Mastering ChatGPT (OpenAI)Apps, plugins and Codex · Lesson 15 of 19

Codex: OpenAI’s coding agent for builders and teams

Article · 16 min · 8 min lecture

Video lecture

Codex: OpenAI’s coding agent for builders and teams

15 chapters · about 8 min · full transcript

Coming soon

Chapter 1 of 15

Codex

  • OpenAI’s coding agent
  • Cloud, terminal, editor, app

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

What Codex is

Codex is OpenAI's coding agent. It can write features, fix bugs, refactor, write tests, answer questions about a codebase and propose pull requests. It runs in several places, all tied to your ChatGPT plan (Plus, Pro, Business, Enterprise and Edu, with usage limits that vary):

  • Codex Web (cloud): at chatgpt.com/codex, tasks run in cloud environments connected to your GitHub repositories, several in parallel.
  • Codex CLI: a local agent in your terminal that reads, edits and runs code on your machine.
  • IDE extension: in VS Code and compatible editors such as Cursor and Windsurf.
  • Codex app: a desktop command centre for running and supervising many agent tasks, with built-in worktrees and cloud environments.
  • Code review: Codex can review pull requests on GitHub.

OpenAI's newest coding models power Codex and are updated frequently.

Getting started with the CLI

Install using the official instructions (standalone installer, npm or Homebrew), then run it in a project:

# one option from the official README
npm install -g @openai/codex

cd my-store-scripts
codex

Sign in with your ChatGPT account (or an API key for usage-based billing). Codex asks for approval according to the approval mode you choose; start conservative so it asks before running commands or editing outside the workspace.

Guide it with AGENTS.md

Codex reads an AGENTS.md file in your repository for project guidance, similar to a README for agents:

# AGENTS.md
## Project
Node.js scripts that sync Shopify orders to our Google Sheet and Slack.

## Commands
- Install: npm ci
- Test: npm test (must pass before any change is considered done)
- Lint: npm run lint

## Rules
- Never commit secrets; read tokens from environment variables.
- Don't modify /migrations or production config.
- Prefer small, focused changes with tests.
- Currency amounts are integers in minor units (fils/halalas/paisa).

Keep it short, specific and up to date.

A delegation pattern that works

  1. Plan first: "Read the repo and propose a plan to add retry logic to the Slack notifier. Don't change code yet."
  2. Small tasks: one feature or fix per task, with a clear definition of done ("tests pass; new test covers a 429 response").
  3. Parallelise carefully: in Codex Web or the app, run independent tasks in parallel on separate branches or worktrees.
  4. Review like any pull request: read the diff, run the tests, check for secrets and unexpected dependencies.
  5. Use Codex code review as an extra reviewer, not a replacement for a human.

Security and governance

  • Keep secrets out of prompts, AGENTS.md and code; use environment variables or a secrets manager.
  • Limit what cloud environments can access (network access and credentials) to what the task needs.
  • Decide who can merge AI-authored changes and require tests and review.
  • On business plans, admins can manage Codex access and settings.

Worked example: a Shopify agency's backlog

A three-person agency in Karachi maintains custom scripts for a dozen Shopify stores in the Gulf. They add AGENTS.md files, then use Codex Web to run five small backlog tasks in parallel overnight (currency formatting for SAR, a flaky test, a CSV export column). In the morning they review five pull requests: three merge after minor edits, one needs rework, one is rejected because it added an unnecessary dependency. Backlog time drops substantially, and every change still passes human review and tests.

Codex vs other coding agents

Claude Code, GitHub Copilot's agent features, Google's tools and others offer similar agentic coding. The durable skills are the same: guidance files, plan-first delegation, small tasks, tests, and review. Choose based on your repository host, security requirements and which models perform best on your codebase in a fair trial.

Hands-on

Install Codex (CLI or IDE extension) on a non-critical repository, add a short AGENTS.md, and complete one small task plan-first with a test. Review the diff as you would a colleague's.

Using Codex from the API

Teams that build their own tooling can also use OpenAI's coding models through the API (Module 7), and the Codex SDK and Agents SDK let developers embed agentic coding or custom agents in their own workflows, for example a CI job that asks an agent to propose a fix when a test fails. Keep the same rules: least-privilege credentials, sandboxed execution, and human review before merge.

Pitfalls

  • Large, vague tasks ("improve the codebase").
  • Merging without running tests or reading the diff.
  • Giving cloud environments production credentials.
  • Stale AGENTS.md files.

How to measure success

Cycle time for small tasks falls, defect rates do not rise, and every AI-authored change is tested and reviewed before merging.

Key takeaways

  • Codex is OpenAI’s coding agent across Codex Web (cloud), CLI, IDE extension, the Codex app and GitHub code review, tied to ChatGPT plans.
  • An AGENTS.md file gives Codex project commands, rules and local conventions; keep it short and current.
  • Delegate plan-first in small tasks with a definition of done; run independent tasks in parallel and review every diff.
  • Keep secrets out of prompts and files, limit cloud environment access, and require tests and human review before merging.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. What is AGENTS.md used for in Codex?
  2. Which delegation approach most often produces mergeable Codex output?

Put it into practice

Install Codex (CLI or IDE extension) on a non-critical repository, write a 10-line AGENTS.md, and complete one small task plan-first with a new test. Review the diff and note one change you requested.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.