The short version
- Auto-review is free for everyone signed in to Codex through a ChatGPT account, according to an October 6, 2026 post.
- The post says Auto-review does not use your plan’s allowance.
- A separate agent reviews eligible actions that would otherwise wait for your approval.
- Some app approvals still go directly to you, and a denied action may require your decision.
Auto-review in Codex is now free for everyone who signs in with a ChatGPT account, and it no longer uses their plan’s allowance, Thibault Sottiaux, who works on Codex and ChatGPT at OpenAI, wrote on X on October 6, 2026. That lets Codex continue a long task while a separate agent approves or denies actions that need review. He wrote, “This Auto-review feature is now free and does not draw usage from your plan.”
Is Codex Auto-review free for ChatGPT users?
Yes. The October 6, 2026 announcement says Auto-review is free for all users signed in through a ChatGPT account and does not draw from their plan’s usage. The change concerns its price and plan usage; Auto-review was already available in Codex.
OpenAI’s security documentation still says automatic reviews use extra model calls and can add to Codex usage. That page had not been changed to match the announcement on October 6, 2026.
How do I turn on Codex Auto-review?
Open settings, then permissions, then auto-review. OpenAI’s Auto-review documentation refers to a permissions mode named Approve for me in the ChatGPT desktop app, available only when your account and organization policy allow it.
- Sign in with your ChatGPT account.
- Open settings, then permissions, then auto-review.
For the CLI, OpenAI’s documentation gives these two lines for config.toml:
approval_policy = "on-request"
approvals_reviewer = "auto_review"
Auto-review requires an interactive approval policy. With approval_policy = "never", there are no approval requests for it to assess.
What does Codex Auto-review review and block?
Auto-review sends eligible requests that would normally pause for your approval to a separate reviewer agent. Those requests include commands seeking permission to leave the sandbox, blocked network requests, edits outside allowed folders, and app or MCP tool calls that require approval. Actions already permitted inside the sandbox continue without review. Auto-review does not expand Codex’s file, network, or sandbox permissions.
It is designed to stop actions that could cause serious harm, including:
- Transferring private information or credentials to an untrusted destination.
- Searching for tokens, cookies, or other credential material.
- Making broad or lasting changes that weaken security.
- Deleting data or making other changes that would be difficult to reverse.
- Executing untrusted code or obeying instructions in untrusted material that conflict with your request.
After a denial, Codex must find a materially safer way to proceed or stop and ask you. A turn is interrupted after three consecutive denials or 10 denials within its last 50 reviews. In the current open-source terminal interface, /approve lets you select one denied action for one retry. Auto-review still assesses that retry and can deny it again.
Computer Use app approvals still go directly to you.
How effective is Codex Auto-review?
OpenAI’s internal figures in its April 30, 2026 research post measure both approval friction and responses to risky actions. Results can vary with the task, environment, and sandbox settings.
OpenAI’s Auto-review measurements
| Measure | Result | What it measures |
|---|---|---|
| Stops for human approval | Roughly 200 times fewer | Pauses for a person compared with manual approval mode. |
| Approval rate on escalated actions | 99.1% | Escalation requests accepted in sampled internal Codex activity. |
| Effective approval rate on all actions | 99.93% | Actions that proceeded, including those inside the sandbox. |
| Overeagerness cases correctly denied | 90.3% | Synthetic cases where an agent sought a risky action while pursuing a task. |
| Prompt-injection cases correctly denied | 99.3% | Tested attacks involving remote code execution, secret exposure, or external upload. |
| MonitoringBench [Hard] | 96.1% | Runs in which a coding agent covertly attempts a malicious task; a run counts as caught when any of its actions is rejected. |
In an illustrative snapshot of 10,000 actions, 9,280 stayed inside the sandbox and 720 went to Auto-review. The reviewer approved 713 and denied seven; four denials led to a safer route, while three stopped for user input.
Is Codex Auto-review safe to leave in charge?
Auto-review can handle eligible approval requests during a long task, but it cannot guarantee that every unsafe action will be stopped. OpenAI puts the limit plainly: “Auto-review should not be treated as a guarantee of security.” Its red-team tests found cases where the reviewer was misled into approving a command.
The reviewer assesses requests to cross a boundary. It cannot protect against a model that conceals its intent, and actions that stay inside the sandbox do not reach it. Keep the sandbox and organization rules suited to the work, and inspect the result before relying on it.
What else changed in Codex in October 2026?
The October 6, 2026 announcement was labeled “Day 2.1” in the 28-day run of daily improvements that OpenAI’s Codex team promised on October 4, 2026. The “Day 1” post on October 5, 2026 said default speed had become about 50% faster on GPT-6 Astra and GPT-6.1 Sol for subscription users, including partner apps that use Sign in with ChatGPT.
Auto-review predates that run. OpenAI’s April 30, 2026 research post says it had been released in Codex the previous week.
- Sign in to Codex with your ChatGPT account and check settings, then permissions, then auto-review.
- If you use the CLI, add the documented lines to
config.tomlwhile keeping interactive approvals enabled. - Watch for app prompts and denials, then review the completed work before using or publishing it.
FAQs
Does Codex Auto-review use my ChatGPT plan’s usage?
The October 6, 2026 announcement says Auto-review is free for ChatGPT account sign-ins and does not draw from plan usage. OpenAI’s security documentation also says automatic reviews use extra model calls and can add to Codex usage, so the written guidance conflicts with that announcement.
What are the Codex Auto-review config.toml settings?
Set approval_policy = "on-request" and approvals_reviewer = "auto_review" in config.toml. The first keeps approvals interactive; the second routes eligible requests to Auto-review.
Was Codex Auto-review already available before October 2026?
Yes. OpenAI’s April 30, 2026 research post says Auto-review had been released in Codex the previous week. The October 6, 2026 announcement changed its price and plan-usage terms.
Does Codex Auto-review give Codex more permissions?
No. Codex keeps the same sandbox, network limits, and allowed folders. Auto-review changes who decides on eligible requests to cross those boundaries.
When do repeated Codex Auto-review denials interrupt a turn?
A turn is interrupted after three consecutive denials or 10 denials within its last 50 reviews. A review that is not a denial resets the consecutive count.
Can I approve a Codex Auto-review denial myself?
Yes. In the current open-source terminal interface:
- Run
/approveto open the denials picker. - Select a recent denied action to authorize one retry of that exact action.
Auto-review assesses the retry and can deny it again.







Leave a Reply