At OpenAI DevDay 2026 on September 29, Codex received four updates: Codex cloud with reusable environments (Plus, Pro, Business, Healthcare, Edu, Enterprise); a refreshed Codex CLI with voice, an /agents view, prompt editing, resume, and worktrees (all plans); Code Review in the ChatGPT desktop app for GitHub PRs and GitLab MRs with automatic cloud reviews (all plans); and Codex Security Cloud for scheduled repository scans and fix preparation (Pro, Business, Enterprise, Edu). The same day, Codex CLI 0.159.1 made GPT-6.1 Sol the default model.
This guide covers what each change does, which commands you’ll use, and where the gaps are. For the rest of the event, see the DevDay 2026 hub for API developers. One gap matters for API teams: Codex writes and reviews code, but its reviews do not call your running API. That is where contract tests in Apidog fit in—the last section shows the CI wiring.
What changed in Codex at DevDay 2026
| Update | What it does | Where you use it | Plans | Status |
|---|---|---|---|---|
| Codex cloud environments | Prepare a setup once and reuse it in isolated workspaces | Web, desktop app, codex cloud
|
Plus, Pro, Business, Healthcare, Edu, Enterprise | Available |
| Refreshed Codex CLI | Voice, /agents view, prompt edit, resume, worktrees |
Terminal | All plans | Available |
| Code Review | PR and MR review pane, automatic cloud reviews | ChatGPT desktop app, GitHub, GitLab | All plans | GitHub GA; GitLab MRs in preview |
| Codex Security Cloud | Scheduled scans, deduplicated findings, fix preparation | Codex cloud, via a plugin | Pro, Business, Enterprise, Edu | Research preview |
| GPT-6.1 Sol as default | Default in the CLI’s bundled model catalog | CLI, also selectable in Codex and ChatGPT Work | Plus, Pro, Business, Enterprise, Edu; admin-enabled on Enterprise and Edu | Available |
Sources: OpenAI’s DevDay 2026 recap, the Codex what’s new page, and the Codex documentation linked below.
Codex cloud: reusable environments
Codex cloud runs coding tasks in the cloud so work can continue while your computer is asleep. The DevDay change is the environment model. According to the cloud environments documentation, an environment is a reusable setup containing repositories, dependencies, tools, and access settings. Each task gets its own isolated workspace created from the published environment version.
Create a reusable environment
- Start a new Codex task.
- Choose Work in > Cloud.
- Select Create environment.
- Choose the GitHub repositories to check out.
- Let Codex inspect the repositories, install dependencies, and test the workflow.
- Provide details Codex cannot infer.
- Review the generated setup report.
- Select Publish.
Codex records the setup in two fields:
- An install script for dependencies and project setup.
- A start skill that starts services and verifies they are ready.
Configure network access safely
Three configuration details matter for API work:
- Repository refresh runs in the background and retains dependency caches, so new tasks do not repeat installation.
- Internet access is configured per environment: use a package-manager preset, custom domains, or unrestricted access.
- Network secrets keep credentials outside the sandbox. Programs receive a placeholder, while a proxy substitutes the real value only for approved HTTPS destinations.
If a cloud task must call a staging API, add the staging host to the allowed domains and save its token as a network secret—not as a plain environment variable.
From a terminal, use codex cloud to hand work to Codex cloud and list recent cloud chats.
The refreshed Codex CLI
Install the CLI with the script from the Codex CLI documentation:
curl -fsSL https://chatgpt.com/codex/install.sh | sh
The Codex changelog also lists npm releases:
npm install -g @openai/codex
CLI version 0.159.1, released September 29, added GPT-6.1 Sol as the default model in the bundled catalog. The same changelog entry also covers the Amazon Bedrock Mantle and Runtime catalogs.
The CLI documentation uses gpt-6.1-sol medium in its sample session. According to the Codex models page, Free and Go are not included at launch, while Enterprise and Edu require an administrator to enable the model.
To change models:
/model
Or start a session with:
codex --model gpt-6-sol
For more context, see What is GPT-6.1 Sol?, including the change from GPT-6 Sol and the missing none effort.
CLI feature-to-command map
| Feature | How to use it | Source |
|---|---|---|
| Voice | Voice conversations have been on by default since 0.156.0. Press F8 to toggle and use /voice settings to select a voice. |
Changelog |
/agents view |
View your agents, filter tasks by status, and start worktree sessions. | Recap, changelog |
| Prompt edit | Edit an earlier prompt to revert the thread to that point. | Changelog |
| Resume | Run codex resume to return to a saved chat. |
CLI docs |
| Worktrees | Use /worktree to run a chat in a new Git worktree. Use /fork to copy a chat into a new chat or worktree. |
Slash command reference |
| Model | Use /model to select a model and reasoning effort. |
CLI docs |
| Local review | Use /review to check uncommitted changes, a commit, or a base branch. |
CLI docs |
Worktree support has been enabled by default since 0.156.0. This makes parallel agents practical because each agent gets its own checkout instead of editing the same files.
Run /review before committing. It reports prioritized findings without modifying your working tree.
Code Review: desktop app, GitHub, and GitLab
Code Review is a plugin in the ChatGPT desktop app. The Code Review documentation says it displays a pull request’s description, changed files, comments, and checks so you can investigate issues before approving.
GitHub review is generally available. GitLab merge request support is in preview.
Enable automatic cloud reviews
Automatic cloud reviews require:
- The ChatGPT Codex connector.
- Repository permissions.
- A connected GitHub repository.
Review comments appear both on GitHub and in the Code Review pane. Cloud review does not require you to create or manage a cloud environment.
According to the GitHub integration guide, you can manually trigger a review by commenting:
@codex review
On GitHub, Codex flags only P0 and P1 issues.
Add repository-specific review rules
Place a ## Code Review Rules section in AGENTS.md. Put the file closest to the code it governs so the rules apply at the right scope.
Keep deterministic checks in CI. Review rules do not replace tests, branch protections, or required approvals.
For a deeper workflow walkthrough, see Codex for code review.
Codex Security Cloud
Codex Security Cloud scans connected GitHub repositories in Codex cloud. OpenAI’s recap describes scheduled scans, deduplicated findings, and cloud-based fix preparation. It also includes Daybreak Blue models without a separate application. See the Daybreak Blue vs Red explainer for details on those tiers.
Codex Security Cloud is in research preview for Pro, Business, Enterprise, and Edu.
Set up a repository scan
Follow the Security Cloud setup guide:
- Install the Codex Security Cloud plugin from the ChatGPT plugin marketplace.
- Select Connect GitHub and grant access to the repositories you want to scan.
- Choose a repository and cloud environment.
- Set the target to Repository.
- Start a scan.
- For ongoing coverage, select Commit changes.
- Adjust the environment, days of history, or pause state under Monitoring settings.
- For a finding, select Fix with Codex to draft a patch.
- Select Create draft pull request to open the change for review.
For per-PR coverage, GitHub also supports:
@codex security review
This is a deeper, security-specific review currently in research preview.
Where Apidog fits: Codex reviews code, but your API still needs a test
Code Review reads diffs, descriptions, comments, and checks. It does not send requests to your running service.
A pull request can rename a JSON field or change a status code, look correct in review, and still break every API client. That is a contract problem, so it needs a test that calls the API.
Use Codex and Apidog together:
- Keep your OpenAPI specification and test scenarios in Apidog.
- Assert status codes and validate responses against endpoint schemas.
- Run scenarios in CI through the Apidog CLI on every pull request.
- Review failing contract checks alongside Codex comments in the PR.
See API contract testing for the broader approach.
Start with endpoints your clients depend on most. Assert:
- Expected status codes
- Required response fields
- Field types
- Schema compatibility
For example, if a Codex-generated pull request changes user_id to userId, the schema check fails. The CLI exits non-zero, the pull request check turns red, and reviewers see the break before they need to spot the rename in a long diff.
This split aligns with OpenAI’s guidance: use review rules for consequential, repository-specific behavior, and use CI for deterministic checks.
Run Apidog contract tests in GitHub Actions
name: api-contract-tests
on: pull_request
jobs:
apidog:
runs-on: ubuntu-latest
steps:
- run: npm install -g apidog-cli
- run: apidog run --access-token "$APIDOG_ACCESS_TOKEN" -t "$SCENARIO_ID" -e "$ENV_ID" -r cli,junit
env:
APIDOG_ACCESS_TOKEN: ${{ secrets.APIDOG_ACCESS_TOKEN }}
SCENARIO_ID: ${{ vars.APIDOG_SCENARIO_ID }}
ENV_ID: ${{ vars.APIDOG_ENV_ID }}
Codex can run the same command locally before opening a pull request, allowing it to see contract-test failures while it still has task context.
See Using the Apidog CLI in Codex for the local setup, or building a software factory with Codex for the full task-to-tested-PR loop.
FAQ
What did Codex get at DevDay 2026?
Reusable cloud environments, a refreshed CLI with voice, /agents, prompt edit, resume, and worktrees; Code Review in the desktop app with automatic cloud reviews; and Codex Security Cloud in research preview.
What is the default model in the Codex CLI now?
GPT-6.1 Sol, since CLI 0.159.1 on September 29. Use /model to switch models or change reasoning effort.
Can I use Codex cloud on the Free plan?
No. Codex cloud is available on Plus, Pro, Business, Healthcare, Edu, and Enterprise. The CLI and Code Review are available on all plans. See the free Codex guide for no-cost routes.
Does Codex Code Review test my API?
No. It reads the pull request diff, description, comments, and checks. Add API contract tests in CI so a check fails when behavior changes.
Who can use Codex Security Cloud?
Pro, Business, Enterprise, and Edu users can access it in research preview. Install it as a plugin and connect GitHub.
Next step
Update the CLI, run /model to confirm you are using gpt-6.1-sol, and try /review on your next branch.
Then download Apidog, turn one critical endpoint into a test scenario, and add the GitHub Actions job above. Every Codex-written pull request can then be checked against both the diff and the running API.
Top comments (0)