explainx.ai0k
TrendingAI News TodayPathwaysSkills
Pricing
explainx.ai

Upskill in AI — 16 free pathways, live workshops & bootcamps, and 50+ courses from practitioners. Plus the skills, tools, and MCP servers to practice on.

follow us

follow on google

Add explainx.ai as a preferred source

corporate training

support@explainx.ai

get started

Find your pathTake Free Evaluation

community

Join the community

learn

mind: share how you thinkpathways — start freeworkshopsbootcampscoursescompare Explainxcertificationsmock testsexplainx universitycorporate traininglearn skills & mcp

discover

skillsmcp serversexplainx mcptoolsmdx readeragentsllmsdesignsdictionarypeopleagi trackerfelony benchranks

company

aboutvisionmissionteaminstructorsteach on explainxpartnershipscommunityhackathonscareers

content

daily AI newsstate of AI — live resultsblogreleasespromptsgeneratorsresource libraryfor LLMsexplainx.ai kids

solutions

all solutionsdeveloper upskillingmarketing upskillingproduct manager upskillingleadership upskilling

newsletter · weekly

Get AI news, tools, and insights in your inbox.

supportcontactprivacytermsdata rightshow we create contentsubmission guidelines

© 2026 AISOLO Technologies Pvt Ltd

explainx.ai

On this page

  • TL;DR — what still changes what you ship?
  • Codex Security Cloud: scan GitHub, then leave the laptop shut
  • Agents API computer use: the beta can drive a UI
  • Bedrock Managed Agents: name AWS, then read two docs
  • Codex in the cloud, voice CLI, /agents, desktop Code Review
  • What you should do this week (and what you should not)
  • Related reading
← Back to blog

explainx / blog

Codex Security Cloud and Agents API Computer Use

OpenAI, Codex, Agents API, Cybersecurity, AWS, DevDay

DevDay leftovers: Codex Security Cloud, Agents API computer use, AWS Bedrock Managed Agents, and Codex in the cloud — what builders ship this week.

Sep 30, 2026·12 min read·Yash Thakker
add explainx.ai
go deep
Codex Security Cloud and Agents API Computer Use

The OpenAI DevDay 2026 hub already covers the keynote noise: Dots, GPT-6.1 Sol, and Ultrafast plus Pro 500. Those posts stay the source of truth for always-on agents, the $2 / $10 Sol card, and the 300 tok/s speed SKU. This page is the leftover pile — the four ships that still change what you wire, scan, or run overnight this week.

Primary source: OpenAI's DevDay 2026 recap. We did not invent prices. If a number is missing from that recap, it stays missing here.

Update — September 30, 2026: Selling Codex Security Cloud / Daybreak-in-product is one incentive TechCrunch cites for OpenAI skipping NVIDIA's public Open Agent Safety pledge — why that absence is not an OpenShell boycott.

Weekly digest3.5k readers

Catch up on AI

Curated AI updates on agents, skills, and MCP — delivered to your inbox. Unsubscribe anytime.

TL;DR — what still changes what you ship?

table · 2 cols
QuestionDirect answer
Why not just read the hub?The hub indexes 20+ launches. This post is the builder checklist for security scans, computer use, AWS residency, and Codex cloud.
What is Codex Security Cloud?Scan connected GitHub repos on demand or a schedule, watch new commits, investigate, dedupe, prepare fixes in the cloud — laptop closed is the point.
Daybreak application?No separate app for Daybreak Blue models inside Security Cloud. Daybreak still explains the program; Red vs Blue is the August gate.
Agents API computer use?Yes. Agents can operate software via an OpenAI-hosted browser. Same capability class as the September 10 Agents API public beta, plus UI control.
Where is computer use listed besides the API?Codex and ChatGPT Work on Pro 500 and Enterprise.
What is Bedrock Managed Agents?AWS plus OpenAI: Codex-style harness, inference on Bedrock, data described as staying inside AWS. Name AWS in procurement; confirm on Amazon's page.
Codex "in the cloud"?Reusable environments (repos, deps, tools, access). Run on a machine, from a phone, or remotely. Voice CLI, /agents, desktop Code Review.
Dots / Sol / Ultrafast here?No recap dump. Use the linked posts.
Pricing for Security Cloud or Bedrock?Not published in the recap we used. Do not budget a made-up rate.

Codex Security Cloud: scan GitHub, then leave the laptop shut

Abstract neon-green defensive geometry on charcoal, reused from explainx.ai Daybreak-era cyber coverage

OpenAI's recap and launch-week write-ups describe Codex Security Cloud as a cloud job, not a local grep wrapper. You connect GitHub repositories. You trigger a scan on demand or put it on a schedule. New commits get another pass. Codex investigates what it finds, drops duplicates, and prepares fixes in the cloud while you are offline.

That last clause is the product. The July Codex Security CLI and TypeScript SDK already covered local and CI scans (@openai/codex-security). Security Cloud is the hosted cousin: investigation and draft remediations keep running after you close the lid. The Decoder's DevDay note matches OpenAI's framing — scan, investigate, filter duplicates, prepare fixes automatically.

Daybreak Blue without a Daybreak application

May's Daybreak / Codex Security launch was a program: threat models, Trusted Access, later GPT-5.5-Cyber. August split that into Daybreak Blue (everyday defensive work) and Daybreak Red (authorized, more permissive exploit research) with GPT-5.6-Cyber — see the Red/Blue post.

DevDay's leftover is distribution, not a new creature name. OpenAI says Security Cloud includes models offered through Daybreak Blue and does not require a separate Daybreak application. If your team stalled on "we never filled out Daybreak," this is the sentence that unblocks a GitHub-connected trial. It does not mean Daybreak Red or GPT-5.6-Cyber is now a checkbox on a personal Pro seat. Red stays the gated track.

What people are asking

Is this just Dependabot with a marketing name? No. Dependabot-class tools alert on known advisories. OpenAI's copy is investigate + dedupe + prepare a fix in a Codex cloud environment. Treat first-week output like a junior security engineer: useful drafts, not merge-without-reading. Prompt injection and poisoned findings still apply once an agent writes into a repo.

Does it replace the open-source CLI? Use both. CLI/SDK for CI you own and air-gapped runners. Security Cloud for scheduled org-wide GitHub coverage and overnight triage. explainx.ai's July CLI post is still the local/CI reference.

Will it burn Codex quota like a 40-step coding loop? OpenAI did not publish a Security Cloud token or seat price in the recap. Assume it can consume plan or API usage until your admin shows a separate meter. ChatGPT Work vs Codex still matters if Work and Codex share a pool.

Can I point it at GitLab? Launch coverage names connected GitHub repositories. Desktop Code Review is the surface that mentions GitLab merge requests in preview. Do not assume Security Cloud scanners speak GitLab until OpenAI lists it.


Agents API computer use: the beta can drive a UI

On September 10, OpenAI put the Codex harness behind one managed call: sessions, subagents, compaction, sandboxes. That story lives in Agents API public beta. DevDay did not re-announce the beta. It added computer use.

OpenAI's recap-class description: the agent navigates websites and operates applications through an OpenAI-hosted browser. You can follow session events while it looks at the interface and chooses the next action. That is a different contract than MCP tools or a shell in a sandbox. The model is clicking and typing in a real UI.

OpenAI also listed computer use for Codex and ChatGPT Work on Pro 500 and Enterprise. If you are on Plus or a leftover Pro 200 seat, do not assume the same desktop/browser control. The Ultrafast / Pro 500 post is where that top seat is documented; this post only records the computer-use eligibility line from launch materials.

Multi-agent, tool search, compaction

The same Agents API write-up already said OpenAI manages sessions, orchestration, context compaction, and recovery while you supply tools and pick an environment. DevDay leftover language that builders should actually use:

  • Multi-agent — delegate to other agents instead of one giant loop. That is the in-app Codex story as well as the API.
  • Tool search — attach a large tool catalog without stuffing every schema into the first prompt. Exact API field names belong in OpenAI's developer docs, not in a guessed snippet here.
  • Compaction — long computer-use sessions fill context with screenshots and DOM dumps. Compaction is how the session survives; it is also how earlier "do not click Pay" constraints get summarized away. We covered that lossiness when Codex's 1M window started auto-summarizing history.

If you already run Claude background computer use, this is a second-provider fallback, not a new category. Test the same booking or admin UI on both. Do not migrate production click-paths on a keynote slide.

What people are asking

Is Agents API generally available now? The hub called this partial: computer use landed, no confirmed GA label. Treat it as public beta plus a capability. ZDR and non-US residency gaps from the September 10 docs still apply until OpenAI updates them — re-read the beta post before a regulated workload.

Hosted browser vs my VPC? Launch copy says OpenAI-hosted browser for computer use. That is a data-residency question. If pixels of an internal admin UI cannot leave your network, you need a self-hosted or partner sandbox story, not a demo against staging.internal.

Does this replace Dots? No. Dots are always-on ChatGPT agents with their own cloud computer for people. The Agents API is a developer endpoint. Do not staff a Dot farm to avoid learning the API, and do not build an internal Dot clone when you needed a session ID and a webhook.


Bedrock Managed Agents: name AWS, then read two docs

OpenAI and Amazon Web Services position Bedrock Managed Agents as OpenAI agents that run entirely on AWS: customer environment, inference on Bedrock, data described as staying within AWS, with Bedrock AgentCore as the default compute/platform layer. AWS's own product page says each agent can have its own AWS identity and permissions, and that the runtime plus model inference remain inside AWS.

That is the procurement sentence. The builder sentence is shorter: if your security review already approved Bedrock and IAM, you can keep the Codex harness shape without sending every token to api.openai.com. If your review has not approved AWS, this leftover does nothing for you this week.

April limited-preview language showed up in some coverage; DevDay is when OpenAI put the pairing on the same board as the Agents API. We are not restating an AWS price list. Confirm current preview/GA status and commercial terms on Amazon's page and in OpenAI's recap. Official AWS overview: Amazon Bedrock Managed Agents.

What this is not

  • Not a substitute for Dots. Different buyer, different computer.
  • Not "OpenAI is exclusive to Azure." The leftover is explicitly AWS-named.
  • Not a reason to skip OpenAI's Agents API if you are a startup without an AWS estate. Use the API; use Bedrock when residency or existing AWS spend is the constraint.

Codex in the cloud, voice CLI, /agents, desktop Code Review

This is the harness leftover, not the security leftover.

Reusable cloud environments hold a project's repositories, dependencies, tools, and access settings. Each task still gets its own workspace. The pitch is start-fast plus a team-approved image, not a one-off remote sandbox that dies when the chat ends. You can run Codex on your computer, from a phone, or in the cloud. Laptop-asleep work is the same story as Security Cloud, applied to ordinary engineering tasks.

CLI voice lets you start and steer tasks out loud. Treat it as a hands-busy input, not a new model. Background noise plus "yes, push it" is a foot-gun; keep destructive git actions behind a confirm you can see.

/agents is the view for delegated work and multiple tasks. If you already live in Codex slash commands, this is the multi-agent pane, not a replacement for /init or AGENTS.md. Prompt editing, session resume, Git worktrees, and terminal polish were listed alongside it. Worktrees matter: parallel agents on one dirty tree is how you lose an afternoon.

Code Review in ChatGPT desktop pulls PR summaries, changed files, comments, and checks into one surface. You inspect diffs and ask Codex to investigate before you post review text. Automatic cloud reviews can run while you are away. GitHub is generally available; GitLab merge requests are in preview. That is the only GitLab line we will stand behind this week.

Teams that already mix harnesses should keep Codex as a Claude Code plugin in the comparison set. DevDay did not make Claude Code obsolete; it made OpenAI's own desktop closer to an IDE-adjacent review tool.

What people are asking

Is cloud Codex the same as a Dot's computer? Related shape, different product. Dots are ChatGPT-goal agents with a browser and 4,000+ apps. Codex cloud is a dev environment for repos and tools. Do not grant a Dot write access to production because Codex cloud felt similar in a keynote grid.

Can I keep using local Codex only? Yes. Cloud is an option, not a forced migration. Local still wins when secrets cannot leave the machine. Cloud wins when the job is an overnight test suite or a Security Cloud scan.

Will voice + /agents drain quota? OpenAI did not publish a voice surcharge in the recap. Voice is still tokens plus whatever the speech stack costs internally. Watch /status the first week you talk at the CLI all afternoon.


What you should do this week (and what you should not)

  1. Connect one non-critical GitHub repo to Security Cloud on a schedule. Compare its first report to your existing scanner. Measure duplicate rate and false-positive rate, not "number of findings."
  2. Re-run one Agents API smoke test from September 10 with computer use enabled on a disposable site. Confirm you can stream events and abort.
  3. If you are on AWS already, book a 30-minute architecture review for Bedrock Managed Agents vs calling OpenAI directly. Bring IAM, VPC, and log-retention requirements. Do not rewrite the agent loop twice.
  4. Stand up one reusable Codex cloud environment for a single service with pinned deps. Try a phone kickoff and a desktop resume. If secrets handling feels worse than your laptop, stay local.
  5. Turn on desktop Code Review for GitHub on a repo you already review by hand. Keep GitLab in preview until your org accepts "preview" in the audit trail.
  6. Do not re-benchmark Sol, restack Dots, or buy Ultrafast from this post. Those decisions belong on their own explainx.ai pages.

Honest limitations, stated once:

  • No Security Cloud or Bedrock dollar figures in the recap we used.
  • GitHub-first for Security Cloud; GitLab is a Code Review preview, not a scanner promise.
  • Agents API is still beta plus computer use — not a GA stamp.
  • Daybreak Blue-in-product ≠ Daybreak Red.
  • Computer use on Work/Codex is called out for Pro 500 and Enterprise, not every paid seat.

Related reading

  • OpenAI DevDay 2026 — full announcement map
  • OpenAI Agents API public beta
  • OpenAI Daybreak and Codex Security (May 2026)
  • GPT-5.6-Cyber: Daybreak Red and Blue
  • Dots: always-on GPT-6 Astra agents
  • GPT-6.1 Sol pricing and benchmarks
  • Ultrafast and ChatGPT Pro 500
  • Codex Security CLI and SDK (July 2026)

Official: DevDay 2026 Recap · Amazon Bedrock Managed Agents · Agents API overview · ChatGPT pricing

Availability, plan gates, and product names are accurate as of September 30, 2026, checked against OpenAI's DevDay recap and contemporaneous launch coverage. Confirm GitHub/GitLab scope, computer-use eligibility, and any fees on openai.com and AWS before production rollout.

Spotted something out of date? Let us know.
Yash Thakker

Written by

Yash Thakker

Yash is an AI expert with over 300K learners. Join his workshops →

View Yash Thakker in People in AI →

Related posts

Sep 29, 2026

OpenAI DevDay 2026: Every Announcement, Explained for Builders

OpenAI made 20+ announcements at DevDay on September 29, 2026. The headline is Dots, always-on ChatGPT agents with their own cloud computer, but the builder-relevant news is GPT-6.1 Sol pricing, Ultrafast, computer use in the Agents API, and plugin extensions. This is the explainx.ai recap, plus what it changes if you build on Claude.

Sep 12, 2026

OpenAI Agents API Public Beta: Codex Harness Behind One Call

OpenAI opened public beta access to the Agents API on September 10, 2026, putting the same session management, subagent orchestration, and sandbox infrastructure behind Codex and ChatGPT into a general-purpose endpoint. Nine hosting partners, no separate fee, and a security backdrop from the same week's Aardvark disclosure make this more than a routine API launch.

Sep 10, 2026

OpenAI Defense Factory: Agent-First Cyber Defense at Scale

On September 10, 2026, OpenAI published The Defense Factory — its answer to long-running agents chaining exploits with open-weight models. The post documents a 250-person security sprint across 100+ service areas, a control plane plus data plane architecture, Codex Security CLI skills, and hard numbers on ownership routing, deduplication, runtime validation, and fix rollback rates.