codex-ide
v1.2.9
Published
Eigenständige Codex IDE mit lokalem Modell, OpenAI-kompatibler API, Codex Auth-Bridge und integriertem Skill-System.
Downloads
60
Readme
Codex IDE
Your agent at work — every change, live.
Codex IDE is a standalone agentic browser development environment. It combines a safe local workspace, multi-buffer code editor, live agent activity, three model backends, and a fully integrated skill system. Its dark application shell uses a warm crimson-and-coral visual system and remains fully responsive from desktop down to narrow mobile screens.
Quick start
Node.js and npm are required. The Codex backend additionally requires the official Codex CLI.
npm install -g codex-ide
codex-ide startThe IDE opens at http://localhost:8787/. There is no separate landing application: index.html is the IDE.
For local development from the source directory, npm install and ./codex-ide start remain available.
Backends
- Local (
local): a Transformers.js text model running in the browser; internal one-shot calls use their own token budget without changing the saved user limit. - API (
api): an OpenAI-compatible endpoint such as OpenAI, OpenRouter, Ollama, or LM Studio. - Codex auth bridge (
codex): official local Codex CLI sign-in with a persistent Codex App Server, streaming, model catalog, reasoning level, and remaining usage limits.
The reasoning selector follows the live model catalog. Supported levels through xhigh, max, and ultra are preserved and shown only for models that advertise them.
All configuration is part of the IDE. The backend can be switched from both the header and settings; language is switched directly in the header through flag buttons.
Codex sign-in:
codex-ide codex login
codex-ide codex login --device-auth
codex-ide codex statusThe same commands can be copied under Settings → Codex auth bridge. Two bars show the remaining daily/short-window and weekly allowance reported by the Codex CLI. Available values are blue; at 20 percent or less a bar turns red and is also labeled low. A period not returned by Codex remains visibly unavailable rather than being estimated. Check status refreshes gateway, sign-in, and usage, while Test gateway sends a short real Codex request.
Features
- safe workspace under
model-home/ - file tree, folders, tabs, dirty state, and syntax rendering
- contextual play button for saved
.htmlfiles with an isolated browser preview - automatic IDE persistence with gateway confirmation
- accelerated character-paced, localized code patches without an artificial size limit: backspace/deletion advances in small adaptive Unicode batches in red, insertion in green with a trailing caret; full-file rebuilds are rejected even for short existing files and atomically at the gateway
- demand-driven project reads; a scoped directory is traversed directly instead of after a global scan, and only files actively being edited open tabs automatically
- fast turn startup without a second full workspace scan or CLI login check
- autonomous multi-file editor actions with a completeness audit
- on-demand model live console inside the agent/reasoning area for autonomous syntax checks, deterministic local Jest/npm tests, linters, type checks, and builds with untruncated, UTF-8-safe, incrementally rendered stdout/stderr, model stdin, and exit status
- a user console activated locally with
/console start:rm folderrecursively removes normal directory trees, and running Python scripts that useinput()receive subsequent prompt entries through a real PTY;/console closeexits the mode without contacting the model - named, locally persistent agent sessions with a visible complete transcript, crash-safe turn state, App Server thread resume, switching, renaming, and deletion
- German, English, and French UI
- installable PWA with controlled updates
- npm version checks and confirmed self-updates with an unchanged
model-home - integrated skill installation, profiles, permissions, setup, tests, and uninstall
- local
.codexskillpackages
Skills
Open Settings → Skills to configure built-in and installed skills for local, api, and codex. External entrypoints run JavaScript inside the app and therefore require an explicit trust confirmation.
codex-ide skill validate skill_packages/PDF_Skill
codex-ide skill pack skill_packages/PDF_SkillSee SKILL_DEVELOPMENT_EN.md for development guidance.
Security
The gateway binds to loopback by default and rejects foreign browser hostnames without an explicit origin allowlist to prevent DNS rebinding. Workspace actions stay confined to model-home/; absolute paths, traversal, control characters, protected targets, and both escaping and dangling symlinks are blocked. Static files must remain inside the application-shell root after symlink resolution. The read-only HTML preview is likewise confined to model-home/, is never cached, and runs in a CSP sandbox without access to the IDE origin. In Codex mode the App Server reads files through the bounded codex_ide_workspace tool. Native patch approvals are declined without aborting the turn; changes remain exclusive to the visible editor. On Termux/PRoot, a discarded workspace copy, isolated writable temporary area, and locally built seccomp runner replace the unavailable bubblewrap sandbox without enabling dangerFullAccess. Jest and npm can create cache files while the real model-home remains unchanged. Model and console turns have no artificial runtime, action, retry, or output ceiling; gateway timeouts remain disabled so a 24-hour turn runs until real completion or an explicit stop. Codex CLI browser credentials are neither requested nor stored.
App Server JSONL and console streams use stateful UTF-8 decoders, so an umlaut or emoji split between chunks cannot corrupt an active turn. A restarted App Server discards incomplete bytes and lines from the old process. Long response and console deltas are accumulated linearly; the browser appends only new output and completion does not retransmit an aggregate that was already streamed.
The separate user console is controlled only by the locally intercepted /console start and /console close directives; neither those directives, entered commands, nor subsequent program input are sent to a model turn or stored in the agent session. It intentionally operates in the real model-home so the user can modify or delete normal workspace files and run their own programs. While a command is running, the still-active prompt sends arbitrary lines, including a blank line, to that process through its PTY; Stop terminates it. Only in this user channel, rm enables recursive deletion by default, so rm folder removes a normal directory tree. The runner exposes stdin, stdout, and stderr through a real PTY. Python therefore detects an interactive console: output from statements already executed is visible before the corresponding input(), only that input call waits, and submitted input resumes the script in normal program order. The seccomp runner still checks every file path and blocks network and privilege paths, write or delete targets outside model-home, protected targets such as .git, node_modules, .env*, and memory.md, and symlink targets. The model console and all existing editor permissions remain unchanged.
npm updates
model-home always remains fixed at <project>/model-home; installation and updates never configure another workspace location. A globally installed interactive codex-ide start checks for a newer stable npm version by reading the npm latest dist-tag directly and waits up to 20 seconds for slower registries. Use --no-update-check or CODEX_IDE_NO_UPDATE_CHECK=1 to skip that check.
codex-ide version
codex-ide update
codex-ide update --yesBefore npm replaces the package, codex-ide update copies model-home into a neutrally named temporary backup and verifies it with SHA-256. After either a successful npm update or an npm failure, the updater restores the workspace at the exact same project path and verifies it again. The temporary backup is removed only after verification succeeds. Self-update is intentionally restricted to a global npm installation and never overwrites a local source checkout. Keep .gitkeep and .npmignore during manual model-home cleanup; the nested ignore file prevents any other workspace content from entering the package and is not published itself.
More commands
codex-ide start --no-open
codex-ide gateway
codex-ide gateway --open
codex-ide clean
npm run pwa:validate
npm test -- --runInBandTechnical documentation: DOKUMENTATION_EN.md.
License
MIT, see LICENSE.
