Codex + GitHub
Codex runs the task; the GitHub connector supplies only the operations and resources allowed by the account you authorize. The Composer selects Codex, asks for GitHub access before sending, and keeps both choices in one task draft.
How the combination works
Codex plans and executes. GitHub supplies authorized app access.
Codex owns the coding-agent loop: it explores the repository, changes files, runs commands, and returns evidence from the cloud workspace.
Where the world builds software. Millions of developers and companies build, ship, and maintain their software on GitHub—the largest and most advanced development platform in the world.
Codex
Owns the task loop, model calls, cloud computer, tool choices, progress and final result.
GitHub connector
Supplies the currently exposed operations for the authorized GitHub account. It does not promise every feature in the GitHub product.
Permission boundary
The connected identity, granted provider scopes, organization policy, resource sharing and the task's explicit instruction all constrain what Codex can do.
Setup and first task
Connect one GitHub account and verify one known resource.
The Composer preselects Codex with GPT-5.6 Sol. Start read-only when possible, then expand to write operations only after the account and resource boundary are clear.
Open the Codex Composer
The Composer above carries Codex, GPT-5.6 Sol, and GitHub. Add a precise target and expected result; the draft stays on this page during sign-in or connector authorization.
Authorize the intended GitHub account
Review the OAuth app and requested scopes. Organization restrictions can require an owner's approval; authorization for your personal account does not prove access to a private organization repository.
Run and verify a bounded task
Ask the agent to inspect a specific repository or issue you are authorized to access and summarize the relevant information without making changes. Name the owner/repository and the exact issue or branch. Compare the returned information with GitHub. For later write tasks, inspect the actual branch, issue or pull request and its URL before accepting completion.
Access, cost and limits
What to verify before scaling Codex + GitHub
Software engineering tasks that benefit from Codex's repository navigation, command execution, and iterative implementation loop.
Establish with the first run
- Codex and GPT-5.6 Sol remain selected after sign-in.
- GitHub shows the intended connected account before the task is sent.
- The returned data matches one known source resource, with write actions excluded until separately authorized.
Still depends on your setup
- A catalog listing does not guarantee every GitHub website feature is available as an agent operation.
- OAuth scopes do not replace organization policy, resource sharing or a precise task instruction.
- Total task cost can include model tokens, active computer time, paid tools, connectors and the provider's own plan or quota.
Verification and recovery
Check GitHub itself before trusting the result.
Compare the returned information with GitHub. For later write tasks, inspect the actual branch, issue or pull request and its URL before accepting completion.
Connection troubleshooting
If a private repository is inaccessible, check the connected GitHub identity, organization approval and any SAML session requirement. Do not repeatedly reconnect without identifying the denied resource.
Writes need explicit scope
Name the target record and exact allowed change. A request to summarize, analyze or draft does not authorize sending, publishing or deleting.
Re-check current state
For decisions or follow-up writes, open the resource in GitHub and check its current state. A successful earlier read may already be stale.
Common questions
Related resources
