codex-in-chatgpt
v0.1.3
Published
ChatGPT thinks. Codex works. Use the ChatGPT web app as the planning and review brain for your Codex coding sessions — one command to install.
Maintainers
Readme
Codex in ChatGPT
ChatGPT thinks. Codex works.
Use the ChatGPT web app as the planning and review brain for your Codex coding sessions, while Codex keeps full ownership of execution. Your repository is never uploaded: ChatGPT reads exactly the lines it needs through a secure, OAuth-protected, read-only MCP connection to your current workspace.
No API keys. No reverse proxy. The official ChatGPT web UI plus a local read-only MCP bridge.
Quick start (one command)
npx codex-in-chatgpt initThat single command:
- sets the Codex model in
~/.codex/config.toml(default:gpt-5.6-luna) - installs the Codex skill to
~/.codex/skills/codex-in-chatgpt/SKILL.md - adds the state directory to Codex's sandbox
writable_roots - checks the environment (Node.js, git, cloudflared)
Then, inside the project you want to connect:
npx codex-in-chatgpt setupThis starts the bridge, opens a secure public connection, and prints a pairing code. Say "Connect ChatGPT" to Codex and give it the pairing code — Codex walks through the ChatGPT connector setup in the built-in browser, and you're done.
Choose a different model
npx codex-in-chatgpt init --model gpt-5.1-codex # at install time
cic model gpt-5.1-codex # any time laterThe model is written as the top-level model = "..." key in ~/.codex/config.toml.
Nothing else in that file is touched. Check the current model with cic model.
How it works
┌──────────────────────┐ OAuth 2.1 + pairing ┌──────────────────────────┐
│ ChatGPT (web app) │────────────────────────▶│ Public MCP endpoint │
│ plan · review │ read-only MCP tools │ (Cloudflare tunnel) │
└──────────────────────┘ └────────────┬─────────────┘
│ read-only
▼
┌─────────────────────┐ ┌─────────────────────┐
│ Codex Harness │ │ Local Workspace │
│ shell / tests / fix│◀────────▶│ (never uploaded) │
└─────────────────────┘ └─────────────────────┘- Control plane: Codex and ChatGPT exchange tiny structured
[C2C]state messages —INIT → PLAN → EXECUTED → REVIEW → DONE. No diffs, no logs, no file bodies are ever pasted. - Data plane (MCP): ChatGPT pulls what it needs itself through 8 read-only tools:
workspace_info,list_directory,read_file,search_workspace,git_status,git_diff,test_status,execution_summary. - Independent review: after Codex executes, ChatGPT inspects the actual git diff and test records through MCP — it never trusts "all tests passed" claims blindly.
Security model (short version)
- Read-only by construction: write/delete/shell/commit tools simply do not exist on the server. No prompt injection can enable them.
- One workspace = one boundary: every token is bound to a single workspace; path
containment uses canonical realpaths (symlink /
..// absolute-path escapes are blocked and tested). - Sensitive files never leave:
.env*, keys, SSH, credentials are denied by default (.env.exampleallowed);.cicignoreadds your own rules. - Knowing the URL grants nothing: the public MCP endpoint requires OAuth 2.1 (PKCE S256, dynamic client registration, rotating refresh tokens). Without a token: 401. Wrong workspace: 403.
- The model never sees long-lived credentials: the only secret that ever touches a browser is a one-time pairing code (5-minute TTL, 5 attempts, rate-limited, destroyed on use).
CLI reference
| Command | What it does |
| --- | --- |
| cic init | One-command install (model + skill + sandbox + env check) |
| cic setup | Connect the current workspace (bridge + tunnel + pairing code) |
| cic start / stop | Manage the bridge for the current workspace |
| cic status | Bridge, tunnel and pairing status |
| cic doctor [--fix] | Diagnose and auto-repair the local setup |
| cic pair | Fresh pairing code for the ChatGPT connector |
| cic unpair | Revoke all ChatGPT tokens for this workspace |
| cic model [id] | Show or change the Codex model (default gpt-5.6-luna) |
| cic record | Append an execution record for the review loop (used by Codex) |
| cic logs | Recent bridge log lines |
| cic update-check | Check npm for a newer release (cached daily) |
Every command supports --json for machine-readable output and -w <path> to target
a workspace other than the current directory.
Development & publishing
Maintainers: build, test, release, and MCP-registry submission steps live in PUBLISHING.md. Users never need a build step — the npm package ships prebuilt.
Status & disclaimer
V1. Simplified, English-only rebuild of the proven codex-with-chatgpt design:
bridge, OAuth + pairing, quick tunnel, one-command install.
Unofficial community project. Not affiliated with or endorsed by OpenAI.
