AI Launch Profile
OpenAI releases Codex Security CLI and TypeScript SDK in limited beta
OpenAI published the Codex Security command-line client and TypeScript SDK. The CLI supports repository and change review, bulk scans, history, CI workflows, SARIF output and false-positive feedback. The SDK exposes typed findings, preflight checks, progress events and cancellation for programmatic integrations.

At a glance
Launch Snapshot
- Company
- OpenAI
- Launch date
- July 28, 2026
- Launch type
- Open-Source Release
- Category
- AI Coding Tools, AI Developer Tools, AI Security
- Audience
- Developers, Engineering Teams, Enterprise IT, Security Teams
- Pricing
- OpenAI does not publish self-serve Codex Security pricing in the reviewed documentation. CLI and SDK access is limited to approved beta customers and partners through an OpenAI account team. Commercial terms, quotas and any Trusted Access for Cyber requirement are account-specific.
- Free plan
- No
- API
- Yes
- Open weights/source
- Yes
Launch Context
Use these links to move from this record into the broader Launch Intelligence database.
Verification & Sources
- Status
- Verified
- Source links
- 6
- Freshness
- Verified July 29, 2026
- Last verified
- July 29, 2026
- Last updated
- July 29, 2026
Key source checks
Suggest a correction
Creator Coverage Next Steps
This launch has signals that may support demos, reviews, creator education, founder storytelling, or practical product explainers.
Launching an AI product that needs clear demos, creator education, and buyer trust? Sponsor a Kingy AI video or launch feature.
Kingy AI Take
The CLI and SDK make Codex Security easier to insert into repeatable engineering workflows and expose useful integration primitives such as typed findings, SARIF, progress and cancellation. The release remains a limited beta, not open product availability. Teams need approved access and should validate false positives, repository scope, data handling, history retention and human triage before treating findings as release gates.
Who it is for
Approved Codex Security limited-beta customers and partners building application-security review into repositories, developer workflows or CI. OpenAI says access requires coordination with an account team; installing the package or authenticating does not independently grant the service or every scan mode.
What feels promising
A common client for local review, CI output and typed programmatic findings can reduce manual transfer between a security service and developer tooling.
What feels unproven
Kingy did not have approved beta access or run a scan. Detection quality, latency, false-positive rates, service limits and full-repository Trusted Access requirements remain environment-specific.
Traction notes
The release gives security teams a scriptable path from Codex Security into local development and CI instead of limiting the workflow to a hosted interface. It also makes the client implementation inspectable. Effectiveness, false-positive rates, data handling, and service access still need to be evaluated in each organization's environment.
Source-backed record