Products & Tools

OpenAI's DevDay 2026: Codex Gets Cloud Environments and Security Scans

At DevDay 2026, OpenAI gave Codex reusable cloud environments, GitHub security scans, and code review, plus a Decisions API, Computer Use, and an 8x-speed Ultrafast tier at 6x the price.

OpenAI expands Codex and its API at DevDay with security scans, a Decisions API, and Ultrafast
OpenAI expands Codex and its API at DevDay with security scans, a Decisions API, and UltrafastAI-generated
By Rebecca Stone6 min read

Updated

Why it matters

  • At DevDay 2026, OpenAI gave Codex reusable cloud environments, automatic security scans for GitHub repositories, and a code review view in the desktop app.
  • The Agents API now supports Computer Use, and a new Decisions API handles fast, single decisions.
  • The Ultrafast premium tier promises up to eight times the speed at six times the price.

At DevDay 2026, OpenAI gave Codex reusable cloud environments, automatic security scans for GitHub repositories, and a code review view in the desktop app. The company also upgraded its developer platform: the Agents API now supports Computer Use, a new Decisions API handles fast, single decisions, and an Ultrafast premium tier promises up to eight times the speed at six times the price.

The announcements mark OpenAI's most substantial update to its coding agent and developer tooling since DevDay became the company's flagship developer event. Together, they show where OpenAI believes agentic software development is heading: agents that persist across sessions, run against real infrastructure, and make money by saving developers time.

Reusable cloud environments for Codex

The headline change to Codex is the introduction of reusable cloud environments. Until now, Codex sessions spun up ephemeral working contexts. With the update, developers can maintain persistent cloud environments that survive across tasks — visible in the Codex interface through filters such as "All," "Cloud," and "Jay's MacBook Pro," sitting above a project list that includes entries like "Landing page" and "Sales dashboard."

The significance is practical. A reusable environment means an agent does not have to reconstruct its context, dependencies, and repository state every time it starts a task. For teams running Codex across multiple projects — a landing page here, a sales dashboard there — the cloud environments act as durable workspaces the agent can return to.

The interface itself signals a shift in how OpenAI positions the product. By presenting local machines and cloud environments side by side, with a purple cloud icon featuring a terminal symbol marking cloud access, Codex now spans both the developer's own hardware and OpenAI's infrastructure. The agent is no longer a tool that lives only on a laptop.

Automatic security scans for GitHub repositories

The second major Codex addition is automatic security scanning for GitHub repositories. OpenAI will scan repositories for security issues without requiring developers to trigger the process manually.

Security scanning addresses one of the loudest objections to AI-assisted coding: that generated code can introduce vulnerabilities at scale. By building scanning directly into the Codex workflow, OpenAI is moving quality assurance from an afterthought into the agent loop itself. Developers using Codex on GitHub-hosted code will get security findings as part of the ordinary development flow rather than as a separate audit step.

For enterprises weighing whether to let AI agents touch production code, automated scanning lowers the barrier. It also puts Codex in more direct competition with established developer security tooling, since the scans arrive bundled with an agent developers are already using.

Code review comes to the desktop app

Codex's desktop app gained a code review view. The feature gives developers a dedicated interface for reviewing what the agent has done before changes land in a repository.

Code review is the checkpoint where human oversight of AI-generated code actually happens in most teams. Building a review view into the desktop app means developers can inspect, evaluate, and presumably accept or reject Codex's work without leaving the tool. That tightens the loop between agent output and human judgment — the step most engineering organizations identify as the bottleneck in adopting coding agents at scale.

Agents API adds Computer Use

Beyond Codex, OpenAI extended its broader developer platform. The Agents API now supports Computer Use, giving agents built on OpenAI's infrastructure the ability to operate a computer interface directly.

Computer Use matters because it generalizes agents beyond APIs and structured tool calls. An agent that can use a computer the way a person does — clicking, typing, navigating software — can operate in environments that were never designed for automation. For developers building agents on OpenAI's platform, the capability extends the range of tasks their software can complete end to end.

The move also tracks a broader industry push. Competitors have been racing to ship computer-using agents, and OpenAI adding the capability to its Agents API makes it a standard option for anyone building on the company's stack rather than a separate product.

A Decisions API for fast, single decisions

OpenAI also introduced a Decisions API, designed for fast, single decisions.

Not every agentic task requires a long-running, multi-step workflow. Many applications need a model to make one judgment call quickly — approve or reject, classify, route, flag. The Decisions API targets that use case, separating lightweight decision-making from the heavier orchestration of the Agents API.

The split reflects how AI workloads are actually deployed. Companies increasingly embed models into pipelines where latency and cost per call dominate. A purpose-built API for single decisions acknowledges that pattern and gives developers a more direct instrument for it.

Ultrafast: eight times the speed at six times the price

The most commercially pointed announcement is Ultrafast, a new premium tier that promises up to eight times the speed at six times the price.

The pricing arithmetic is the story. OpenAI is betting that developers building latency-sensitive applications will pay a 6x premium for an 8x speed gain. For workloads where response time translates directly into product quality — real-time agent interactions, live interfaces, high-volume decision pipelines — the trade can justify itself. For batch workloads, it almost certainly will not, and OpenAI's decision to keep Ultrafast as a separate tier rather than a default upgrade suggests the company expects the same split.

Premium speed tiers are becoming a standard lever in the AI infrastructure market. As base model performance commoditizes, providers are differentiating on throughput and latency. Ultrafast puts OpenAI's offer in concrete terms: a stated multiple, a stated price, and a clear choice for the developer.

Why DevDay 2026 matters

Taken together, the announcements sketch OpenAI's strategy for the agentic coding market from two directions. On the product side, Codex gains the features — persistent environments, security scans, review workflows — that turn an AI coding assistant into something closer to an infrastructure platform. On the platform side, the Agents API, Decisions API, and Ultrafast tier give developers building their own agent products more capable and more differentiated tools on OpenAI's stack.

Both directions respond to real pressure. Coding agents are among the fastest-growing categories in AI software, and enterprises have been explicit that security, oversight, and reliability determine adoption. Automatic repository scanning and an integrated review view answer those objections directly. Meanwhile, agent frameworks are proliferating, and OpenAI's API expansions — Computer Use, single-decision calls, speed tiers — are bids to keep developers building inside its ecosystem rather than on alternatives.

The pricing signal matters beyond Ultrafast itself. If developers accept a 6x price for 8x speed, expect OpenAI and its competitors to segment performance more aggressively — selling speed the way cloud providers sell compute tiers. If they don't, the premium-speed bet will force a rethink.

What comes next depends on adoption. The cloud environments, scans, and API additions are all shipping features now, not research previews, and their uptake will show whether OpenAI's bet on durable, security-scanned, review-gated agent workflows matches how teams actually want to work.

Original: the-decoder.de

Share this article:

More from Rebecca Stone

Rebecca Stone

Show full bio

Correspondent covering consumer brands and retail at AI In Context.

157 articles

Related articles

  1. OpenAI Turns Codex Cloud Environments Persistent and Reusable Across Devices
  2. OpenAI to Acquire Ona, Pushing Codex Toward Persistent Cloud Agents
  3. OpenAI's Codex Update Lets Agents Click, Type and Schedule Work
  4. OpenAI Takes Codex Coding Agent to General Availability
  5. OpenAI Upgrades Codex: Faster, More Reliable, More Autonomous

« Previous articleNext article »