Codex Cloud Setup: Reusable Environments and Cloud Tasks

This research library uses AI-assisted source research and drafting. Linked sources support product claims; analysis and proposed exercises are our interpretation. Unless an article documents a test and its results, do not read it as a hands-on review or an independently verified benchmark.
Codex Cloud runs Codex coding tasks in an OpenAI-hosted VM, so work continues while your computer is asleep and you can review it from the web, the ChatGPT desktop app, or your phone. At DevDay on 29 September 2026, OpenAI added reusable cloud environments: you prepare a project setup once, publish it, and every new task starts from that prepared filesystem. The Codex Cloud docs describe the flow, and this page adds the decisions you will hit on day one.
Who can use Codex Cloud, and what does a task get?
OpenAI lists Codex in the cloud for Plus, Pro, Business, Healthcare, Education, and Enterprise plans. It is not part of API-key sign-in: the Codex pricing page lists cloud chats, cloud environments, and GitHub code review as ChatGPT plan features. Local messages and cloud chats share one usage allowance, and the same page notes that cloud tasks may use more of it than local messages.
Each task runs in its own VM. These are the default sizes from the cloud environments guide:
| ChatGPT plan | vCPUs | Memory | Disk |
|---|---|---|---|
| Plus, Edu Plus | 2 | 8 GiB | 8 GiB |
| Pro, Business, Enterprise | 4 | 16 GiB | 32 GiB |
| Edu, Edu Pro | 4 | 16 GiB | 32 GiB |
A task's saved VM state stays recoverable for up to seven days after you last start a turn or resume it. Enterprise workspaces can ask their OpenAI account team about larger VMs.
Create and publish a Codex environment
A Codex environment is the reusable setup that tasks use: repositories, dependencies, tools, and access settings. You do not have to write an install script yourself. Codex inspects the repositories, proposes a setup, and tests it with you.
- Open ChatGPT on the web or in the desktop app. In a new task, choose Work in > Cloud, open Select environment, and select Create environment.
- Select the GitHub repositories to check out. Connect GitHub if prompted.
- Select Get started. Codex installs dependencies and tools, then tests the workflow. Answer its questions about missing access, versions, or services.
- Review the setup report, configuration, and files. Save your changes, select Publish, and wait for Environment published.
- Select Start a new task and describe the work.
You can also begin from Settings > Codex Cloud > Environments > Create environment.
Codex records the tested setup in two fields. The install script holds commands that install dependencies and prepare development assets. The start skill holds instructions that start services and check they are ready.
Three verbs mean different things here. Saving stores configuration. Publishing captures the prepared filesystem for new tasks. Sharing controls who can use the environment.
Skills stored in your repository are available in cloud tasks, but personal skills from your laptop are not synced. Put the project rules Codex needs in the repository's AGENTS.md, because that file travels with every checkout.
Give the environment network access and secrets
Turn on Allow Codex to access internet in the environment configuration. Under Allow domains, choose the Package managers preset or Custom domains only, then add hosts under Additional allowed domains. The preset covers registries such as npm, PyPI, crates.io, the Go proxy, Maven, and GitHub downloads. All (unrestricted) exists, but start narrow and add hosts when setup fails.
Credentials go in one of two places:
| Value | Configure it as | What the program receives |
|---|---|---|
A setting a program reads directly, such as APP_MODE |
Environment variable | The value itself |
| A token sent to one HTTPS service, such as a private registry | Network secret | A placeholder that the proxy swaps for the real value |
Network secrets work for HTTPS on port 443 and keep the raw credential out of local processes and files. If a tool must read the raw value, it has to be an environment variable instead. The Personal vault under Settings > Codex Cloud lets a shared environment request a key that each person fills from their own account.
Private services need extra setup. Tailscale is currently the only supported VPN provider, over IPv4, without private DNS or SSH. OIDC for short-lived cloud credentials is available by request for Enterprise workspaces.
Start and follow a cloud task
Select the published environment, describe the goal, and send it. Codex edits files, runs commands, and checks its work in the task's own workspace. Reopen the same task on another device to continue it, while a new task starts fresh from the published setup. On mobile, open Codex and choose an available environment that you created on the web or desktop first.
From the terminal, the CLI reference documents these commands, with codex cloud marked experimental:
# Open the interactive picker for cloud chats
codex cloud
# Submit a task to one environment; --attempts runs best-of-N (1-4)
codex cloud exec --env ENV_ID --attempts 2 "Fix the flaky date parser test and explain the root cause"
# List recent cloud chats as JSON for scripts
codex cloud list --env ENV_ID --json --limit 10
# Apply the latest diff from a cloud chat to your local working tree
codex apply TASK_ID
The JSON from codex cloud list includes each task's id, url, status, and summary, so a small script can watch for finished work. codex apply exits non-zero when git apply fails, so a script can stop on conflicts. Review the diff and test results before you commit or open a pull request, because saved task state does not replace source control.
When the project changes, open Settings > Codex Cloud > Environments and choose Edit from the environment's menu. Let Codex prepare and test the change, then select Republish. Existing tasks keep their own state, and only new tasks see the update.
Codex local vs cloud: where should this task run?
Codex in the cloud now covers three places the work can run. Choose by where the code and tools need to be.
| Mode | Where the work runs | Choose it when |
|---|---|---|
| Local (CLI, IDE, desktop app) | Your machine | You need local tools, a running dev server, or a repository outside GitHub |
| Remote from your phone | Your connected Mac or Windows PC | You want to approve and steer local work away from your desk, with the host awake |
| Codex Cloud | One OpenAI-hosted VM per task | Work should continue while your laptop sleeps, or several tasks share one setup |
The current cloud limits send some work back to local: computer and browser use are not supported, and neither are GitLab or self-hosted GitHub Enterprise Server. In a desktop chat, /cloud, /cloud-environment, and /local switch where the chat runs.
A good first workflow is small. Publish one environment for your busiest repository, send a bug fix as a cloud task, and pull the result down with codex apply to run your usual checks. If that loop works, move longer investigations to the cloud and keep interactive debugging local. Our Delegate, Review, Own methodology shows how to scope cloud tasks so the resulting diff stays easy to review.
Pick one repository today, publish its environment, and send one small task before you move anything larger.