Comparison guide

Codex vs GitHub Copilot: what teams on GitHub should know

On each vendor's own documentation, checked on 29 September 2026, Codex is OpenAI's coding agent, included in ChatGPT plans, and GitHub Copilot is GitHub's set of coding tools, sold per seat. Three differences matter to a team on GitHub. Where the work happens: Codex runs on the engineer's machine and in Codex Cloud, and reaches GitHub through a connected repository, where it reviews pull requests on request or automatically; Copilot lives inside GitHub, and its cloud agent works in a GitHub Actions environment and opens pull requests there. How it is billed: Codex draws on a ChatGPT plan's usage allowance and then on credits, while Copilot Business and Enterprise pool a monthly allowance of AI credits per seat, charged at US$0.01 a credit beyond the pool. And they overlap: GitHub offers OpenAI Codex as a third-party agent inside Copilot, in public preview, billed to the Copilot subscription.

Coding agent on GitHub. An AI agent, such as Codex or GitHub Copilot's cloud agent, that takes a coding task, works on a copy of a repository, and hands the change back as a branch or pull request for a person to review.

1AYM is an OpenAI Select Partner. Its founder holds personal Claude certifications. 1AYM is not an Anthropic partner.

Checked . Every vendor fact below was read on OpenAI's or GitHub's own documentation. OpenAI's help centre blocks scripted reading, so that article was read in a browser. Prices are the US dollar list prices both vendors' pages served; neither OpenAI's Codex pricing page nor the GitHub pages read for this guide say whether tax is included. Several features compared here, including Codex inside Copilot, are in public preview. Vendors change prices, plans, models and features without notice, so confirm them on the sources below before you buy.

Codex and GitHub Copilot side by side

This is what OpenAI and GitHub each publish about their own tool, read on the same day. No head-to-head test sits behind it, so it records what the vendors say; how well either performs on your code is for a pilot to show. Where a vendor's pages are silent on a point, the cell says so, and the numbers in brackets point to the sources at the foot of the page.

What OpenAI and GitHub publish about Codex and GitHub Copilot for a team: where each runs, how each works with GitHub, team prices in US dollars, usage billing and admin controls, as read on 29 September 2026
DimensionCodex (OpenAI)GitHub Copilot (GitHub)
What it is [1, 12, 14, 18]OpenAI's coding agent. There is no separate Codex subscription: it comes inside ChatGPT plans from Free to Enterprise, sharing a seat's usage allowance with ChatGPT Work, or runs on an OpenAI API key at API rates without cloud featuresGitHub's coding tools: code completion, chat, a CLI, an app, code review and a cloud agent that researches, plans and opens pull requests. Sold as Copilot plans for individuals, and as Copilot Business and Copilot Enterprise for organisations
Where it runs [1, 4, 11, 14, 18]On the engineer's machine through the Codex CLI, the IDE extension and the ChatGPT desktop app, and in Codex Cloud, where each task gets its own isolated workspace and keeps running while the engineer's computer is asleepIn the IDE, on GitHub.com, in GitHub Mobile and the CLI. The cloud agent works in an ephemeral development environment powered by GitHub Actions
Working with GitHub [2, 4, 14, 17]Connect GitHub to Codex. Codex Cloud checks out the repositories you choose; code review runs when someone comments @codex review on a pull request, or automatically once it is switched on for the repositoryBuilt into GitHub. Assign an issue to Copilot, ask it in the agents panel, or mention @copilot on a pull request. Admins set policies for the organisation or enterprise, and repository owners can opt repositories out of the cloud agent
Code not on GitHub.com [4, 8, 11, 12, 14, 18]Codex Cloud does not yet support GitLab or self-hosted GitHub Enterprise Server; OpenAI lists both as on its roadmap. Code review for GitLab merge requests is in preview. Codex on the desktop works with local folders and repositoriesGitHub says Copilot is not currently available for GitHub Enterprise Server, and the cloud agent only works with repositories hosted on GitHub. Copilot code review is in public preview for Azure DevOps
Models [1, 11, 16, 22]OpenAI's own models. For Standard Business, OpenAI's usage table lists GPT-6 Astra, GPT-6.1 Sol, GPT-6 Sol and GPT-6 Luna; what a workspace sees depends on plan and admin settingsModels from several providers, including OpenAI, Anthropic, Google, xAI and Microsoft, with GPT-6 Sol among them. When Copilot runs the OpenAI Codex agent, that agent offers GPT-5.3-Codex, GPT-5.4 and GPT-5.4 nano
Team plan, US list price [1, 12]ChatGPT Business: US$20 per user a month billed annually, or US$25 monthly, for 2 or more users. ChatGPT Enterprise is quote-only, through OpenAI's sales teamCopilot Business: US$19 per granted seat a month. Copilot Enterprise: US$39 per granted seat a month, for enterprises on GitHub Enterprise Cloud
Usage beyond the seat [1, 12, 13, 14]An allowance per plan, which OpenAI gives as estimates per five-hour period, with weekly limits possible on top. Past it, work continues on credits priced per million tokens; the price of a credit depends on your plan or agreement1,900 AI credits per user a month on Business and 3,900 on Enterprise, pooled across the organisation. Beyond the pool, US$0.01 a credit if paid usage is allowed. Code completion is not billed in credits. The cloud agent also uses GitHub Actions minutes
Pull request review [2, 18]Posts a standard GitHub review and flags only P0 and P1 issues, following review rules written in AGENTS.md. A deeper Security Review is in research previewReviews pull requests on GitHub.com and in the IDEs, CLI and GitHub Mobile. On Business and Enterprise, admins can let members without a Copilot licence request reviews, billed as paid usage
Admin controls [1, 5, 17]Business: a dedicated workspace with SAML SSO, MFA and essential admin controls. Enterprise adds SCIM, EKM, role-based access control and domain verification. Codex Cloud is off by default on Enterprise until an admin grants it, and a managed requirements file sets policy for the CLI, IDE extension and desktop appPolicies on the enterprise's AI controls tab or in organisation settings decide which Copilot features, agents and models users reach. For the cloud agent, an enterprise can choose exactly which organisations get it
Audit [1, 7, 20]On Enterprise, audit logs and usage monitoring through the Compliance API, which OpenAI positions for security, legal and investigation work rather than productivity reportingThe enterprise audit log records plan, policy and licence changes and agent activity on the GitHub website. It does not include client session data such as prompts a user sends to Copilot locally
Training on your code [1, 23]ChatGPT Business: no training on your business data by default, and Enterprise includes everything in BusinessGitHub says it does not use Copilot Business or Enterprise data to train its models. On Copilot Free, Pro and Pro+, interaction data may be used for training unless the user opts out

Codex runs inside Copilot too, and it is not the same thing

The search "Codex vs Copilot" assumes two separate purchases. On GitHub's own pages that is no longer quite true. GitHub lists OpenAI Codex as a third-party coding agent, in public preview, which uses OpenAI's Codex SDK and can be powered by an existing Copilot subscription [15, 16]. You can start it from the agents tab, assign it an issue, or mention it on a pull request, and it works alongside Copilot's own cloud agent [15].

Before anyone treats that as a free Codex seat, look at what changes. Inside Copilot, the Codex agent offers GPT-5.3-Codex, GPT-5.4 and GPT-5.4 nano [15, 16], which is a different model list from the one OpenAI's own plans show [1]. It is billed in Copilot AI credits and GitHub Actions minutes [15]. It sits under GitHub's policies and audit log: switching it on installs a GitHub App called openai code agent, whose actions show in the audit log [15]. And it gets the same security checks GitHub runs on its own cloud agent, CodeQL, secret scanning and a check of new dependencies against the GitHub Advisory Database, without needing a GitHub Advanced Security licence [15].

So I would pick the admin console, bill and model list you want the agent to live under first, and let that choose the route. A company already running ChatGPT Enterprise may want Codex in the ChatGPT workspace, next to ChatGPT Work and its existing controls. A company whose engineering governance lives in GitHub may be better served by running the Codex agent through Copilot and keeping one policy screen, one audit log and one bill.

What each costs a team

Both vendors price in two parts: a seat, and usage on top of it. The seats are close on list price, though they buy different things: the ChatGPT seat also covers ChatGPT for that person, and the Copilot seat covers Copilot only. The usage models are not alike, so compare them on a pilot, not on the headline.

Copilot's seat includes its own usage
Copilot Business includes 1,900 AI credits per user a month at US$0.01 a credit, which is US$19 of usage, the same as the seat price; Enterprise's 3,900 credits match its US$39 seat the same way (our arithmetic from GitHub's figures) [12, 13]. The credits are pooled, so light users cover heavy ones, and unused credits do not carry over [13].
Copilot's overage is on by default
Paid usage beyond the pool is enabled by default for organisations and enterprises. To stop any spend past the included credits, an admin has to switch off the AI credits paid usage policy. User-level budgets cap one person, and a budget of zero blocks them at once. When a budget runs out, Copilot does not fall back to a cheaper model [13].
Codex's allowance is shared with ChatGPT Work
A ChatGPT seat's Codex allowance is the same allowance its ChatGPT Work tasks draw on [1, 11]. On a credit-based workspace, Work across the company draws on the same pool of credits as Codex, so a budget sized for engineers alone can run short [9]. Our guide to Codex pricing and credits covers the allowance, the credit rates and a worksheet for estimating a team's month.
Codex's controls depend on the agreement
On credit-based ChatGPT workspaces, admins can set per-user usage limits and a workspace overage limit. Where supported, an overage limit of zero stops usage once credits run out; OpenAI says "No limit" is not a zero-spend cap, and that usage alerts notify without stopping spending [9]. OpenAI also says these workspace controls cover eligible Codex activity, not all Codex usage, and not OpenAI API billing [10].
The agents cost more than chat
Copilot's cloud agent and third-party agents, including Codex, consume GitHub Actions minutes as well as AI credits [14, 15]. On the OpenAI side, cloud tasks may use more of the allowance than local messages [1].

Which fits which situation

Start from the situation below that looks most like yours. Where two apply, the one your security team cares about usually settles it.

GitHub is already where engineering is governed
Copilot keeps the agent, its policies, its audit log and its bill inside GitHub [14, 17, 20]. If your engineers want Codex specifically, try the Codex agent inside Copilot first, remembering it is in public preview and offers a narrower model list than OpenAI's own plans [1, 15].
The company already buys ChatGPT Business or Enterprise
Codex is already in that workspace, under the same sign-on, admin roles and data terms, and it shares its allowance with ChatGPT Work [1, 11]. Pilot it before adding a second vendor's seats for the same engineers.
You run GitHub Enterprise Server
Copilot is not available for GitHub Enterprise Server [12], and Codex Cloud does not support it yet [4]; only Codex on the engineer's machine works there, on local checkouts [11]. A pilot there tests the local route only.
Some of your code is on GitLab or Azure DevOps
Codex code review for GitLab merge requests is in preview [8], and Copilot code review for Azure DevOps is in public preview [18]. Copilot's cloud agent works only on repositories hosted on GitHub [14]. Pilot on the platform that holds the code that matters most.
Engineers want to hand off long tasks
Copilot's cloud agent works in one repository and on one branch per task, opens one pull request, and stops at 59 minutes, a hard limit [14]. Codex Cloud gives each task its own workspace that keeps running while the engineer's computer is asleep, and keeps a task's saved state for up to seven days [4]. If long tasks are the reason for buying, test your longest real task on both.
Finance wants a hard ceiling
On Copilot, switch off paid usage beyond the pool, or set user budgets [13]. On a credit-based ChatGPT workspace, set per-user limits and, where supported, a workspace overage limit of zero [9]. In both cases, check the setting on a test user before rollout.
You already pay for both
Nothing stops both reviewing the same pull request. Decide which reviewer's comments must be resolved before merge, because two automated reviewers with equal weight produce noise rather than safety.

What to check before either touches a real repository

Both vendors put real guardrails in front of their agents, and both are clear that those guardrails do not replace your own. OpenAI says Codex's review rules do not replace tests, branch protections or required approvals [2]. GitHub lists the risks of its cloud agent and the mitigations it applies [19]. Read these before you switch anything on.

Who can start the agent
Only users with write access to the repository can trigger Copilot's cloud agent, and comments from anyone else never reach it [19]. The Codex GitHub Action, by default, runs only for users with write access, and OpenAI advises limiting who can start the workflow [3].
What the agent can push
Copilot's cloud agent pushes to a single branch (a new copilot/ branch, or the pull request's branch when mentioned on one), cannot approve or merge its pull request, and by default its pull requests do not trigger GitHub Actions workflows until someone with write access approves them [19]. Codex Cloud respects the repository permissions and protections the connected source system exposes [5].
Network access
Codex runs with network access off by default, and locally it works inside a sandbox that typically limits it to the workspace [6]. GitHub restricts the Copilot cloud agent's internet access through a firewall you can customise [19].
Prompt injection
GitHub filters hidden characters, such as HTML comments, before passing issue and comment text to its cloud agent [19]. OpenAI tells teams using the Codex GitHub Action to sanitise prompt input taken from pull requests, commits or issues [3].

Whichever tool you pick, the permissions, review gates and shared instructions around it are what decide whether its pull requests are safe to merge. Our rollout guide for Codex and Claude Code sets out that operating layer, and most of it applies to Copilot unchanged.

A two-week pilot on one repository

Vendor pages will not tell you how either tool does on your code, so the only comparison I would put in front of a budget holder is a pilot. Pick one repository that ships often, measure it before either tool touches it, and run both routes on the same backlog.

The same work
Give each route the same kinds of issues: a bug, a small feature, a test-coverage task and one long task. If you are testing Codex inside Copilot as well, treat it as a third route.
The same review
Have a reviewer judge each pull request without knowing which tool wrote it, and record whether it merged, how much it needed changing and how long review took.
Usage per person
Read Copilot usage in AI credits and Actions minutes, and Codex usage from ChatGPT's usage dashboard [1, 13]. Record the median user and the heaviest one, because the heavy users set the bill.
The controls
Switch on the policies you would run in production, try an action each one should block, and check that the audit record shows it [7, 20].

If the question behind this page is really Codex against Claude Code, our comparison of Codex and Claude Code for business covers that choice with the same method.

Where 1AYM fits

Rolling out AI coding tools to engineering teams is core 1AYM work, and the parts of this guide that take hands are the parts we do: the two-week pilot, the policies and spend limits, the shared AGENTS.md and review rules, and the path from an agent's pull request to production. We sell it as AI Engineering Transformation. The closest documented case is engagement file D-01, listed below: at a large international marketing agency we hold the lead architect role on its AI platform and contribute engineering to its internal Claude Code skill platform.

1AYM is an OpenAI Select Partner, which is why the disclosure sits at the top of this page. We build on OpenAI's and Anthropic's tools alike, so the decision guide above matches a tool to a situation, and a pilot result outweighs the partnership. We take small fixed-scope statements of work as well as larger builds, and a fixed-scope pilot can start within a day of the scope being signed. If you already have the rollout scoped, it can be resourced on contract from the collective of associates who work with 1AYM, held to the same standard. Book a call from the end of this page, or email tayyeb@1aym.com.

For engineers: GitHub wiring, policies and audit gaps

The details behind the table for whoever will connect the repositories, write the policies and answer the security review, each with its source.

Codex review rules
Codex reads AGENTS.md files and follows a "## Code Review Rules" section in the file nearest the changed code; root rules apply repository-wide and nested files add service rules. "@codex review for issues in the database migration" focuses one review, and "@codex fix the P1 issue" starts a task that can push a fix to the branch when it has permission [2].
Codex in CI
openai/codex-action@v1 installs the Codex CLI and runs codex exec in a workflow, with an OpenAI API key stored as a GitHub secret. Keep safety-strategy on drop-sudo, choose the narrowest sandbox, and use allow-users and allow-bots to restrict triggers. On Windows runners it must run as unsafe [3]. An API key bills at API rates and has no cloud features such as GitHub code review [1].
Codex local policy
Admins deliver requirements.toml through a supported channel to constrain the ChatGPT desktop app, Codex CLI and IDE extension, for example allowed permission profiles. Cloud environments do not inherit local device policy, so review cloud requirements separately [5].
Copilot policy precedence
Enterprise policy comes first; for most policies it can enable, disable or let organisations decide. A user licensed through several organisations in one enterprise usually gets the least restrictive setting; across different enterprises, almost always the most restrictive. The Copilot app and Copilot CLI have separate client policies [17].
Copilot agent identity
Cloud agent commits are authored by Copilot with the requester as co-author, are signed, and link to the session log. When the agent opens a pull request under its own app identity, one more approval is required where the repository already requires one [19].
Third-party agent apps
Allowing the Codex coding agent installs the openai code agent GitHub App. Its actions appear in the audit log, but the app does not appear in the account's list of installed GitHub Apps [15].
Audit gaps
GitHub's audit log excludes client session data such as local prompts; GitHub notes that some companies send Copilot CLI events to their own logging through custom hooks [20]. OpenAI treats its Admin API reference as the source of truth for which Codex events the Compliance API covers [7].
Content exclusion limits
Copilot content exclusion is not supported in Edit and Agent modes of Copilot Chat in VS Code and other editors, and does not apply to symlinks or repositories on remote filesystems [21]. Do not rely on it to keep a file away from an agent.

Sources

  1. [1]OpenAI, Codex and ChatGPT Work pricing (learn.chatgpt.com), read 29 September 2026
  2. [2]OpenAI, Review GitHub pull requests with Codex (learn.chatgpt.com), read 29 September 2026
  3. [3]OpenAI, Codex GitHub Action (learn.chatgpt.com), read 29 September 2026
  4. [4]OpenAI, Codex Cloud environments (learn.chatgpt.com), read 29 September 2026
  5. [5]OpenAI, Admin rollout guide (learn.chatgpt.com), read 29 September 2026
  6. [6]OpenAI, Agent approvals and security (learn.chatgpt.com), read 29 September 2026
  7. [7]OpenAI, Compliance API and audit events (learn.chatgpt.com), read 29 September 2026
  8. [8]OpenAI, Code review (learn.chatgpt.com), read 29 September 2026
  9. [9]OpenAI, ChatGPT Work: usage and cost, including workspace spend controls (learn.chatgpt.com), read 29 September 2026
  10. [10]OpenAI, ChatGPT usage limits and spend controls (learn.chatgpt.com), read 29 September 2026
  11. [11]OpenAI Help Center, ChatGPT Work and Codex (read in a browser), read 29 September 2026
  12. [12]GitHub Docs, Plans for GitHub Copilot, read 29 September 2026
  13. [13]GitHub Docs, Usage-based billing for organizations and enterprises, read 29 September 2026
  14. [14]GitHub Docs, About GitHub Copilot cloud agent, read 29 September 2026
  15. [15]GitHub Docs, About third-party coding agents, read 29 September 2026
  16. [16]GitHub Docs, OpenAI Codex, read 29 September 2026
  17. [17]GitHub Docs, GitHub Copilot policies for enterprises and organizations, read 29 September 2026
  18. [18]GitHub Docs, About GitHub Copilot code review, read 29 September 2026
  19. [19]GitHub Docs, Risks and mitigations for GitHub Copilot cloud agent, read 29 September 2026
  20. [20]GitHub Docs, Reviewing audit logs for GitHub Copilot, read 29 September 2026
  21. [21]GitHub Docs, Content exclusion for GitHub Copilot, read 29 September 2026
  22. [22]GitHub Docs, Supported AI models in GitHub Copilot, read 29 September 2026
  23. [23]GitHub, Copilot plans and pricing, including the data and training FAQ, read 29 September 2026

Common questions

What is the difference between Codex and GitHub Copilot?

Codex is OpenAI's coding agent, included in ChatGPT plans and billed from the plan's usage allowance and credits. GitHub Copilot is GitHub's set of coding tools, sold per seat with a pooled allowance of AI credits, and built into GitHub's issues, pull requests and admin policies. Both review pull requests and run cloud agents that open them.

Can we use Codex inside GitHub Copilot?

Yes, in public preview. GitHub lists OpenAI Codex as a third-party coding agent that can be powered by an existing Copilot subscription, once an admin enables it. It offers GPT-5.3-Codex, GPT-5.4 and GPT-5.4 nano, and uses Copilot AI credits and GitHub Actions minutes rather than a ChatGPT allowance.

Which is cheaper for a team?

On list prices the seats are close: ChatGPT Business is US$20 per user a month billed annually, and Copilot Business is US$19 per granted seat a month. The ChatGPT seat also covers ChatGPT for that person; the Copilot seat covers Copilot only. The bigger difference is usage. Copilot's seat includes AI credits worth its price at list, pooled across the organisation; Codex draws on an allowance shared with ChatGPT Work, then credits. Only a pilot tells you which costs less for your team.

Does either work with GitHub Enterprise Server?

Copilot does not; Codex only on the engineer's machine. GitHub says Copilot is not currently available for GitHub Enterprise Server, and OpenAI lists self-hosted GitHub Enterprise Server as not yet supported in Codex Cloud. Codex on an engineer's own machine works with local repositories.

Does either train on our code?

Not on business plans by default. OpenAI says ChatGPT Business does not train on business data by default, and Enterprise includes everything in Business. GitHub says it does not use Copilot Business or Enterprise data to train its models; on Copilot Free, Pro and Pro+ it may use interaction data unless the user opts out.

Can Codex review pull requests on GitHub?

Yes. Once a repository is connected to Codex and code review is switched on, commenting @codex review on a pull request starts a review, or reviews can run automatically. Codex posts a standard GitHub review, flags only P0 and P1 issues, and follows review rules written in AGENTS.md.

Which should we choose?

Start from where your code is hosted, which admin console and audit log your security team wants, and how your finance team wants usage billed. Then run both on the same repository for two weeks and compare merged pull requests, review time and usage per person.

Further

We build these systems for a living. See the engagement files for what that looks like in practice, or write to us if yours is the next one.

Last reviewed · 1AYM