logo Codex Security
Updated

Codex Security is OpenAI's CLI and TypeScript SDK for finding, validating and fixing security vulnerabilities in a codebase.

Pricing Free open source
Visit site
Company OpenAI
Pricing model Open Source
Paid plans None listed
Category peers 19
01Overview

It scans repositories, selected paths or Git diffs, confirms candidate findings, proposes and verifies patches, and keeps threat models and findings for later triage.

02Key features
  1. 01

    Standard, deep (parallel discovery workers) and diff scans of repos or selected paths

  2. 02

    Finding validation, patch generation and fix verification

  3. 03

    Saved threat models and drafted SECURITY.md policies

  4. 04

    Offline exposed-credential checks across source, tests and unused code

  5. 05

    GitHub code scanning import, SARIF/JSON/CSV export and Linear publishing for CI workflows

03Pricing

Open Source

The Codex Security CLI and TypeScript SDK are open source under the Apache 2.0 license; scans consume model usage through a ChatGPT login, an OpenAI API key, or Amazon Bedrock, OpenRouter or Fireworks AI credentials, and some cybersecurity requests require Trusted Access for Cyber approval.

04Who it's for

Best for

Engineering and security teams that want an agentic vulnerability scanner they can run locally, in CI or from their own TypeScript tooling.

Not ideal for

Teams needing a fully offline scanner or a deterministic rules-only SAST tool, since scans rely on hosted model providers.

05Verdict
OpenAI's first-party, scriptable security scanner that goes beyond flagging issues to validating and patching them.
ai.dosa.dev editorial · Oct 8, 2026
06Recent updates

Codex Security 0.2.0, released October 6, 2026, saves threat models with Standard, Deep and Diff scan results, adds offline exposed-credential checks, and lets --model and --effort be set for patching and validation.

As of

07Pricing & FAQ
Is Codex Security free?

Yes - Codex Security is Open Source. The Codex Security CLI and TypeScript SDK are open source under the Apache 2.0 license; scans consume model usage through a ChatGPT login, an OpenAI API key, or Amazon Bedrock, OpenRouter or Fireworks AI credentials, and some cybersecurity requests require Trusted Access for Cyber approval.

Is Codex Security open source?

Yes - Codex Security is open source. The Codex Security CLI and TypeScript SDK are open source under the Apache 2.0 license; scans consume model usage through a ChatGPT login, an OpenAI API key, or Amazon Bedrock, OpenRouter or Fireworks AI credentials, and some cybersecurity requests require Trusted Access for Cyber approval.

Who is Codex Security best for?

Engineering and security teams that want an agentic vulnerability scanner they can run locally, in CI or from their own TypeScript tooling.

Who is Codex Security not ideal for?

Teams needing a fully offline scanner or a deterministic rules-only SAST tool, since scans rely on hosted model providers.

What are the best Codex Security alternatives?

The closest Codex Security alternatives on ai.dosa.dev are CodeRabbit, Qodo, Snyk Code - all listed under AI Code Review & Security.

Who makes Codex Security?

Codex Security is developed by OpenAI. It is listed in the AI Code Review & Security category on ai.dosa.dev.

08More in Code Review
09Tags
  • Security
  • Code Review
  • CLI
  • SDK
  • Open Source
Track Codex Security in your AI stack

Favorite this tool to revisit it later, or Zap it to contribute to the public vote count.

Compare Code Review Sign in to save
Content on this page is AI-generated. Please verify details with the vendor's website for accuracy. Are you the maker? Get your Featured badge ← Back to directory