Installation
What You'll Accomplish
- Install Codex CLI on your system
- Authenticate with your OpenAI/ChatGPT account
- Understand the sandbox security model
- Run your first Codex command
Before You Begin
You'll need:
- A terminal application
- A ChatGPT Plus, Pro, Business, Edu, or Enterprise account (for primary auth), OR an OpenAI API key
- macOS, Linux, or Windows (with native support or WSL)
Step 1: Install Codex CLI
Recommended — Homebrew:
brew install --cask codex
Alternative — install script:
curl -fsSL https://chatgpt.com/codex/install.sh | sh
Alternative — npm (if you have Node.js):
npm install -g @openai/codex
Codex CLI now supports Windows natively (no WSL required):
Install script (PowerShell):
irm https://chatgpt.com/codex/install.ps1 | iex
Alternative — WSL:
curl -fsSL https://chatgpt.com/codex/install.sh | sh
Alternative — npm (if you have Node.js):
npm install -g @openai/codex
Step 2: Authenticate
Codex CLI supports two authentication methods:
Method 1 — ChatGPT account (recommended):
codex auth login
This opens your browser for OAuth sign-in with your ChatGPT account. No API key management needed.
Method 2 — API key (for automation or API-only access):
export CODEX_API_KEY="sk-your-key-here"
To persist this, add it to your shell profile:
echo 'export CODEX_API_KEY="sk-your-key-here"' >> ~/.zshrc
source ~/.zshrc
In your terminal:
echo 'export CODEX_API_KEY="sk-your-key-here"' >> ~/.bashrc
source ~/.bashrc
Step 3: Understand the Sandbox Model
Codex CLI runs in a sandboxed environment by default. This means:
- File operations are contained to your project directory
- Network access is restricted
- System-level commands are blocked unless you approve them
This gives you safety — you can ask Codex to do things and review before they take effect.
Approval policies:
- Untrusted (default) — shows proposed changes, you approve each one
- On-request — automatically applies file edits, asks before shell commands
- Never — executes everything autonomously (use with caution)
Sandbox modes:
- Read-only — Codex can read files but not write (safest for exploration)
- Workspace-write — can write within your project directory (default)
- Danger-full-access — unrestricted system access (advanced use only)
Step 4: Verify Installation
codex --version
Then try a quick command:
codex "List all files in this directory and explain what each one does"
You should see Codex analyse your directory and provide explanations.
Key Takeaways
- Codex CLI installs via Homebrew, install script, or npm
- Authentication uses ChatGPT account sign-in (recommended) or API key
- The sandbox model keeps operations safe by default
- Three approval policies: untrusted, on-request, never
Next up: Lesson 1 — Getting Started with Codex CLI where we'll explore the interaction model and run our first real tasks.