AI Launch Profile
OpenAI releases Codex Security CLI and TypeScript SDK in limited beta
OpenAI published the Codex Security command-line client and TypeScript SDK. The CLI supports repository and change review, bulk scans, history, CI workflows, SARIF output and false-positive feedback. The SDK exposes typed findings, preflight checks, progress events and cancellation for programmatic integrations.

At a glance
Launch Snapshot
- Company
- OpenAI
- Launch date
- July 28, 2026
- Launch type
- Open-Source Release
- Category
- AI Coding Tools, AI Developer Tools, AI Security
- Audience
- Developers, Engineering Teams, Enterprise IT, Security Teams
- Pricing
- OpenAI does not publish self-serve Codex Security pricing in the reviewed documentation. CLI and SDK access is limited to approved beta customers and partners through an OpenAI account team. Commercial terms, quotas and any Trusted Access for Cyber requirement are account-specific.
- Free plan
- No
- API
- Yes
- Open weights/source
- Yes
Launch Context
Use these links to move from this record into the broader Launch Intelligence database.
Verification & Sources
- Evidence state
- Recheck due
- Source links
- 6
- Freshness
- Needs recheck: checked July 29, 2026
- Last updated
- July 29, 2026
What this evidence state means
- Definition
- The claim was previously checked, but its review window expired or a material change may have invalidated it.
- Required provenance
- The prior evidence and check date are retained, together with the expiry or change signal that triggered recheck.
- Owner
- Kingy freshness queue owner and assigned editorial reviewer
- Freshness rule
- This is already outside its freshness rule. It must not be presented as current until reviewed against current evidence.
- Disputes and corrections
- Use “Suggest a correction” on the record. Kingy editorial reviews the cited evidence, records material corrections, and changes or removes the state when it is not supported.
Key source checks
Suggest a correction
Creator Coverage Next Steps
This launch has signals that may support demos, reviews, creator education, founder storytelling, or practical product explainers.
Launching an AI product that needs clear demos, creator education, and buyer trust? Sponsor a Kingy AI video or launch feature.
Kingy AI Take
The CLI and SDK make Codex Security easier to insert into repeatable engineering workflows and expose useful integration primitives such as typed findings, SARIF, progress and cancellation. The release remains a limited beta, not open product availability. Teams need approved access and should validate false positives, repository scope, data handling, history retention and human triage before treating findings as release gates.
Who it is for
Approved Codex Security limited-beta customers and partners building application-security review into repositories, developer workflows or CI. OpenAI says access requires coordination with an account team; installing the package or authenticating does not independently grant the service or every scan mode.
What feels promising
A common client for local review, CI output and typed programmatic findings can reduce manual transfer between a security service and developer tooling.
What feels unproven
Kingy did not have approved beta access or run a scan. Detection quality, latency, false-positive rates, service limits and full-repository Trusted Access requirements remain environment-specific.
Traction notes
The release gives security teams a scriptable path from Codex Security into local development and CI instead of limiting the workflow to a hosted interface. It also makes the client implementation inspectable. Effectiveness, false-positive rates, data handling, and service access still need to be evaluated in each organization's environment.
Source list
Sources
Related Kingy Links
Editorial submissions and sponsor-fit reviews are separate. Payment does not influence Kingy scores, verdicts, rankings, evidence labels, or publication decisions.