Skip to main content

AI Launch Profile

OpenAI releases Codex Security CLI and TypeScript SDK in limited beta

OpenAI published the Codex Security command-line client and TypeScript SDK. The CLI supports repository and change review, bulk scans, history, CI workflows, SARIF output and false-positive feedback. The SDK exposes typed findings, preflight checks, progress events and cancellation for programmatic integrations.

Security findings move from an evidence track into resolved review wells

At a glance

Launch Snapshot

Company
OpenAI
Launch date
July 28, 2026
Launch type
Open-Source Release
Category
AI Coding Tools, AI Developer Tools, AI Security
Audience
Developers, Engineering Teams, Enterprise IT, Security Teams
Pricing
OpenAI does not publish self-serve Codex Security pricing in the reviewed documentation. CLI and SDK access is limited to approved beta customers and partners through an OpenAI account team. Commercial terms, quotas and any Trusted Access for Cyber requirement are account-specific.
Free plan
No
API
Yes
Open weights/source
Yes

Verification & Sources

Status
Verified
Source links
6
Freshness
Verified July 29, 2026
Last verified
July 29, 2026
Last updated
July 29, 2026
Suggest a correction

Form submissions, correction notes, score details, URLs, and analytics events may be stored for editorial review, spam prevention, product improvement, and follow-up. Do not submit secrets, unreleased financials, private customer data, or regulated personal data through these forms.

Kingy AI Take

The CLI and SDK make Codex Security easier to insert into repeatable engineering workflows and expose useful integration primitives such as typed findings, SARIF, progress and cancellation. The release remains a limited beta, not open product availability. Teams need approved access and should validate false positives, repository scope, data handling, history retention and human triage before treating findings as release gates.

Who it is for

Approved Codex Security limited-beta customers and partners building application-security review into repositories, developer workflows or CI. OpenAI says access requires coordination with an account team; installing the package or authenticating does not independently grant the service or every scan mode.

What feels promising

A common client for local review, CI output and typed programmatic findings can reduce manual transfer between a security service and developer tooling.

What feels unproven

Kingy did not have approved beta access or run a scan. Detection quality, latency, false-positive rates, service limits and full-repository Trusted Access requirements remain environment-specific.

Traction notes

The release gives security teams a scriptable path from Codex Security into local development and CI instead of limiting the workflow to a hosted interface. It also makes the client implementation inspectable. Effectiveness, false-positive rates, data handling, and service access still need to be evaluated in each organization's environment.