Codex Security Cloud pricing: what it costs and how it spends your Codex quota
Codex Security Cloud, announced September 29, 2026, is OpenAI’s always-on security scanner: it scans connected GitHub repositories, checks new commits as they land, reproduces suspected vulnerabilities in a sandbox, and prepares fixes — while your laptop is closed (OpenAI: DevDay 2026 Recap (Sep 29, 2026) OpenAI Learn: Codex Security (plugin, CLI and Security Cloud)). The first question every Codex subscriber asked that day was the right one: what does a scan do to my remaining Codex usage? The short answer: Security Cloud has no separate price, and no separate meter — it runs in Codex cloud, and cloud tasks spend the same allowance as the rest of your Codex work (OpenAI Learn: Codex pricing (shared usage, cloud tasks)).
Codex Security Cloud pricing and usage rules in one table
| Question | What OpenAI says | Official source |
|---|---|---|
| What Codex Security Cloud is | A plugin that scans connected GitHub repositories in Codex cloud, validates likely vulnerabilities, and presents findings with evidence and remediation guidance. Repository scans run once; commit monitoring watches new commits. Launched Sep 29, 2026 in research preview, on web and desktop. | OpenAI: DevDay 2026 Recap (Sep 29, 2026)OpenAI Learn: Codex Security (plugin, CLI and Security Cloud)OpenAI Learn: Codex Security Cloud FAQ |
| Who can use it | Available to all Pro, Business, Enterprise and Edu users on desktop and web; it needs a workspace with access, a connected GitHub repository and a compatible Codex cloud environment. | OpenAI: DevDay 2026 Recap (Sep 29, 2026)OpenAI Learn: Codex Security (plugin, CLI and Security Cloud) |
| Does it have a separate price? | No price is published. There is no Security Cloud pricing page; it is a plugin inside ChatGPT, and OpenAI’s recap describes no add-on fee. | OpenAI Learn: Codex Security (plugin, CLI and Security Cloud)OpenAI: DevDay 2026 Recap (Sep 29, 2026) |
| Does a scan spend my Codex usage? | Yes — by design. Security Cloud “scans connected GitHub repositories in Codex cloud”, and cloud tasks share your plan’s usage allowance with local messages — cloud tasks “may use more of your allowance than local messages”. OpenAI has not published a per-scan cost, so a large repo scan can take a meaningful share of your Codex allowance. | OpenAI Learn: Codex Security (plugin, CLI and Security Cloud)OpenAI Learn: Codex pricing (shared usage, cloud tasks) |
| Which models it uses | Scans include access to models offered through Daybreak Blue without a separate Daybreak application. | OpenAI: DevDay 2026 Recap (Sep 29, 2026) |
| How findings are produced | A threat model is built for the repo, the code is scanned once or per commit, suspected issues are reproduced in an ephemeral sandbox container (auto-validation), and validated findings come with a proposed patch. Patches are never auto-applied — you review before creating a draft pull request. | OpenAI Learn: Codex Security Cloud FAQ |
| Can I pause or control scanning? | Yes. Open Repositories, pick the repo, open Monitoring settings and set monitoring to Paused. Scan time varies with repository size and validation work. | OpenAI Learn: Codex Security Cloud FAQ |
| Does it replace SAST or manual review? | No. OpenAI positions it as a complement to SAST: it adds semantic, LLM-based reasoning and automated validation, while SAST keeps broad deterministic coverage — and it “does not replace code-level validation, exploitability checks, or human threat assessment”. | OpenAI Learn: Codex Security Cloud FAQOpenAI Learn: Codex Security (plugin, CLI and Security Cloud) |
| Where to watch the usage it spends | The usage dashboard at chatgpt.com/codex/settings/usage shows current limits; /status shows remaining limits inside a Codex CLI session. | OpenAI Learn: Codex pricing (shared usage, cloud tasks) |
Why one scan can eat most of your day’s Codex allowance
None of this is hidden — it follows from how Codex meters work. OpenAI states that local messages and cloud chats share one plan allowance, that weekly limits may also apply, and that cloud tasks may use more allowance than comparable local messages (OpenAI Learn: Codex pricing (shared usage, cloud tasks)). Security Cloud jobs are cloud tasks with an unusually large appetite: they clone a whole repository, build a threat model, scan every meaningful path, and then spin up ephemeral containers to try to reproduce each suspected issue (OpenAI Learn: Codex Security Cloud FAQ). Validation is what makes the findings trustworthy — and what makes a big first scan expensive in usage terms.
OpenAI publishes no per-scan or per-repository usage figures, so this page won’t invent any. What is documented: usage drains faster at higher speed modes (Astra Ultrafast burns included usage at 8× the standard rate), and Enterprise admins are explicitly warned that higher usage rates “can consume a user’s budget faster” (OpenAI Learn: Codex pricing (shared usage, cloud tasks) OpenAI Learn: ChatGPT usage limits and spend controls). Treat a full-repository scan as a heavy Codex session, not a free background chore.
How to keep Security Cloud from eating your quota
The official controls, in the order that saves the most usage:
- Start with a Repository scan, not commit monitoring. A one-time scan tells you the shape of the consumption on your repo; ongoing monitoring multiplies it by every push (OpenAI Learn: Codex Security Cloud FAQ).
- Pause monitoring between bursts of work. Monitoring settings accept a Paused state per repository, and pausing is instant (OpenAI Learn: Codex Security Cloud FAQ).
- Set the environment up once. A reusable cloud environment (repos, access, install script) is created during setup and shared by later scans, so repeat scans don’t re-pay the setup work (OpenAI Learn: Codex Security Cloud setup).
- Watch the usage dashboard after the first scan. Check chatgpt.com/codex/settings/usage to see how much of your allowance the scan took, then decide the monitoring cadence (OpenAI Learn: Codex pricing (shared usage, cloud tasks)).
- If you hit the wall mid-scan, the in-progress agent turn can finish, then you wait for the reset or spend credits — Plus and Pro users can buy credits to continue (OpenAI Learn: Codex pricing (shared usage, cloud tasks)).
Codex Security Cloud alternatives
“Alternative” here means a different way to get the findings without the same quota draw — not a like-for-like product, since Security Cloud’s validated-findings pipeline is the differentiator:
- Local Codex Security plugin. The original Codex Security runs scans locally, inside a Codex task you control — same agent family, and because you pick the scope and moment, you decide what it spends (OpenAI Learn: Codex Security (plugin, CLI and Security Cloud)). Deep scans even accept an estimated cost limit in USD (an estimate, not a hard cap) (OpenAI Learn: Codex Security Cloud FAQ).
- Your existing SAST. OpenAI itself says Security Cloud complements SAST rather than replacing it — deterministic scanners keep covering the broad surface cheaply (OpenAI Learn: Codex Security Cloud FAQ).
- Manual review for the diff that matters. For a single pull request, a focused manual review can be cheaper in usage than a whole-repo scan; Security Review is the CI-oriented middle ground (OpenAI Learn: Codex Security (plugin, CLI and Security Cloud)).
- Codex for Open Source. Maintainers of open-source projects can apply for API credits, six months of ChatGPT Pro with Codex, and Codex Security access (OpenAI: Codex for Open Source).
Track the reset after a heavy scan
When a scan drains your allowance, Codex shows your limits in the usage dashboard and ChatGPT shows reset times when available — and no one, including Support, can reset a limit early (OpenAI Learn: Codex pricing (shared usage, cloud tasks) OpenAI Help Center: About ChatGPT Pro tiers). QuotaClock turns the reset time into a countdown:
- Read the reset time in ChatGPT (Settings → Usage) or the Codex usage dashboard.
- Register it in the countdown tool: set Window started at to now, type the minutes until reset, and name it “Codex (Security Cloud)”.
- Confirm at zero in the dashboard before scheduling the next scan.
More on the Codex side of your plan: how Codex Cloud tasks spend your allowance, the ChatGPT Pro 500 vs 200 vs 100 comparison if you are weighing a bigger tier, and the ChatGPT dots limits page for what dots add on top. How QuotaClock works explains why the countdown never sees your account.
Frequently asked questions
How much does Codex Security Cloud cost?
No separate price is published. It is included as a plugin for Pro, Business, Enterprise and Edu users, and its scans run in Codex cloud — so they draw on the same Codex usage allowance as your other cloud tasks, which may be more per task than local sessions.
Does Codex Security Cloud have a free tier?
No free tier is offered: access starts at Pro on personal plans. Free-plan Codex access covers quick coding tasks on the desktop app with GPT-6 Luna, not security scanning (OpenAI Learn: Codex pricing (shared usage, cloud tasks) OpenAI: DevDay 2026 Recap (Sep 29, 2026)).
How much Codex usage does one scan use?
OpenAI has not published per-scan figures. Scan time and usage vary with repository size and validation work; check the usage dashboard after your first repository scan to calibrate.
Can I schedule scans or run them continuously?
Yes. Commit-monitoring mode reviews new commits as they arrive, per repository; you can pause it at any time in Monitoring settings.
What happens when my Codex usage runs out mid-scan?
The agent can finish the current turn, subject to fair use. After that you wait for the allowance reset, or — on Plus, Pro and flexible Business/Edu/Enterprise plans — buy credits to continue.
Is Codex Security Cloud the same as the Codex Security plugin?
No. The Security Cloud plugin scans connected GitHub repositories in Codex cloud; the Codex Security plugin runs local scans inside a Codex task on your machine. Same analysis family, different runtime and different quota implications.
Sources
All official OpenAI pages, last read 2026-09-30:
- OpenAI: DevDay 2026 Recap (Sep 29, 2026)
- OpenAI Learn: Codex Security (plugin, CLI and Security Cloud)
- OpenAI Learn: Codex Security Cloud FAQ
- OpenAI Learn: Codex Security Cloud setup
- OpenAI Learn: Codex pricing (shared usage, cloud tasks)
- OpenAI Learn: ChatGPT usage limits and spend controls
- OpenAI Help Center: About ChatGPT Pro tiers
- OpenAI: Codex for Open Source
QuotaClock is not affiliated with, endorsed by, or connected to OpenAI. “Codex”, “Codex Security Cloud” and “Daybreak Blue” are OpenAI product names, used here only to describe them.
QuotaClock is an independent, non-official tool. It is not affiliated with, endorsed by, or connected to Anthropic, OpenAI, or any other AI provider. It does not sign in to your accounts, does not read API keys, tokens, or usage data, cannot reset anything for you, and cannot promise that a provider's window rules stay the same. The countdown is built only from the times and lengths you type in. Window lengths and reset rules are set by each provider and change over time — always check the provider's own current documentation.