Codex Cloud: Delegating Tasks to OpenAI’s Cloud Agent

Codex cloud runs coding tasks in containers on OpenAI’s side while you do something else. How to connect GitHub, set up an environment, start tasks from the web, your editor, the terminal, GitHub, Slack or Linear, review the result, and keep it safe.

7 min read

Codex cloud is the version of OpenAI’s coding agent that runs on OpenAI’s machines instead of yours. You connect a GitHub repository, describe a task, and Codex checks out the code in an isolated container, runs your setup, edits files, runs checks and comes back with a summary and a diff that you can turn into a pull request. Because nothing runs on your laptop, you can start several tasks at once and close the lid. You start them at chatgpt.com/codex, which the openai/codex README calls Codex Web, or from your editor, the terminal, a GitHub comment, Slack or Linear. It needs a ChatGPT sign-in; an API key is not enough.

OpenAI’s own pages now call these runs “cloud chats”; this post says tasks, because that is what each one is. This page is about using cloud well. How it compares with the CLI, the IDE extension and the desktop app is in Codex app vs CLI vs IDE extension.

What happens when you start a task

OpenAI’s cloud environments page (opens in a new tab) describes the same five steps for every task:

  1. Codex creates a container and checks out your repository at the chosen branch or commit.
  2. It runs your setup script, or a maintenance script when it resumes a cached container.
  3. It applies the environment’s internet settings. Setup has internet access; the agent, by default, does not.
  4. The agent works in a loop: edits code, runs commands, checks its work. It reads AGENTS.md to find your lint and test commands.
  5. It shows its answer and a diff. You open a pull request or ask for changes.

Connect GitHub

Open Codex in ChatGPT, sign in, and connect GitHub when asked, choosing which repositories Codex may access. GitLab is also offered, marked Beta. OpenAI’s authentication page (opens in a new tab) adds one requirement: because cloud works directly on your code, an account that signs in with email and password must set up multi-factor authentication first. Social and single sign-on accounts should turn it on with their provider.

Set up an environment

An environment is the recipe for one repository’s container. Tasks run on a default image called universal, with common languages and tools installed, and you can pin versions of Python, Node.js and other runtimes. For npm, yarn, pnpm, pip, pipenv and poetry projects, Codex can install dependencies itself. Anything else goes in a setup script.

Environment settings — setup script
pnpm install
pip install pyright
# export does not carry into the agent phase;
# add variables in the environment settings or ~/.bashrc instead
  • Environment variables last for the whole task. Secrets are extra-encrypted and available only to setup scripts; they are removed before the agent starts.
  • Containers are cached for up to 12 hours. Changing the setup script, maintenance script, variables or secrets clears the cache; Reset cache does it by hand.
  • On Business and Enterprise workspaces the cache is shared by everyone with access to the environment.

Decide on internet access

Agent internet access is off by default and set per environment. The agent internet access page (opens in a new tab) lists the risks of turning it on: prompt injection from web content, leaking code or secrets, pulling in malware or vulnerable packages, and licence problems. If a task needs it, turn it on narrowly.

  • Start from the Common dependencies allowlist, or from an empty list, and add domains one at a time. All is unrestricted.
  • Restrict methods to GET, HEAD and OPTIONS, which blocks posts and uploads.
  • Read the work log afterwards, not just the diff.

Where you can start a task

  • The web: chatgpt.com/codex. Choose the environment, describe the result, then watch the log or leave it.
  • Your editor: the IDE extension can send a task to the cloud and bring the result back to review.
  • The terminal: codex cloud opens a picker, and codex cloud exec --env <ENV_ID> "task" submits one directly.
  • GitHub: comment @codex on a pull request with a request, such as @codex fix the CI failures, and it starts a cloud task with the pull request as context. @codex review asks for a code review.
  • Slack: mention @Codex in a channel or thread. It reads the thread, picks an environment and replies with a link and the result.
  • Linear: assign an issue to Codex, or mention @Codex in a comment. Triage rules can assign new issues automatically.

In Slack and Linear, Codex picks the environment that best matches the request and falls back to the one you used most recently, so name the repository when it matters: @Codex fix this in acme/api. The Linear integration page (opens in a new tab) adds that tasks started by triage rules run under the account of the person who created the issue.

Run several at once

Each task gets its own container, so tasks do not share files and your machine is not involved. Start three small, separate tasks and review them as each finishes. For a problem with more than one reasonable answer, codex cloud exec --attempts 3 asks for several attempts at the same task, from one to four, so you can keep the best.

Review the result and open a pull request

A finished task shows a summary, the diff and the logs. Read all three: the summary says what Codex believes it did, the logs show what it ran and whether the tests passed. Ask for changes in the same task, or open a pull request when it is ready. To try the change locally first, codex apply <TASK_ID> applies the diff to your working tree and exits with an error if it conflicts. Then review the pull request like any other. The GitHub integration page (opens in a new tab) is clear that Codex’s own reviews do not replace tests, branch protection or required approvals.

What to put in a task

  • One outcome per task. “Add CSV export to the orders page” is a task; “improve the dashboard” is not.
  • Where to look: the files, the error, the failing test.
  • Constraints: what must not change, which patterns to follow.
  • Done when: the tests that must pass, the behaviour that must be visible.
  • Setup the environment cannot guess goes in the environment, and project rules go in AGENTS.md, not in every prompt.

A well-specified task is a small spec. If you find yourself writing several paragraphs, see spec-driven development and consider splitting it.

Security in short

  • Tasks run in isolated containers with no access to your computer.
  • Secrets never reach the agent phase. Anything the agent needs at run time is a variable, so keep real credentials out of it.
  • Internet access stays off unless you allow it, with the narrowest allowlist that works.
  • Point Codex only at issues and pages you trust. An issue body can carry instructions meant for the agent; see indirect prompt injection.
  • Slack answers can include information from the environment. Enterprise admins can limit Codex to posting a link.
  • Merge nothing you have not reviewed.

Keeping delegated tasks on a board

Delegating makes it easy to lose track: five cloud tasks, two pull requests, one abandoned. The list of what was asked for, and what came back, is worth keeping in one place outside Codex. OpenAI’s cloud environment settings cover scripts, variables and internet access rather than MCP servers, so the board connection sits with your local Codex. With fenbs added to the CLI, the loop is: read the task in Next Up, submit it with codex cloud exec, move the task to In Progress with the cloud task link in a comment, and when the pull request is merged, set testStatus and testNotes from what the logs show and move it to Completed. Each change is recorded under the assistant’s name. Connection steps are on Codex CLI on fenbs.

Related

Every CLI command in one place, including codex cloud and codex apply: Codex CLI commands. Habits for local runs: Codex CLI best practices. Keeping a human gate on agent pull requests: AI agents for PR review.

Questions people ask.

What is Codex cloud?

OpenAI’s coding agent running in isolated containers on OpenAI’s side. You connect a repository, describe a task, and it returns a summary and a diff that you can open as a pull request.

Is Codex web the same as Codex cloud?

Yes. The openai/codex README calls the cloud-based agent Codex Web, at chatgpt.com/codex, while OpenAI’s documentation now calls it Codex cloud. It is not the same as ChatGPT on the web, where Work handles documents and research rather than repositories.

Does Codex cloud have internet access?

Setup scripts do, so they can install dependencies. The agent does not by default. You can turn it on per environment, limited to a domain allowlist and to safe HTTP methods if you choose.

Can I use Codex cloud with an API key?

No. OpenAI says Codex cloud requires signing in with ChatGPT, and accounts that use email and password must set up multi-factor authentication first.

Start with one thing.

There is nothing to set up first. Write one line and you’ve started.