DevFlow vs Codex: 7 dimensions, sourced
DevFlow and Codex are compared on 7 dimensions below, each read from OpenAI's own documentation on 1 Oct 2026; 3 cases where Codex fits better are listed too.
Codex Cloud, from OpenAI, works through coding tasks in the cloud, from investigating bugs to building features, while you review the changes and continue from the web, mobile or desktop app.↗
Each claim about the other product was read on 1 Oct 2026 from the page its ↗ link opens. Cells in the DevFlow column are written from files in DevFlow's own codebase, named next to each cell; that codebase is not public. A comparison left unchecked for 90 days is flagged for review.
| Dimension | DevFlow | Codex |
|---|---|---|
| Where it runs | On the hosted instance at devflow.fraway.io. A self-hosted install is not self-serve: it is arranged with Fraway on request.site/src/lib/site.tsENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelte | A Codex chat runs on your computer, in the current project directory or an isolated Git worktree, or as a Cloud task in its own workspace started from a published environment.↗ |
| Where your code goes | On the hosted instance at devflow.fraway.io, DevFlow clones repositories into worktrees on the servers that run it. Prompts, which include code, go to the model provider the workspace chooses.CLAUDE.mdsite/src/lib/site.ts | For Codex Cloud you choose GitHub repositories and connect GitHub; Codex inspects them and installs their dependencies and tools in a cloud environment.↗ |
| Model choice | Each workspace stores its own key for OpenRouter, Anthropic, OpenAI or Google. On Pro and higher plans, managed OpenRouter inference can stand in when no OpenRouter key is stored.internal/relay/providers.gointernal/entitlement/entitlement.goCLAUDE.md | OpenAI models picked in the model picker or a saved configuration, such as GPT-6.1 Sol or GPT-6 Luna, depending on the plan and client.↗ |
| Isolation | Each task gets its own git worktree. Agent CLIs run under a Landlock sandbox or, when enabled, in a per-invocation container; test and build commands run in non-root containers capped at 4 CPUs and 4 GB of memory by default.CLAUDE.mdinternal/agent/depcache.go | Each new cloud task gets its own isolated workspace from the published environment, and the environment's internet-access settings define which domains its VM can reach.↗ |
| Verification | Runs the repository's configured test commands plus an AI code review and records both in a merge evidence report. A repository with no configured commands is not built or tested, and the report shows the skipped check.CLAUDE.mdinternal/agent/evidence.gointernal/agent/gate_command.go | While preparing a cloud environment, Codex installs dependencies and tests the workflow; each task then shows its changes and test results for review.↗ |
| Human gates | A person approves, edits or rejects the plan before code is written, and a person marks the task done, which starts the squash, push and pull request when GitHub is connected. Opt-in autopilot keeps both gates.CLAUDE.mdinternal/agent/evidence.go | You review the changes and test results, request follow-ups, and commit or open a pull request when you are ready.↗ |
| Pricing model | The self-serve plans are Free, Pro and Team; an Enterprise plan is arranged with Fraway on request. Model usage is paid to the provider whose key the workspace stores, or through managed inference on Pro and above.internal/entitlement/entitlement.goENTITLEMENTS.mdweb/src/lib/components/billing/PlanCards.svelte | Codex comes with ChatGPT plans: the pricing page lists Free, Go, Plus, Pro, Business and Enterprise & Edu, and states that ChatGPT Work and Codex share usage.↗ |
How to read the table
- Where it runs compares hosted machines, machines you operate, and the options in between.
- Where your code goes compares where a checkout lives and which hosting services each product works with.
- Model choice compares fixed model sets, model pickers and keys you bring yourself.
- Isolation compares virtual machines, containers, sandboxes and network limits.
- Verification compares test runs, reviewing models and security scans.
- Human gates compares plan approval, pull request review and approval of individual actions.
- Pricing model compares plans, usage credits and the model spend you pay directly.
Where Codex fits better
- You already pay for a ChatGPT plan and want coding tasks to draw on the usage that plan includes.↗
- You want chats that work directly in your current project directory on your own computer.↗
- You want cloud tasks that keep running while your computer is asleep, reviewed from the web, mobile or the desktop app.↗
What OpenAI documents
A cloud task uses the files and services available in its cloud environment; your computer's local files, running processes, browser sign-ins and VPN access are not transferred to it automatically.↗
Network secrets are sent only to allowed HTTPS services: programs receive a placeholder, and a proxy substitutes the real value for allowed destinations.↗
VPN settings connect a cloud environment's VM to services on a private network.↗
How DevFlow runs the work
A DevFlow task moves from planning to a plan review, then to decomposition into at most 8 subtasks, implementation, verification and a written summary. Each task gets its own branch, named after its task ID, in a worktree under the repository's .devflow/worktrees directory.
By default, every agent invocation has a hard limit of 90 minutes and is stopped after 45 minutes without output. A workspace can also set a monthly spend cap, and a task over that cap fails with a reason before it starts.
On Pro and higher plans, finalization also runs dependency scanners for the languages DevFlow detects, such as govulncheck for Go modules and pnpm audit for Node packages, each stopped after 300 seconds by default. Scan results go into the evidence report and do not block the pipeline.
What DevFlow records along the way
A task that finishes implementation gets a merge evidence report listing the models that did the work, each subtask's verifier outcome, the build checks, the security scan summary, the final review and the people who approved the plan and clicked Mark Done. The report is added to the pull request body, and later rework refreshes it there.
Agent processes start with an allowlisted environment instead of inheriting the server's own. Provider keys and GitHub tokens are encrypted at rest with AES-256-GCM.
FAQ
Can Codex run on my own machine?
Yes. A Codex chat can run locally, in the current project directory or in a Git worktree, and cloud tasks run remotely. DevFlow runs at devflow.fraway.io, with one git worktree per task; a self-hosted DevFlow install is arranged with Fraway on request.
Which models can Codex and DevFlow use?
Codex's models page lists OpenAI models such as GPT-6.1 Sol and GPT-6 Luna. DevFlow workspaces store their own keys for OpenRouter, Anthropic, OpenAI or Google, so a DevFlow workspace can run models from more than one company.