Codex adapter

Start with a conservative free local hard gate for Codex: read-only shell commands from a conservative allowlist; patch application, interpreters, chaining, redirection, and mutating commands are blocked by default. Upgrade to a paid path when you need governance through the Dexgate runtime for destructive actions, traces, and Passport-shaped evidence through the hosted runner / native approval-callback path.

Available free · controlled host coverage

Current availability

Free adapters: available now on npm

Paid governed workflows: early-access pilot

Coverage last validated: July 30, 2026

Validated free packages: @dexgate/openclaw-trusted-mode@1.0.18, @dexgate/codex-trusted-mode@0.1.16

See the compatibility matrix for coverage, limitations, and current versions.

Narrower host coverage than the OpenClaw free path. dexgate does not provide the Codex application. Readonly governance-gap results are a real host boundary when Codex does not expose a pre-execution readonly approval hook. Plain interactive codex (including Full Access / user-approved shell) is not the paid enforcement path—validate with codex-trusted-mode-run-turn, not a normal TUI session alone.

Free standalone posture (default allowlist)

Paid pilot / hosted runner

Get Started View Codex Resources

View Codex Release Trail