Installation

15 min beginner

What You'll Accomplish

  • Install Codex CLI on your system
  • Authenticate with your OpenAI/ChatGPT account
  • Understand the sandbox security model
  • Run your first Codex command
NOTE
Tool Version
This lesson covers Codex CLI v0.136+. Codex is actively developed — check github.com/openai/codex for the latest release if anything below doesn't match your experience.

Before You Begin

You'll need:

  • A terminal application
  • A ChatGPT Plus, Pro, Business, Edu, or Enterprise account (for primary auth), OR an OpenAI API key
  • macOS, Linux, or Windows (with native support or WSL)

Step 1: Install Codex CLI

Recommended — Homebrew:

brew install --cask codex

Alternative — install script:

curl -fsSL https://chatgpt.com/codex/install.sh | sh

Alternative — npm (if you have Node.js):

npm install -g @openai/codex

Codex CLI now supports Windows natively (no WSL required):

Install script (PowerShell):

irm https://chatgpt.com/codex/install.ps1 | iex

Alternative — WSL:

curl -fsSL https://chatgpt.com/codex/install.sh | sh

Alternative — npm (if you have Node.js):

npm install -g @openai/codex

Step 2: Authenticate

Codex CLI supports two authentication methods:

Method 1 — ChatGPT account (recommended):

codex auth login

This opens your browser for OAuth sign-in with your ChatGPT account. No API key management needed.

Method 2 — API key (for automation or API-only access):

export CODEX_API_KEY="sk-your-key-here"

To persist this, add it to your shell profile:

echo 'export CODEX_API_KEY="sk-your-key-here"' >> ~/.zshrc
source ~/.zshrc

In your terminal:

echo 'export CODEX_API_KEY="sk-your-key-here"' >> ~/.bashrc
source ~/.bashrc
WARNING
Watch Out
Never commit API keys to git. Use environment variables or a .env file that's in your .gitignore.

Step 3: Understand the Sandbox Model

Codex CLI runs in a sandboxed environment by default. This means:

  • File operations are contained to your project directory
  • Network access is restricted
  • System-level commands are blocked unless you approve them

This gives you safety — you can ask Codex to do things and review before they take effect.

Approval policies:

  • Untrusted (default) — shows proposed changes, you approve each one
  • On-request — automatically applies file edits, asks before shell commands
  • Never — executes everything autonomously (use with caution)

Sandbox modes:

  • Read-only — Codex can read files but not write (safest for exploration)
  • Workspace-write — can write within your project directory (default)
  • Danger-full-access — unrestricted system access (advanced use only)

Step 4: Verify Installation

codex --version

Then try a quick command:

codex "List all files in this directory and explain what each one does"

You should see Codex analyse your directory and provide explanations.

TIP
Tip
Start with the default 'untrusted' approval policy until you're comfortable with how Codex works. You can always approve individual actions as you go.

Key Takeaways

  • Codex CLI installs via Homebrew, install script, or npm
  • Authentication uses ChatGPT account sign-in (recommended) or API key
  • The sandbox model keeps operations safe by default
  • Three approval policies: untrusted, on-request, never

Next up: Lesson 1 — Getting Started with Codex CLI where we'll explore the interaction model and run our first real tasks.