Codex Security Cloud pricing 2026: plans, credits, and what a scan costs

Kurnia Kharisma
Written by

Kurnia Kharisma

Katelin Teen
Reviewed by

Katelin Teen

Last edited October 1, 2026

Expert Verified
Hand-drawn illustration of a developer on a laptop and a colleague looking at a dashboard with a code repository, a security shield, a usage meter and a stack of credit coins

What does Codex Security Cloud cost?

Most people who search "Codex Security Cloud pricing" are after one number, and I went looking for it too. OpenAI doesn't publish one. The Codex pricing page has no Codex Security row, and the Cloud FAQ doesn't mention cost at all. The only availability statement is in the DevDay 2026 recap: "Available to all Pro, Business, Enterprise and Edu users on desktop and web."

So the honest answer, as far as I can tell, is that Codex Security Cloud costs whatever its tokens cost on your plan. It runs in Codex cloud, and the pricing page says plainly that "ChatGPT Work and Codex share usage." Your scans compete for the same allowance with your coding tasks and your ChatGPT Work jobs, and also with the Excel add-in.

Codex Security Cloud findings dashboard with tabs for Overview, Findings, Repositories, Scans and Configure, a pipeline from Discovered to Done, and a Needs attention table with Fix buttons, as taken from OpenAI's DevDay recap
Codex Security Cloud findings dashboard with tabs for Overview, Findings, Repositories, Scans and Configure, a pipeline from Discovered to Done, and a Needs attention table with Fix buttons, as taken from OpenAI's DevDay recap

I write about AI pricing for eesel, and I've read enough eesel sales-call notes to know why this matters. On one eesel call this year, a buyer said they'd watched a previous vendor's price more than double, and the first thing they asked for was a price lock. A usage meter that has no published per-job price is pretty much the opposite of that, which is fine for a pilot but harder to put in a budget.

Which plans include Codex Security Cloud?

This is the part where it gets messy, because two OpenAI pages disagree with each other. The DevDay recap names four plan families. The feature matrix at the bottom of the Codex pricing page lists "Codex Security for connected GitHub repositories" as available on Enterprise only, and unavailable on Plus, Pro, Business and API key.

Hand-drawn table comparing what the DevDay recap says against what the pricing matrix says: Plus no and no, Pro yes and no, Business yes and no, Enterprise and Edu yes and yes, with question marks beside Pro and Business
Hand-drawn table comparing what the DevDay recap says against what the pricing matrix says: Plus no and no, Pro yes and no, Business yes and no, Enterprise and Edu yes and yes, with question marks beside Pro and Business

My read on it is that the matrix just hasn't caught up with the launch yet, since the recap is the newer page. The Codex Security docs hedge too: "If access is unavailable, check with your workspace administrator." I wouldn't upgrade a plan only for this until you've actually seen the plugin in your own workspace.

Here are the plans, with the base price you pay before any scanning happens:

PlanPriceCloud access per DevDayPricing matrixAfter the included allowance
Free$0/monthNoNoLimited credit pilot
Go$8/monthNoNoLimited credit pilot
Plus$20/monthNoNoPersonal credits
Pro$100, $200 or $500/monthYesNoPersonal credits
Business standard seat$20/user/month annual, $25 monthlyYesNoWorkspace credit pool
Business premium seat$100/user/month annual, $125 monthlyYesNoWorkspace credit pool
Enterprise and EduContact salesYesYesContract credit pool
API keyAPI ratesNo cloud featuresNoBilled per token

Prices come from the Codex pricing page and OpenAI's business pricing. Business needs at least 2 seats. Pro has no five-hour limit, though weekly limits can still apply, and that matters if you plan on leaving commit monitoring running.

How are Codex Security Cloud credits calculated?

Once the included usage runs out, every scan gets billed on tokens. The ChatGPT rate card gives the formula: input tokens times the input rate, plus cached input times the cached rate, plus output times the output rate, each per million.

The model that matters here is Daybreak Blue. Cloud "includes access to models offered through Daybreak Blue without a separate Daybreak application," per the DevDay recap. That access is OpenAI's fix for the refusals that CLI users ran into in July, and the rate card prices it at GPT-5.6 Sol rates. Here's the slice of the rate card that applies to security work:

ModelInput (credits per 1M)Cached inputOutput
Daybreak Blue (GPT-5.6 Sol rates)10010500
Daybreak Red312.531.251,875
GPT-6.1 Sol502.5250
GPT-6 Sol505250
GPT-6 Luna2.50.2512.5

Three details from the same pages change the math. Codex doesn't charge for cache writes. Fast mode costs 2x the credit rate, and it burns the included allowance at 2.5x. Then the pricing page also notes "GPT-5.6 Sol's promotional pricing is available at least through November 21, 2026," for usage paid with purchased credits. OpenAI doesn't say what the rate turns into after that, so I'd treat the Blue rate as a number that can still move.

Daybreak Red is a separate track altogether. It needs Trusted Access for Cyber approval on top of Blue, and Blue approval "doesn't grant access to Daybreak Red." Most teams that scan their own code won't ever touch it. My GPT-5.6 Cyber piece covers the cyber model tiers.

What does one real scan cost in credits?

OpenAI won't tell you this, so I measured one myself. For my Codex Security Cloud review, I ran the open-source Codex Security CLI on a 56-line Flask app with 5 planted bugs. It found all 5. The scan took 8 minutes 56 seconds and logged these tokens:

  • 18,684 fresh input tokens
  • 173,804 cache writes
  • 3,357,854 cache reads
  • 73,204 output tokens

Since Codex doesn't bill cache writes separately, I counted them as input. Running those numbers through the rate card gives this:

Rate appliedInputCached inputOutputTotal
Daybreak Blue19.2 credits33.6 credits36.6 credits89 credits
GPT-6 Sol9.6 credits16.8 credits18.3 credits45 credits
GPT-6.1 Sol9.6 credits8.4 credits18.3 credits36 credits
Hand-drawn bar chart of the same 3.6M-token scan in credits: Daybreak Blue at GPT-5.6 Sol rates 89 credits circled, GPT-6 Sol rates 45 credits, GPT-6.1 Sol rates 36 credits, with a note that a typical Codex task is 2 to 15 credits
Hand-drawn bar chart of the same 3.6M-token scan in credits: Daybreak Blue at GPT-5.6 Sol rates 89 credits circled, GPT-6 Sol rates 45 credits, GPT-6.1 Sol rates 36 credits, with a note that a typical Codex task is 2 to 15 credits

For a sense of scale, the rate card says "a typical Codex task using GPT-6.1 Sol may consume between 2 and 15 credits," and the pricing page puts a typical GPT-5.6 Sol task at 5 to 30. One scan of a toy app cost about as much as 6 to 45 ordinary Codex tasks.

And what about dollars? OpenAI doesn't publish a per-credit price for personal or Business plans, so the closest yardstick I've found is a Pro subscriber's grant email, posted on Hacker News, describing "62,500 usage credits (a $2,500 USD value)." That works out to $0.04 per credit, or about $3.58 for my scan. That is roughly in line with the CLI's own estimate on the API route, which was $3.75 to $6.77.

There are two caveats on my number. It's a tiny repo, and a real codebase will use more tokens, though 93% of mine were cache reads from the agent re-reading its own context, which is mostly fixed overhead. And the Cloud plugin may not run exactly the same steps as the CLI. Treat 89 credits as a floor-ish reference point, not a quote.

What does it cost for a whole team?

Here's the worked example I would use for a budget. A 10-person team on ChatGPT Business, billed annually, pays $200 a month for seats. Suppose they run one full scan a week on each of 5 repos, about 20 scans a month. If each scan cost what mine did, that's roughly 1,780 credits, or about $71 at the $0.04 yardstick, once the included allowance is gone. Bigger repos push that number up, and commit monitoring does as well.

To compare, OpenAI's rate card says "Codex costs approximately $100–$200 per developer per month" on average, before anyone turns on security scans. The GitHub Code Security add-on is a flat $30 per active committer, so $300 a month for the same 10 people, with no meter.

You can plug in your own numbers below. The default credits per scan is the 89 I measured, and switching the rate shows you what happens if Cloud moves to a GPT-6 model.

If the numbers look high, the lever to pull isn't the plan, it's how often you scan. A weekly full scan plus commit monitoring on your 2 or 3 riskiest repos covers most of the value for a fraction of the credits.

Where do the hidden costs come from?

The rate card is the easy part of this. The money you don't plan for tends to come from scans that bill you and return nothing.

Hand-drawn leaky bucket labelled your credit pool with four drips: refused scans still bill, failed setup still bills, max-cost is only an estimate, and commit monitoring repeats work
Hand-drawn leaky bucket labelled your credit pool with four drips: refused scans still bill, failed setup still bills, max-cost is only an estimate, and commit monitoring repeats work
  1. Refused scans still bill. Before Daybreak Blue came bundled in, CLI users ran long scans that ended in a cyber-risk refusal, and they paid for the whole run anyway.
Hacker News

"it ran for over 40 minutes and during that time I had no idea what was happening, thought it was frozen or in a bad state. Also, it ate through 25% of my weekly credits :("

  1. Failed setup still bills. My own first run quit in preflight and left an empty output folder, after using about $0.74 to $1.40 of tokens. Another user reported a rate-limit failure that "cost me ~$13," and an OpenAI team member replied in the same thread that retries and resume weren't built yet.
Hacker News

"it started a scan but stopped after hitting the rate-limit of my account. It gave up after just a minute of retrying"

  1. The cost cap isn't a cap. The CLI's --max-cost flag is, per OpenAI's CLI FAQ, "an estimate, not a hard spending cap." I set $4, and my final high estimate still came out at $6.77.
  2. Commit monitoring repeats work. The Commit changes mode reviews new commits and can reach back into existing history, per the setup docs. Every push takes another bite out of the allowance. You can pause it per repo in Monitoring settings.
  3. Cloud tasks cost more than local ones. The pricing page warns that "Cloud tasks may use more of your allowance than local messages," and the scanner runs entirely in the cloud.

The Blue bundle should cut down the first problem, but nobody has posted a hands-on Cloud bill yet, so I can't confirm that from real use. The Hacker News launch thread had zero comments when I checked.

How do credits work on each plan?

How you top up depends on which side of the ChatGPT house you're on.

Plus and Pro. When you hit a limit, you can buy personal credits from Settings, with optional automatic reload and a monthly maximum. Per OpenAI's credits article, credits are "valid for 12 months from purchase," non-refundable outside billing errors, and "not API credits." Prices "can vary by account, region, and plan."

Business. Credits are optional and pooled across the workspace, bought under Settings > Billing, valid for 12 months. Per OpenAI's flexible pricing FAQ, if the pool is empty "the feature is blocked." For a cost-conscious team, that's a nice default to have. Set Usage Alerts before you connect a repo.

Enterprise and Edu. One shared pool per contract with no per-seat caps by default. Admins can set overage limits, but even a limit of 0 "does not guarantee that your credit balance stays at or above zero," since in-progress requests finish. Long scans are exactly the kind of request this applies to.

The Codex Security Cloud setup flow runs from installing the plugin to choosing between a one-off Repository scan and Commit changes monitoring. That choice is the biggest cost lever you have:

Scrolling capture of OpenAI's Codex Security Cloud setup documentation, from installing the plugin through monitoring new commits

Can you use an API key instead?

Not for Cloud. The pricing page says API-key accounts get "No cloud-based features (GitHub code review, Slack, etc.)." What you can do is run the open-source CLI in CI with an OpenAI API key and pay API rates per token. That's the route I tested, and it's also the only one that has a real dollar figure: $3.75 to $6.77 for my tiny app.

There's a catch, though. An open GitHub issue, #1024, reports that the Daybreak Blue selection gets dropped under API-key auth. So the CI route may scan with standard guardrails, which is what produced the refusals above. If refusals are what worries you, Cloud with a ChatGPT sign-in is the safer bet. My OpenAI Codex integration with GitHub guide covers the other GitHub hooks.

There's also a cheaper path on the way. A recent commit on the codex-security repo switches the CLI default to GPT-6 Sol. At GPT-6 Sol rates, my scan would have been 45 credits instead of 89. OpenAI hasn't said whether Cloud will follow.

Are there free or discounted options?

There are a few, and they're narrower than the headlines make them sound.

  • The free preview month is over. The March 2026 research preview came "with free usage for the next month." That window closed a long time ago.
  • Daybreak credits for defenders. OpenAI's Daybreak page promises "$1 billion in Daybreak credits for defenders," aimed at state and local governments, critical-infrastructure operators, community banks, nonprofits and open-source maintainers. You do have to apply for them.
  • Codex for OSS. The research preview post says open-source maintainers can get free ChatGPT Pro and Plus accounts plus Codex Security through Codex for OSS. Access isn't instant, though. One vim maintainer said on Hacker News they had "applied twice already never heard anything back."

Is Codex Security Cloud worth the price?

For a team already paying for ChatGPT Business, Pro or Enterprise, a pilot costs you almost nothing extra. The scanner itself is good: in my test it found every planted bug and explained each one well. The price problem isn't the size of the bill, it's that you can't see it in advance.

Here's how it stacks up next to the per-seat tools most teams already know:

ToolPriceBilling unitBest for
Codex Security CloudIncluded plan usage, then creditsTokens (about 89 credits for my test scan)Deep, validated findings on a few key repos
GitHub Code Security$30 per active committer/monthSeatA deterministic floor on every PR
SnykFree; Team from $25/monthPlan, up to 10 developers on TeamDependency and open-source risk
SemgrepFree to 10 contributors; Code from $30/contributor/monthSeatCustom rules you write yourself

OpenAI's own FAQ answers the "replace or add" question: "Codex Security complements SAST." So I would budget for Codex Security on top of a seat-priced tool, not instead of one. If you're also comparing coding agents, my OpenAI Codex alternatives and Claude Code pricing posts cover the same metering question from the other side. Claude Mythos is the closest rival for security research.

My verdict: worth a pilot, not yet worth a budget line. I'd revisit it after November 21, when the GPT-5.6 Sol promotion window ends and the first real Cloud bills start showing up.

Want AI with a price you know in advance?

eesel doesn't scan code. It's a platform of AI teammates you hire for specific jobs, starting with an AI helpdesk teammate that works your support queue and an AI blog writer. The pricing works as the opposite of a token meter. One ticket or chat is one credit, with a free plan of 100 credits and paid plans from $299 a month for 500, all on the pricing page.

eesel Reports view for a Zendesk teammate showing task volume, trigger events by type, and approval usage per tool
eesel Reports view for a Zendesk teammate showing task volume, trigger events by type, and approval usage per tool

Before it answers a customer, the helpdesk teammate runs against your past tickets, so you get to see what it would say and what that would cost. If you'd rather drive it from a terminal, the eesel CLI lets you run the same teammate yourself, or hand it to a script or a coding agent like Claude Code. Try eesel on a week of real tickets.

Frequently Asked Questions

How much does Codex Security Cloud cost?
There's no separate price. Codex Security Cloud uses the Codex usage included in your ChatGPT plan, then credits, and its Daybreak Blue model bills at GPT-5.6 Sol rates of 100, 10 and 500 credits per million input, cached and output tokens. The same token count as my test scan works out to about 89 credits. My Codex pricing guide covers the wider credit system.
Is Codex Security Cloud free?
Not really. There's no fee to install the plugin, but every scan draws from paid plan usage, and it isn't offered on the Free, Go or Plus plans. The March 2026 research preview had a free first month, but that offer has ended. Open-source maintainers can apply for OpenAI's subsidized programs, and the Codex Security Cloud overview lists them.
Which ChatGPT plan do I need for Codex Security Cloud?
OpenAI's DevDay recap says Pro, Business, Enterprise and Edu. Its own pricing matrix still lists GitHub repository scanning as Enterprise and Edu only. Check that the plugin shows up in your workspace before you buy a plan for it. My ChatGPT pricing breakdown has every plan's cost.
What is the Daybreak Blue credit rate in Codex Security Cloud pricing?
Daybreak Blue uses GPT-5.6 Sol credit rates, which are 100 credits per million input tokens, 10 per million cached input and 500 per million output. That's twice the rate of GPT-6 Sol. Daybreak Red costs more, at 312.5, 31.25 and 1,875, and needs separate approval.
How much does a Codex Security scan cost with an API key?
My CLI scan of a 60-line app with an API key used 3.6 million tokens and the tool estimated $3.75 to $6.77. API-key accounts get no cloud features, so that route means the open-source CLI, not Cloud. My Codex Security Cloud review walks through the full test.
Do failed Codex Security scans still use credits?
Yes. Tokens are billed as they're used, so a scan that fails in setup or ends in a cyber refusal still costs money. My first run failed after using about $0.74 to $1.40, and Hacker News users reported failed runs costing $13 and more. The OpenAI rate limits guide explains how usage windows work.
Is Codex Security Cloud cheaper than GitHub Code Security?
It depends on how often you scan. GitHub Code Security is a flat $30 per active committer per month, while Codex Security Cloud bills by tokens, so frequent full scans on big repos add up. Many teams will want both, since OpenAI says Codex Security complements static analysis tools. See my GitHub pricing guide for the full plan list.

Share this article

Kurnia Kharisma

Article by

Kurnia Kharisma

Kurnia is a software engineer and writer at eesel AI with two years of SEO experience, writing about AI tools, helpdesk software, and customer support. He pairs a developer's understanding of how these products are built with search-driven research into what actually ranks and resonates with the people searching for them.

Related Posts

All posts →
Hand-drawn illustration of a reviewer holding a scorecard with three ticks and a question mark, next to a cloud-connected code repository and a magnifying glass over a bug inside a shielded sandbox box
Trending

Codex Security Cloud review: I ran its scanner on a buggy app

My Codex Security Cloud review: I planted 5 bugs in a small app and ran OpenAI's scanner. It found all 5, wrote a 55KB report, and cost $3.75 to $6.77.

Rama AdiRama AdiOct 1, 2026
Hand-drawn illustration of a developer at a laptop connected to a smiling cloud that links a repository, a shielded sandbox box, and a findings list, with a second person looking on
Trending

Codex Security Cloud explained: how OpenAI's security agent works

Codex Security Cloud scans your GitHub repos, checks new commits, and tests each finding in a sandbox. Here's how it works, who gets it, and what it costs.

KiraKiraOct 1, 2026
Hand-drawn illustration of a developer comparing five shield-shaped security scanners lined up on a code repository, each with a magnifying glass over a bug
Alternatives

8 best Codex Security Cloud alternatives in 2026 (compared)

The 8 best Codex Security Cloud alternatives in 2026, from Claude Security to Semgrep and Strix, compared on how they prove a bug is real and what they cost.

KiraKiraOct 1, 2026
Hand-drawn illustration of a person holding a green ChatGPT key card in front of a row of open doors, with a weekly usage meter in the corner
Trending

Sign in with ChatGPT: how it works, which apps support it, and the limits

Sign in with ChatGPT lets Plus and Pro users spend their plan inside 16 partner apps. How the two permissions work, the weekly caps, and what partners still charge.

Rama AdiRama AdiOct 1, 2026
Illustrated hero banner of AI agents working inside separate sandbox boxes while a shield-shaped watchdog monitors them from outside, for a post on the NVIDIA Open Agent Safety Platform
Trending

NVIDIA Open Agent Safety Platform: what it is, how it works, and who needs it

The NVIDIA Open Agent Safety Platform is two things: OpenShell, a free runtime you can install today, and Sentry, a hardware watchdog most teams won't touch.

KiraKiraSep 29, 2026
One plugin package feeding several different AI coding agents at once
Trending

Agent Plugins: the new open standard for AI agent extensions

Agent Plugins 1.0.0 shipped on 6 August 2026 with AWS, Cursor, Microsoft, OpenAI and Vercel behind it. Here is what it standardizes, and what it leaves out.

Rama AdiRama AdiAug 6, 2026
CrowdStrike and NVIDIA logos beside an AI-in-shield node linking cloud, laptop and server icons
Trending

CrowdStrike SafeMind: what the NVIDIA-built security models actually do

CrowdStrike SafeMind pairs the Red Tempest and Blue Solano models, built on NVIDIA Nemotron, in a red-vs-blue loop. Here is what it does and where the numbers hold up.

KiraKiraSep 9, 2026
Illustration of a stopwatch lifting away to reveal open runway, representing a lifted usage limit
Trending

OpenAI removed Codex's 5-hour limit: what actually changed

OpenAI temporarily removed the 5-hour usage limit on Codex and ChatGPT Work. Here is what changed on July 12, what stayed, and what it means for you.

Rama AdiRama AdiJul 20, 2026
Hand-drawn illustration of a reviewer with a clipboard grading a document page made of a text block, a chart block, and a prompt button, while a friendly robot edits one block
Trending

ChatGPT pages review: block by block, which parts are ready

A block-by-block ChatGPT pages review: Prompt blocks and Ask for change are strong, Visualize is slow, and pages have no export or version history yet.

Rama AdiRama AdiOct 1, 2026

Ready to hire your AI teammate?

Set up in minutes. No credit card required.

Get started free