OpenAI Codex: the coding agent, and which Codex this is not

OpenAI Codex is a software development agent from OpenAI. You give it a goal or a task, it gathers the context it needs in your repository, takes action and produces working code. The name needs clearing up first: this is not a medieval codex, not the Codex Alimentarius food standards of the UN and WHO, and not one of the Frankfurt businesses that carry Codex in their company name.

For a finance developer the interesting comparison is with Claude Code, and the interesting question is what a bank's platform team has to settle before either of them runs on a work machine.

What OpenAI Codex is and where it runs

OpenAI's own documentation lists four surfaces: the Codex CLI for the terminal, the Codex IDE extension, Codex Cloud, and Codex inside the ChatGPT desktop, mobile and web apps. The same tool therefore reaches a developer at a terminal and a reviewer on a phone, which is why teams end up using more than one surface.

The security model has four named parts in that documentation: sandboxing, agent approvals, auto-review, and profile-based permissions. Sandboxing limits what the agent can reach, approvals put a person in front of actions that matter, auto-review has the system check work before a human does, and permission profiles let a team grant different rights in different contexts.

One historical note to avoid confusion: OpenAI published something called Codex years ago as a model that translated natural language into code. The product described here is the development agent, not that earlier model, and descriptions of the old one do not apply.

AGENTS.md and how a team sets the rules

Codex reads an AGENTS.md file in the repository as its agent configuration. That file is where a team writes the operational rules: which commands to run, which conventions to follow, what the agent must leave alone, and how subagents split larger work. OpenAI's documentation groups it with subagents and rules management under agent configuration.

For a bank this file is the control document, and it belongs in version control like any other. A reviewer can see who changed the rules and when, which is the question an auditor asks about any automated process.

What it does in a finance codebase, and where the limits sit

The work it suits is the same work any coding agent suits: writing the tests that cover rounding, currency conversion and cutoff handling in old payment code, carrying a library upgrade across many files, and explaining a service whose author has left the firm. Codex also runs code review as part of the development workflow, which puts a first pass on a pull request before a colleague reads it.

The limits are worth stating plainly. An agent does not know your firm's unwritten conventions unless the AGENTS.md file says them. It does not know which systems are in scope for a regulatory audit. And it does not carry accountability: the pull request still needs a human approver, and in a regulated firm that approval is the control, not a formality.

Codex and Claude Code side by side

Both are agents that work in a repository, both run from a terminal, an IDE and a cloud surface, and both ask before they act. Claude Code from Anthropic is steered from terminal, VS Code, JetBrains, Slack and the web and asks permission before changing a file or running a command. Codex covers the CLI, IDE extension, cloud and the ChatGPT apps with the sandboxing and approval model described above. Both read a repository instructions file.

Neither is placed above the other here. ChatGPT and Claude compared for finance sets out the comparison and explains why the decision in a bank usually follows the cloud and the identity provider the firm already runs.

What does a bank ask about a coding agent?

Where the code goes and under which contract, whether the provider may train on it, which repositories the agent may reach, whether it may run commands that touch the network, how its actions show up in the audit log, and who approves its pull requests. Those six questions decide whether a tool gets on a work machine.

The sandboxing and permission profiles in Codex are the mechanism for several of those answers, but the policy comes first. A permission prompt that every developer clicks through is not a control, and the EU AI Act obligations attach to the system the code ends up in, whoever or whatever wrote it.

Where do developers in Frankfurt discuss both?

At the German-language Claude meetup the Agentic AI Community Frankfurt runs every other week at byte5 GmbH in the Speicherstraße, where programming and web development sit on the agenda next to prompting and AI workflows, and where people compare the tools they actually use. Claude meetups in Frankfurt has the format.

Finance Loop runs Claude Hacker House for people in finance, and AI in Frankfurt lists the rest of the city's AI scene by institution and event.

AI coding tools and Finance Loop

Finance Loop brings together the developers and platform people in Frankfurt's finance firms who put coding agents on real repositories and then had to explain the arrangement to risk and audit. Finance Loop is the meeting place for that conversation, and it names the tools without selling any of them.

Finance Loop is a professional network and has the goal of driving the adoption of emerging technologies in finance, such as AI, tokenization, stablecoins, and DeFi. Finance Loop helps its members build skills and personal networks in these fields: Investment & Digital Assets, Payments & Digital Money, Digital Infrastructure & Sovereignty, and Risk & Compliance.

Let's stay in touch

4,000+ members in finance and tech. Become a Network Member for free.

Get updates for free!

Exclusive event invitations, member perks and news from the network. Unsubscribe at any time.

By submitting you agree to the terms.