Codex Security is OpenAI's CLI and TypeScript SDK for finding, validating and fixing security vulnerabilities in a codebase.
It scans repositories, selected paths or Git diffs, confirms candidate findings, proposes and verifies patches, and keeps threat models and findings for later triage.
- 01
Standard, deep (parallel discovery workers) and diff scans of repos or selected paths
- 02
Finding validation, patch generation and fix verification
- 03
Saved threat models and drafted SECURITY.md policies
- 04
Offline exposed-credential checks across source, tests and unused code
- 05
GitHub code scanning import, SARIF/JSON/CSV export and Linear publishing for CI workflows
Open Source
The Codex Security CLI and TypeScript SDK are open source under the Apache 2.0 license; scans consume model usage through a ChatGPT login, an OpenAI API key, or Amazon Bedrock, OpenRouter or Fireworks AI credentials, and some cybersecurity requests require Trusted Access for Cyber approval.
Best for
Engineering and security teams that want an agentic vulnerability scanner they can run locally, in CI or from their own TypeScript tooling.
Not ideal for
Teams needing a fully offline scanner or a deterministic rules-only SAST tool, since scans rely on hosted model providers.
OpenAI's first-party, scriptable security scanner that goes beyond flagging issues to validating and patching them.
Codex Security 0.2.0, released October 6, 2026, saves threat models with Standard, Deep and Diff scan results, adds offline exposed-credential checks, and lets --model and --effort be set for patching and validation.
As of
Is Codex Security free?+
Yes - Codex Security is Open Source. The Codex Security CLI and TypeScript SDK are open source under the Apache 2.0 license; scans consume model usage through a ChatGPT login, an OpenAI API key, or Amazon Bedrock, OpenRouter or Fireworks AI credentials, and some cybersecurity requests require Trusted Access for Cyber approval.
Is Codex Security open source?+
Yes - Codex Security is open source. The Codex Security CLI and TypeScript SDK are open source under the Apache 2.0 license; scans consume model usage through a ChatGPT login, an OpenAI API key, or Amazon Bedrock, OpenRouter or Fireworks AI credentials, and some cybersecurity requests require Trusted Access for Cyber approval.
Who is Codex Security best for?+
Engineering and security teams that want an agentic vulnerability scanner they can run locally, in CI or from their own TypeScript tooling.
Who is Codex Security not ideal for?+
Teams needing a fully offline scanner or a deterministic rules-only SAST tool, since scans rely on hosted model providers.
What are the best Codex Security alternatives?+
The closest Codex Security alternatives on ai.dosa.dev are CodeRabbit, Qodo, Snyk Code - all listed under AI Code Review & Security.
Who makes Codex Security?+
Codex Security is developed by OpenAI. It is listed in the AI Code Review & Security category on ai.dosa.dev.
Favorite this tool to revisit it later, or Zap it to contribute to the public vote count.