OpenAI details codex-1: an o3 variant tuned for real coding work
OpenAI's addendum to the o3 and o4-mini system card describes codex-1, a reinforced-learning-tuned o3 variant that powers Codex, its sandboxed cloud coding agent.

Updated
Why it matters
- Codex is a cloud-based coding agent powered by codex-1, a version of OpenAI o3 optimized for software engineering.
- Each Codex agent runs in its own cloud container with no internet access, preloaded with the user's code and user-defined development environment.
- codex-1 was trained with reinforcement learning on real-world coding tasks to mirror human coding style, follow instructions precisely, and iterate on tests until passing.
OpenAI has published an addendum to its o3 and o4-mini system card that describes Codex, a cloud-based coding agent powered by codex-1, a version of OpenAI's o3 reasoning model optimized specifically for software engineering.
The document, released alongside the main o3 and o4-mini system card on OpenAI's website, gives the most detailed technical picture yet of how the company built and sandboxed its agentic coding product. It matters for two reasons. First, coding agents are currently the most commercially contested application of frontier AI models, and OpenAI is competing directly with offerings such as GitHub Copilot and Anthropic's Claude-based tooling. Second, the addendum outlines concrete isolation and verification measures that speak to ongoing enterprise and policy concerns about letting autonomous agents execute code.
How codex-1 was trained
According to the addendum, OpenAI trained codex-1 using reinforcement learning on real-world coding tasks across a variety of environments. The training objectives were specific: generate code that closely mirrors human style and pull request preferences, adhere precisely to instructions, and iteratively run tests until passing results are achieved.
That last point is the notable one. Rather than producing a single code output and stopping, codex-1 was optimized to loop through test execution and refine its work until tests pass. This training approach aligns the model with how developers actually validate code, and it distinguishes codex-1 from models tuned primarily on static code completion.
Sandboxing architecture
Each Codex agent runs in its own cloud container with no internet access, the addendum states. The container is preloaded with the user's code and a development environment defined by the user, including any dependencies, configuration, or tooling they specify. Only after this setup completes does OpenAI disable internet access and begin the model trajectory.
Within that isolated environment, Codex can read and edit files and execute commands, including tests, linters, and type checkers. The design gives the agent the tools of a normal development workflow while cutting off external network effects — a balance aimed at enterprises worried about agents fetching untrusted content or exfiltrating data mid-task.
Users can ask Codex to perform coding tasks or answer questions about a codebase, the document says.
Verification by design
Codex is also trained to provide verifiable evidence of its actions through citations of terminal logs and files, allowing the user to validate the model's work. This is a direct response to one of the core criticisms of agentic AI systems: that their outputs are difficult to audit. By anchoring claims in logs and file references that the user can inspect, OpenAI positions Codex as an agent whose work can be checked rather than trusted blindly.
Once a task is complete, users can inspect the results, request refinements, or export the generated diff. Export options include converting the diff into a GitHub pull request or copying it for local testing and development. The workflow maps cleanly onto existing code review practices, which lowers the friction of adopting the agent inside real engineering teams.
Why the addendum matters
OpenAI has faced pressure from researchers and regulators to document the capabilities, limitations, and safety posture of its frontier models. System cards are the company's primary vehicle for that documentation. Publishing a dedicated addendum for Codex signals that OpenAI treats agentic coding — where a model takes actions, not just generates text — as a distinct risk and capability category deserving its own disclosure.
The security model described in the addendum is deliberately conservative: per-task containers, no internet access during execution, and user-defined environments. For potential enterprise customers evaluating whether to hand a model write access to their codebases, these are the details procurement teams will scrutinize.
The addendum also clarifies Codex's relationship to OpenAI's broader model lineup. Codex is not a new foundation model; it is codex-1, a software-engineering-optimized version of o3. That means improvements to o3's reasoning capabilities can be expected to propagate into Codex over time, even as the RL training layer specializes its behavior for engineering tasks.
OpenAI directs readers to the full o3 and o4-mini system card for broader safety and capability analysis of the underlying model family.
As coding agents move from novelty to standard developer infrastructure, the disclosures in this addendum — sandboxing, test-driven iteration, and log-based verification — will likely become baseline expectations for every vendor in the category.
Source: OpenAI News
More from Sophie Lindqvist
Show full bio
Staff writer covering marketplaces and e-commerce at AI In Context.
114 articles