Editorial illustration for OpenAI expands Codex API with security scans and agents that run software
OpenAI Upgrades Codex with Security Scans and Agents
OpenAI used its DevDay 2026 conference in San Francisco to load up Codex and its developer API with tools aimed at making coding assistants faster, more autonomous, and harder to exploit. Codex now runs on reusable cloud development environments, comes with a voice-controlled command line interface, and gets a code review feature built into the ChatGPT desktop app. A companion tool, Codex Security Cloud, scans repositories for vulnerabilities and drafts fixes without a developer asking it to.
The changes go beyond Codex itself. OpenAI added a feature called Computer Use to its Agents API, letting agents click through and operate software on their own rather than just generating code. The company also introduced a Decisions API, built on a model called GPT-6 Luna, designed for quick single-choice tasks like classification. For teams that want raw speed, there's a new pricing tier called Ultrafast that multiplies token generation costs but cuts response times.
Together, the announcements point to OpenAI pushing Codex from a coding helper toward something closer to an autonomous operator, while giving paying customers more control over how fast and how expensively they can run it.
Codex now gets reusable cloud environments and can scan repositories for security holes. The Agents API picks up Computer Use, and OpenAI is adding a Decisions API and Ultrafast, a pricey new speed tier.
Why this matters
For developers, the calculus around Codex just shifted. Security scans that auto-generate fixes and agents that can operate software directly mean less time babysitting code review and more surface area for things to go wrong unsupervised. That trade-off deserves scrutiny, not applause.
Computer Use has been sitting in beta since September 11 on the same infrastructure as ChatGPT and Codex, so OpenAI clearly sees this as core plumbing, not a side experiment. Founders building on the Agents API now have to think about what happens when an agent makes a change to a live system without a human checking first. Reusable cloud environments and voice-controlled CLI tools are conveniences.
Letting an agent take actions inside software it's supposed to be securing is a different category of risk. We'd rather see OpenAI publish failure rates and audit logs for Codex Security Cloud than take "prepares fixes automatically" at face value. The pattern here is consistent: OpenAI keeps shipping autonomy features faster than the tooling to verify what those agents actually did once they're done.
Common Questions Answered
What new security features did OpenAI add to Codex at DevDay 2026?
OpenAI introduced Codex Security Cloud, a companion tool that automatically scans repositories for vulnerabilities and drafts fixes without requiring developer intervention. This feature represents a significant shift in how developers can approach code security, reducing the need for manual code review processes.
How does the Agents API enhance Codex's capabilities with Computer Use?
The Agents API now includes Computer Use functionality, allowing Codex agents to operate software directly and run tasks more autonomously than before. This capability enables developers to delegate more complex coding tasks to the AI, though it also expands the surface area for potential unsupervised errors.
What infrastructure improvements did Codex receive for cloud development?
Codex now runs on reusable cloud development environments and includes a voice-controlled command line interface for easier interaction. Additionally, a code review feature has been built directly into the ChatGPT desktop app, streamlining the development workflow.
What is Ultrafast and how does it differ from standard Codex API pricing?
Ultrafast is a new premium speed tier introduced at DevDay 2026 that offers faster performance for Codex API operations at a higher price point. This option caters to developers who prioritize speed and responsiveness over cost efficiency.
Why does OpenAI's addition of autonomous agents to Codex warrant caution according to the article?
While autonomous agents reduce developer oversight needs for code review and fixes, they simultaneously increase the risk of unsupervised errors and security issues occurring without human intervention. The article suggests this trade-off between efficiency and control deserves careful scrutiny rather than immediate adoption.
Further Reading
- Introducing the Agents API - OpenAI
- Agents API - OpenAI Developers - OpenAI Developers
- Codex Security FAQ - OpenAI Help Center
- Self-hosted sandboxes - OpenAI Developers
- OpenAI open-sources Codex Security CLI for repository vulnerability scanning - RuntimeWire