Claude Code vs Codex CLI vs Cursor: An Honest Field Guide for Working Developers
I use all three. Not because I enjoy collecting tools, but because they genuinely think differently — and picking the wrong one for a task costs real time.
Last week I sat down and turned my notes into a proper cheatsheet repo: ai-coding-cheatsheet. Every command, shortcut, and config option in it was checked line by line against the official docs on 2026-10-06, and anything I couldn't verify got deleted rather than guessed at. These tools move fast, so treat anything version-sensitive as "check the official docs."
This article is the companion piece: not the command list, but the judgment — what each tool is actually for, and the habits that make them work.
Claude Code: the terminal assistant with a memory
Claude Code's defining idea is that the AI should remember your project. That memory lives in CLAUDE.md: put one at the project root (committed, shared with the team), keep personal preferences in ~/.claude/CLAUDE.md, and keep local-only notes in CLAUDE.local.md — which belongs in .gitignore. An AGENTS.md file is read too, so the two conventions can coexist.
The second defining idea is permission control. Claude Code asks before it acts, and you tune how much: plan mode makes it propose before touching anything, and the blunt instruments like --dangerously-skip-permissions exist for trusted environments only. Inside a session, Shift+Tab cycles the permission modes, and /init scaffolds a CLAUDE.md draft for you to refine by hand.
Two habits matter most. First, write verifiable instructions in your memory files — "run npm test before committing" beats "write good code" every time. Keep each file under about 200 lines; long workflows deserve their own skill file instead. Second, for anything big, start in plan mode: let the AI lay out which files it will change, nod, and only then let it type. One task, one session — don't pile unrelated work into a single conversation.
Codex CLI: the agent that separates "what" from "when"
Codex CLI's signature design decision is splitting two questions most tools blur together: what the agent is allowed to touch (sandbox) and when it has to ask you (approval). The sandbox (read-only / workspace-write / danger-full-access) and the approval policy (on-request by default, or never) are independent knobs. Once you see it, you can't unsee how useful that is.
Its superpower for automation is codex exec "fix the failing tests" — non-interactive, made for scripts and CI. It reads AGENTS.md from the project root on every run (build commands, code standards, forbidden actions), accepts an image in the first prompt for things like error screenshots, and can hand work off to the cloud. The VS Code plugin shares the same AGENTS.md, config, and MCP servers as the CLI, so your setup follows you into the editor.
The honest caveat: the flags with "dangerously" in the name mean it. Only bypass approvals and sandboxes in an isolated environment you can afford to rebuild.
Cursor: the IDE where AI is a first-class citizen
Cursor's whole pitch fits in three shortcuts: Cmd/Ctrl+K edits the selected code inline, Cmd/Ctrl+L opens a chat with your selection already in context, and Cmd/Ctrl+I hands the wheel to the Agent for multi-file rewrites. Learn those three and you know most of the tool.
Context control is explicit: @Files, @Codebase (semantic search across the repo), @Docs, @Web, @Git, or just @ a filename. Project rules live in .cursor/rules/ as one .mdc file each, with four attachment modes — Always, Auto Attached, Agent Requested, Manual — so rules can follow file patterns instead of living in one giant document. And the Agent itself has three postures: Ask (read-only, good for exploring unfamiliar code), Agent (edits files, you confirm each diff), and Plan (proposal first). One honest note from my cheatsheet: Cursor's interface changes fast, so for anything UI-related, check the official docs.
Side by side
| Claude Code | Codex CLI | Cursor | |
|---|---|---|---|
| Home turf | Terminal, any editor | Terminal, scripts & CI | Inside the IDE |
| Getting started |
claude to chat; /init scaffolds project memory |
npm install -g @openai/codex, then codex
|
Install, learn the three shortcuts |
| Permission model | Permission modes (plan → auto), tuned per session |
Sandbox and approval as separate knobs | Per-diff confirmation in Agent mode |
| Project memory |
CLAUDE.md (AGENTS.md also read) |
AGENTS.md, auto-read every run |
.cursor/rules/ + @ references |
| Best for | Long-lived terminal workflows with team-shared conventions | Scripted and automated agent runs, cloud handoff | Day-to-day editing where you live in the editor |
Five habits that work across all three
- Plan before typing. Every tool here has a plan mode. Use it for anything bigger than a typo fix — a 30-second plan review saves 30-minute cleanups.
-
Write the machine-readable rules down.
CLAUDE.md,AGENTS.md,.cursor/rules/— whichever your tool reads, the payoff is the same: stop re-explaining your build commands and taboos every session. -
Keep secrets out of the chat. Keys, tokens, private keys, customer data — never paste them in. API keys belong in environment variables, and
.envbelongs in.gitignore, never in the repo. - Respect the "dangerously" flags. They exist for isolated environments you can rebuild — not your laptop.
-
Small steps, visible diffs. One task per session,
git diffbefore moving on, and make the AI show test results — "run the tests and paste the output" beats "make sure it works."
I'm still learning these tools, and they change fast — if anything above is out of date or just wrong, I'd genuinely like to know. The full command-level cheatsheet (Chinese, Spanish, and Brazilian Portuguese versions included) lives here:
https://github.com/Ezra-Zhao/ai-coding-cheatsheet
I'm building in public at github.com/Ezra-Zhao — corrections welcome.
Top comments (0)