Claude Code vs Codex

Comparison

Claude Code and Codex are the first-party AI coding agents of the two largest model labs. Claude Code is Anthropic's agent, running Claude models from a terminal CLI, IDE extensions, a desktop app and the web. Codex is OpenAI's agent, running GPT models from an open-source CLI, an IDE extension, the ChatGPT desktop and mobile apps, and Codex Cloud. Each is bundled into its maker's consumer subscription, and each is the reference implementation of how that lab thinks agents should work.

They are more alike than different: both read a repository, plan, edit files, run commands, open pull requests and run tasks in the cloud. The differences that matter are the safety model (permission prompts and a classifier versus an operating-system sandbox), how readily each reaches for the web, the model line-up, and what a subscription includes. JetBrains' survey for May to July 2026 found 39% of professional developers using Claude Code at work and 16% using Codex. Details below were checked on both vendors' pages in October 2026.

Feature Comparison

DimensionClaude CodeCodex
MakerAnthropicOpenAI
SurfacesTerminal CLI, VS Code extension, JetBrains plugin, desktop app, web (claude.ai/code), Claude mobile app, SlackCodex CLI, IDE extension (VS Code, Cursor, Windsurf), ChatGPT desktop app, web, mobile app, Codex Cloud, GitHub mentions and Slack
ModelsClaude models only: Opus 5.5 (default on Pro, Max, Team, Enterprise and API), Sonnet 5.5, Haiku and Fable; also served through Amazon Bedrock, Google Cloud and Microsoft FoundryOpenAI models: GPT-6.1 Sol (recommended), GPT-6 Astra and GPT-6 Luna; GPT-5.5 retires October 14, 2026; custom providers through a compatible Responses API endpoint
CLI sourcePublic GitHub repository (149.6k stars on October 6, 2026); an open-source licence is not publicly documentedApache-2.0 on GitHub (128k stars on October 6, 2026)
Local safety modelPermission modes: Manual (asks before edits, commands and network access), acceptEdits, plan, and auto mode, where a classifier model reviews actionsOS-level sandbox: read-only, workspace-write (default) or danger-full-access, enforced with Seatbelt on macOS and bubblewrap on Linux; network restricted by default
Web accessBuilt-in WebSearch and WebFetch tools, both permission-gatedCached web search from an OpenAI-maintained index is on by default for local work; live search is optional
Cloud executionCloud sessions on isolated Anthropic-managed VMs for Pro, Max, Team and eligible Enterprise seats; no separate compute charge; scheduled and event-triggered routinesCodex Cloud runs each task in its own container with restricted network access by default; started from ChatGPT web, desktop or mobile, the CLI, GitHub or Slack
Project instructionsCLAUDE.md, with AGENTS.md also read; auto memory across sessionsAGENTS.md
ExtensibilityMCP servers, skills, hooks, subagents, plugins and the Agent SDKMCP servers, skills, plugins, subagents and scheduled tasks
Pricing (as of October 2026)Included in Claude Pro at $20/month ($17 billed annually) and Max from $100/month (5x or 20x usage); Team seats $25 standard or $125 premium per month; Enterprise $20 per seat plus usage at API ratesChatGPT Free and Go ($8/month) list limited Codex access; Plus $20/month; Pro from $100/month ($100, $200 or $500); Business $20 per user per month billed annually; Enterprise custom; or API-key usage
Adoption at work (JetBrains, May to July 2026)39% of professional developers16% of professional developers
Web search when choosing tools (Armature, September 2026)Searched the web in about 30% of sessions, but browsed three times as many pages as Codex when it didUsed web search in 94% of sessions

Detailed Analysis

Two Safety Models

The clearest architectural difference is how each agent is kept inside its bounds on a developer's machine. Codex relies on an operating-system sandbox. Its default mode, workspace-write, lets the agent read and edit files in the project and run routine commands, and requires approval to go further. The sandbox is enforced by platform mechanisms (Seatbelt on macOS, bubblewrap on Linux, a native sandbox on Windows), and network access is restricted unless granted. A read-only mode and an unrestricted mode sit on either side.

Claude Code relies on permission modes. In Manual mode it stops and asks before most actions that edit files, run shell commands or reach the network. Other modes relax that: acceptEdits approves file changes, plan mode explores without editing, and auto mode hands the approve-or-deny decision to a second model, a classifier, that reviews each action. Anthropic's documentation says auto mode is now the starting mode for interactive terminal and VS Code sessions on current versions. One approach draws a hard boundary and lets the agent move freely inside it; the other evaluates actions one by one. Security teams tend to have a preference, and it is worth asking them before standardising.

Web Search and Tool Choice

The two agents differ sharply in how often they consult the web. Armature, a vendor, analysed 5,292 valid agent sessions in which Claude Code, Codex and Cursor were asked to pick tools such as databases, payment providers and email services across 75 repositories. Codex used web search in 94% of sessions. Claude Code searched in roughly 30%, although when it did, it browsed about three times as many pages as Codex. The three agents chose the same tool only 42% of the time.

The product defaults are consistent with that gap. Codex enables cached web search by default for local work, drawing on an OpenAI-maintained index instead of fetching arbitrary pages live, which OpenAI says reduces prompt injection risk. Claude Code's WebSearch and WebFetch tools require permission. The practical consequence for developers is that Codex's recommendations are more likely to reflect recently published information, while Claude Code's are more likely to reflect what the model learned in training unless it is told to look. For companies that build developer tools, it means the two agents are reached through different channels. The study is a vendor report and does not state which model versions were used, so the exact percentages should be treated as a snapshot.

Models and Openness

Each agent is tied to its maker's models by default. Claude Code uses Opus 5.5 as the default on paid plans and the API, with Sonnet 5.5, Haiku and Fable models selectable, and enterprises can route them through Amazon Bedrock, Google Cloud or Microsoft Foundry. Codex recommends GPT-6.1 Sol, which OpenAI describes as offering "near-Astra performance for complex work at a lower cost", with Astra for the hardest work and GPT-6 Luna for lighter tasks.

Codex is the more open of the two as software. The CLI is published under the Apache-2.0 licence, and its documentation describes configuring custom model providers through any compatible Responses API endpoint. Claude Code's repository is public and widely starred, but an open-source licence for the agent is not publicly documented, and the product runs Claude models only. Teams that want to audit, fork or re-point the harness will find more room in Codex. Teams that want the agent their model vendor tunes most closely get that from either.

Cloud Tasks and Surfaces

Both run long tasks in the cloud. Codex Cloud gives each task its own container with restricted network access by default, and tasks can be started from ChatGPT on the web, desktop or mobile, from the CLI, by mentioning @codex on GitHub, or from Slack. Claude Code's cloud sessions run on isolated Anthropic-managed virtual machines with limited network access by default, start from the browser, mobile app, desktop app or terminal, and can be pulled back into a local terminal session. Anthropic also offers routines for scheduled and event-triggered runs, and Codex lists scheduled tasks. Functionally these are close. Codex's advantage is that it lives inside ChatGPT, which many organisations already license. Claude Code's is session mobility between local and cloud.

Pricing and Adoption

Both are bundled with a $20 subscription. ChatGPT Plus includes Codex with published estimates of 15 to 160 local messages per five hours on GPT-6.1 Sol and 350 to 3,000 on GPT-6 Luna; Pro starts at $100 with $200 and $500 options, and Business is $20 per user per month billed annually. OpenAI also lists limited Codex access on its Free and $8 Go plans. Claude Pro at $20 includes Claude Code, Max starts at $100 with five or twenty times Pro's usage, and Team seats are $25 or $125. Anthropic does not publish message-count estimates on its pricing page.

On usage, JetBrains' survey of more than 15,000 professional developers (May to July 2026) put Claude Code at 39% and Codex at 16%, with GitHub Copilot at 21% and Cursor at 12%. Shares overlap because many developers use several agents.

Best For

Hard OS-level sandbox on developer machines

Codex

Codex confines the agent with Seatbelt or bubblewrap and restricts network access by default, a boundary that does not depend on per-action judgement.

Fine-grained approval and policy hooks

Claude Code

Claude Code's permission modes, hooks and managed settings let teams decide action by action what runs, and enforce it centrally.

Choosing libraries and services that changed recently

Codex

Codex searched the web in 94% of sessions in Armature's study, so its picks more often reflect current documentation.

Auditing or forking the agent itself

Codex

The Codex CLI is Apache-2.0 and supports custom model providers through a compatible Responses API endpoint.

Moving a task between laptop, cloud and phone

Claude Code

Claude Code sessions can start in the cloud, be steered from mobile and be teleported back into a local terminal.

Organisation already licensed for ChatGPT

Codex

Codex is included in ChatGPT Plus, Pro, Business and Enterprise plans, so there is no second vendor to procure.

Organisation buying models through AWS, Google Cloud or Azure

Claude Code

Claude Code can run against Claude models on Amazon Bedrock, Google Cloud or Microsoft Foundry with cloud-native billing.

Everyday feature work and bug fixing

Depends

Both plan, edit, test and open pull requests competently. Model preference and existing subscriptions usually decide.

The Bottom Line

Claude Code and Codex are close competitors with similar reach. Claude Code has the larger share of professional developers in the most recent JetBrains survey, a flexible permission system, and strong session mobility across terminal, cloud and mobile. Codex has an open-source CLI, an operating-system sandbox as its default safety boundary, tight integration with ChatGPT, and a marked tendency to check the web before deciding.

For most teams the choice follows the model relationship they already have. An organisation with ChatGPT Business or Enterprise gets Codex without a new contract, and one with Claude Team or Enterprise gets Claude Code the same way. Where both are available, the meaningful questions are whether the security team prefers a sandbox or reviewed permissions, and whether the work benefits from an agent that searches by default.

Because both read AGENTS.md and both speak the Model Context Protocol, repository instructions and tool integrations carry over. That keeps switching costs low, and it is why many developers in the JetBrains data use more than one agent.