dexgate Codex Adapter One-Pager
The Codex adapter starts with a useful free local hard gate (available free) and upgrades to a customer-hosted Dexgate policy runtime for paid pilot Passport governance—not a generally available production guarantee.
Free baseline (default allowlist)
- Allows read-only shell commands from a conservative allowlist
- Blocks
apply_patch, broad interpreters, chaining, redirection, and mutating commands by default - Blocks high-consequence mutation (for example
git commit/git push) - No Passport; free path does not mint Action Passports
Paid pilot claim boundary
- Live Dexgate policy runtime path for destructive-action governance on validated builds
- Readonly actions may report a governance gap when Codex lacks a pre-execution hook—that is a host boundary
- Current status is defined only in the Compatibility Matrix (AVAILABLE / PILOT / ROADMAP)—not a general production SLA
- Supporting Linux validation may back a declared matrix row without claiming broader production coverage