does, Codex repairs ChatGPT by deleting that workspace's connector and adding it again. That repair path is automated, but it is still a failure mode: every restart invalidates the address the web app knows about.
The mitigation is an optional stable hostname such as `c2c-<project>.your-domain.com`, available if you have a Cloudflare account and a domain already on Cloudflare. Choosing it opens a browser so you can authorize Cloudflare, and after that the ChatGPT connector keeps working across restarts. The README is candid about the alternative: if you skip it or the login fails, Codex stays on the temporary address with the same features and just a slower repair.
So the honest framing is that the tunnel is not optional, only its stability is. There is no documented mode that avoids a public address entirely, and the README does not document rollback of the connector changes Codex makes on your behalf. If your threat model forbids exposing a workspace endpoint through a Cloudflare hostname, even a read-only one, this project is the wrong tool and no configuration flag in the documentation changes that. Credentials, at least, stay in the OS app state directory rather than in the project.
How this differs from running Codex against the API directly
The obvious alternative is what most people already do: run Codex against the API, or run it however the default harness is configured, and let it plan and review on its own. That approach needs no tunnel, no OAuth handshake, no pairing code, and no browser step, and it works in an air-gapped environment. Its cost is exactly the cost the README names: planning and review consume API or Codex tokens that the project considers scarce.
The difference in approach is not model quality, it is billing and context routing. The API path sends your prompts and context to the model endpoint and pays per token. This project keeps the model in the ChatGPT web app, which you already pay for, and gives it a read-only channel into the workspace instead of a full repository upload. The README's claim is that ChatGPT reads, in its words, exactly the lines it needs.
A second, quieter difference is the control plane. Codex and ChatGPT do not share a conversation; they exchange short `[C2C]` state messages. That keeps the exchange small, but it also means the planning context lives in two places, the web conversation and the local session, and the README does not document what happens when those two drift apart mid-task. If your workflow depends on a single continuous transcript, the API path is simpler.
Maintenance, updates and what the MIT licence leaves to you
The repository is not archived and the last push was on 2026-09-09, so there is recent activity. Version 0.1.3 is in package.json, while the most recent tagged release listed is v0.1.2 from 2026-09-04, titled "Structured MCP, Safer Tunnels & Windows Polish." The two prior releases are v0.1.1 on 2026-08-31 and v0.1.0 on 2026-08-30. Three releases inside a week, at 0.x, tells you the surface is still moving.
Upgrade cost is deliberately low. The README states the Skill checks GitHub once a day and updates itself when a new version is released, with no action needed, and that you can also say "更新 Codex with ChatGPT" at any time. If you prefer the manual path, the build is ordinary: `corepack pnpm install` then `corepack pnpm build`, with Node.js >= 20 required and pnpm pinned at 11.24.0 through packageManager. Tests run with `corepack pnpm test` via vitest.
The licence is MIT. That permits commercial use, modification and redistribution with the copyright notice and permission notice retained, and it disclaims warranty. It says nothing about the ChatGPT subscription terms, the Cloudflare tunnel, or OpenAI's policies on how the web app may be used, and those are separate agreements between you and those providers. Whether routing planning work through the web UI fits your subscription tier is a question for those terms, not for this repository's LICENSE file.
Where the documentation stops
Two gaps are worth flagging before you invest time. First, the README's troubleshooting section is essentially one instruction: update and retry. There is no documented diagnostic for a bridge that starts but never reaches the file read test, and no documented rollback for the connector edits Codex makes in ChatGPT when the tunnel address changes. Second, the repository ships `examples/c2c.json` and `examples/c2cignore.example`, which suggests an ignore mechanism analogous to ignore files, but the README excerpt does not explain the schema or the matching rules. The `ignore` dependency in package.json points in the same direction without settling it.
There is also a version mismatch to keep in mind. The README's own update advice assumes you are running the latest release, while package.json already reads 0.1.3 against a newest listed tag of v0.1.2. In practice that means the self-updating Skill is the mechanism you are trusting, and the release notes are a lagging indicator of what is on your disk.
None of this makes the project unsound. It makes it early. The architecture is coherent and the failure modes are named in the README rather than hidden. But you should treat the first session as a test of the bridge, not of your codebase, and read `examples/c2c.json` yourself before assuming you can scope what ChatGPT is allowed to read.
Editorial conclusion
Adopt it if you already pay for ChatGPT Plus, Pro, Business or Enterprise and want planning and review to stop consuming API or Codex tokens, and you can accept a bridge that depends on a Cloudflare tunnel. Skip it if you need a hermetic or offline environment, if nobody on the team can debug a tunnel or an OAuth flow, or if your workspace cannot be exposed through a Cloudflare hostname even in read-only form. Before you commit, verify three things: that the c2c setup pairing code completes inside the built-in browser, that the file read test passes on your own repository, and whether you want the optional stable hostname, because the README states the default public address changes when the bridge restarts and Codex then repairs ChatGPT by deleting and re-adding that workspace's connector.
Frequently asked questions
What does Codex do in ChatGPT with this project?
In this project, Codex keeps execution: it owns shell, tests, edits and git against the local workspace. ChatGPT takes the planning and review role, reading code on demand through a read-only MCP connection.
Can I use codex-with-chatgpt with ChatGPT Go?
The README frames the problem around idle ChatGPT Plus and Pro web quota, and says no API keys are used. It does not list specific subscription tiers as supported or unsupported, so the tier question is settled by your own subscription terms, not by the repository.
Is Codex included with ChatGPT Plus?
That is a question about OpenAI's product tiers, not about this repository, and the README does not address it. What the README does say is that this project moves planning work onto a paid ChatGPT web subscription while Codex executes locally.
Is Codex now ChatGPT?
The README treats them as two separate roles rather than one product: ChatGPT is the planning and review brain in the web app, and Codex is the harness that executes shell commands, tests and edits. Its summary of that split is "ChatGPT thinks. Codex works."
How do I use codex-with-chatgpt with a ChatGPT Plus subscription?
Install the Skill by copying skill/ to ~/.codex/skills/codex-with-chatgpt/, then tell Codex "Set up Codex with ChatGPT." to run first-time setup, which runs c2c setup and opens the built-in browser for the connector and pairing code. Afterwards, start work with "Use Codex with ChatGPT to implement XXX."
What is codex-with-chatgpt?
It is a TypeScript tool, MIT licensed, that uses the ChatGPT web app as the planning and review brain for a Codex coding session while Codex keeps execution. It connects ChatGPT to the local workspace through a read-only, OAuth-protected MCP bridge, so the repository is never uploaded.
Official sources
Add this badge to your README
If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.
[](https://hysenlabs.com/projects/xiaoduoya-codex-with-chatgpt)