npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

codex-in-chatgpt

v0.1.3

Published

ChatGPT thinks. Codex works. Use the ChatGPT web app as the planning and review brain for your Codex coding sessions — one command to install.

Readme

Codex in ChatGPT

ChatGPT thinks. Codex works.

Use the ChatGPT web app as the planning and review brain for your Codex coding sessions, while Codex keeps full ownership of execution. Your repository is never uploaded: ChatGPT reads exactly the lines it needs through a secure, OAuth-protected, read-only MCP connection to your current workspace.

No API keys. No reverse proxy. The official ChatGPT web UI plus a local read-only MCP bridge.

Quick start (one command)

npx codex-in-chatgpt init

That single command:

  • sets the Codex model in ~/.codex/config.toml (default: gpt-5.6-luna)
  • installs the Codex skill to ~/.codex/skills/codex-in-chatgpt/SKILL.md
  • adds the state directory to Codex's sandbox writable_roots
  • checks the environment (Node.js, git, cloudflared)

Then, inside the project you want to connect:

npx codex-in-chatgpt setup

This starts the bridge, opens a secure public connection, and prints a pairing code. Say "Connect ChatGPT" to Codex and give it the pairing code — Codex walks through the ChatGPT connector setup in the built-in browser, and you're done.

Choose a different model

npx codex-in-chatgpt init --model gpt-5.1-codex   # at install time
cic model gpt-5.1-codex                           # any time later

The model is written as the top-level model = "..." key in ~/.codex/config.toml. Nothing else in that file is touched. Check the current model with cic model.

How it works

┌──────────────────────┐   OAuth 2.1 + pairing   ┌──────────────────────────┐
│  ChatGPT (web app)   │────────────────────────▶│  Public MCP endpoint      │
│  plan · review       │   read-only MCP tools   │  (Cloudflare tunnel)      │
└──────────────────────┘                         └────────────┬─────────────┘
                                                              │ read-only
                                                              ▼
      ┌─────────────────────┐          ┌─────────────────────┐
      │    Codex Harness    │          │   Local Workspace   │
      │  shell / tests / fix│◀────────▶│  (never uploaded)   │
      └─────────────────────┘          └─────────────────────┘
  • Control plane: Codex and ChatGPT exchange tiny structured [C2C] state messages — INIT → PLAN → EXECUTED → REVIEW → DONE. No diffs, no logs, no file bodies are ever pasted.
  • Data plane (MCP): ChatGPT pulls what it needs itself through 8 read-only tools: workspace_info, list_directory, read_file, search_workspace, git_status, git_diff, test_status, execution_summary.
  • Independent review: after Codex executes, ChatGPT inspects the actual git diff and test records through MCP — it never trusts "all tests passed" claims blindly.

Security model (short version)

  • Read-only by construction: write/delete/shell/commit tools simply do not exist on the server. No prompt injection can enable them.
  • One workspace = one boundary: every token is bound to a single workspace; path containment uses canonical realpaths (symlink / ../ / absolute-path escapes are blocked and tested).
  • Sensitive files never leave: .env*, keys, SSH, credentials are denied by default (.env.example allowed); .cicignore adds your own rules.
  • Knowing the URL grants nothing: the public MCP endpoint requires OAuth 2.1 (PKCE S256, dynamic client registration, rotating refresh tokens). Without a token: 401. Wrong workspace: 403.
  • The model never sees long-lived credentials: the only secret that ever touches a browser is a one-time pairing code (5-minute TTL, 5 attempts, rate-limited, destroyed on use).

CLI reference

| Command | What it does | | --- | --- | | cic init | One-command install (model + skill + sandbox + env check) | | cic setup | Connect the current workspace (bridge + tunnel + pairing code) | | cic start / stop | Manage the bridge for the current workspace | | cic status | Bridge, tunnel and pairing status | | cic doctor [--fix] | Diagnose and auto-repair the local setup | | cic pair | Fresh pairing code for the ChatGPT connector | | cic unpair | Revoke all ChatGPT tokens for this workspace | | cic model [id] | Show or change the Codex model (default gpt-5.6-luna) | | cic record | Append an execution record for the review loop (used by Codex) | | cic logs | Recent bridge log lines | | cic update-check | Check npm for a newer release (cached daily) |

Every command supports --json for machine-readable output and -w <path> to target a workspace other than the current directory.

Development & publishing

Maintainers: build, test, release, and MCP-registry submission steps live in PUBLISHING.md. Users never need a build step — the npm package ships prebuilt.

Status & disclaimer

V1. Simplified, English-only rebuild of the proven codex-with-chatgpt design: bridge, OAuth + pairing, quick tunnel, one-command install.

Unofficial community project. Not affiliated with or endorsed by OpenAI.

License

MIT