SpyBara
Go Premium

Documentation 2026-09-13 15:02 UTC to 2026-09-14 22:58 UTC

14 files changed +42 −31. View all changes and history on the product overview
2026
Tue 29 22:57 Mon 28 22:57 Sat 26 23:59 Fri 25 23:58 Thu 24 23:58 Wed 23 23:58 Tue 22 23:57 Mon 21 23:00 Sat 19 23:00 Fri 18 22:59 Thu 17 10:04 Wed 16 20:58 Tue 15 22:59 Mon 14 22:58 Sun 13 15:02 Fri 11 20:00 Thu 10 18:01 Wed 9 23:59 Sat 5 17:01 Fri 4 23:59 Thu 3 23:00 Wed 2 22:59
Details

17 17 

18You need an OpenAI project API key, a Blaxel API key and workspace, and the Codex CLI package.18You need an OpenAI project API key, a Blaxel API key and workspace, and the Codex CLI package.

19 19 

20Set `OPENAI_API_KEY`, a separate restricted `OPENAI_EXECUTOR_API_KEY`, `BL_API_KEY`, and `BL_WORKSPACE` in your environment. Grant the application key `api.agents.read` and `api.agents.write` for session operations, plus `api.responses.write` for model inference. Add `api.vaults.read` and `api.vaults.write` if your application manages vaults. Create the executor's [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication) and use the same organization, project, and user or service account for both keys. Only the restricted executor key enters the sandbox. Choose the sandbox region in your provisioning code. Use `us-was-1` if you need the Agent Drive persistence option below.20Set `BL_API_KEY` and `BL_WORKSPACE`, and use `OPENAI_API_KEY` for application requests. Set `OPENAI_EXECUTOR_API_KEY` to an [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication), and pass only that key into the sandbox as `CODEX_API_KEY`.

21 

22Choose the sandbox region in your provisioning code. Use `us-was-1` if you need the Agent Drive persistence option below.

21 23 

22## 1. Set up the Blaxel environment24## 1. Set up the Blaxel environment

23 25 

24Create a [self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID. Use the Blaxel SDK or API to create an isolated sandbox with the configured working directory. Install the Codex CLI in the sandbox, then [start its executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) with that environment ID and the restricted executor key.26Create a [self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID. Use the Blaxel SDK or API to create an isolated sandbox with the configured working directory. Install the Codex CLI in the sandbox, then [start its executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) with that environment ID and the environment key.

25 27 

26The Blaxel Node image uses Alpine Linux, so install `ripgrep` with `apk`. Pass the restricted executor key as `CODEX_API_KEY` only to the executor process. Set `keep_alive=True` to prevent the sandbox from scaling to zero while the executor runs. Bounded setup, executor, and sandbox timeouts prevent abandoned resources from running indefinitely.28The Blaxel Node image uses Alpine Linux, so install `ripgrep` with `apk`. Pass the environment key as `CODEX_API_KEY` only to the executor process. Set `keep_alive=True` to prevent the sandbox from scaling to zero while the executor runs. Bounded setup, executor, and sandbox timeouts prevent abandoned resources from running indefinitely.

27 29 

28For regular use, build a Blaxel image with Codex and `ripgrep` already installed so the sandbox can connect sooner.30For regular use, build a Blaxel image with Codex and `ripgrep` already installed so the sandbox can connect sooner.

29 31 

Details

16 16 

17## Before you begin17## Before you begin

18 18 

19You need a Cloudflare account with Containers access, an OpenAI application API key, and a separate restricted executor key. Follow [executor authentication](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication) to configure the keys. Keep the application key outside the Container.19You need a Cloudflare account with Containers access. Use `OPENAI_API_KEY` for application requests. Set `OPENAI_EXECUTOR_API_KEY` to an [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication), and pass only that key into the Container as `CODEX_API_KEY`.

20 20 

21[Create an agent](https://developers.openai.com/api/docs/guides/agents-api/configuration#reuse-an-agent-across-sessions) and save its ID as `OPENAI_AGENT_ID`. Use the same agent ID in your application and the reference Worker.21[Create an agent](https://developers.openai.com/api/docs/guides/agents-api/configuration#reuse-an-agent-across-sessions) and save its ID as `OPENAI_AGENT_ID`. Use the same agent ID in your application and the reference Worker.

22 22 


41Enter these values when prompted:41Enter these values when prompted:

42 42 

43| Variable | Value |43| Variable | Value |

44| ------------------------- | ------------------------------------------------------- |44| ------------------------- | --------------------------------------------------------- |

45| `OPENAI_API_KEY` | Key used by the Worker to retrieve session state |45| `OPENAI_API_KEY` | Key used by the Worker to retrieve session state |

46| `OPENAI_EXECUTOR_API_KEY` | Restricted key passed to `codex exec-server` |46| `OPENAI_EXECUTOR_API_KEY` | Environment key passed to the executor as `CODEX_API_KEY` |

47| `OPENAI_AGENT_ID` | Agent ID served by this Worker |47| `OPENAI_AGENT_ID` | Agent ID served by this Worker |

48| `OPENAI_WEBHOOK_SECRET` | `pending-webhook-registration` for the first deployment |48| `OPENAI_WEBHOOK_SECRET` | `pending-webhook-registration` for the first deployment |

49| `EXECUTOR_CLIENT_SECRET` | Secret generated for cleanup |49| `EXECUTOR_CLIENT_SECRET` | Secret generated for cleanup |

Details

25 25 

26You need an OpenAI project API key, a Daytona API key, and the Codex CLI package.26You need an OpenAI project API key, a Daytona API key, and the Codex CLI package.

27 27 

28Set `OPENAI_API_KEY`, a separate restricted `OPENAI_EXECUTOR_API_KEY`, and `DAYTONA_API_KEY` in your environment. Grant the application key `api.agents.read` and `api.agents.write` for session operations, plus `api.responses.write` for model inference. Add `api.vaults.read` and `api.vaults.write` if your application manages vaults. Create the executor's [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication) and use the same organization, project, and user or service account for both keys. Only the restricted executor key enters the sandbox.28Set `DAYTONA_API_KEY` and use `OPENAI_API_KEY` for application requests. Set `OPENAI_EXECUTOR_API_KEY` to an [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication), and pass only that key into the sandbox as `CODEX_API_KEY`.

29 29 

30### 1. Set up the Daytona environment30### 1. Set up the Daytona environment

31 31 

32Create a [self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID. Use the Daytona SDK or API to create an isolated sandbox with the configured working directory. Install the Codex CLI in the sandbox, then [start its executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) with that environment ID and the restricted executor key.32Create a [self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID. Use the Daytona SDK or API to create an isolated sandbox with the configured working directory. Install the Codex CLI in the sandbox, then [start its executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) with that environment ID and the environment key.

33 33 

34The executor's connection to OpenAI is outbound and long-lived, and Daytona's inactivity tracking does not observe it. Set `auto_stop_interval=0` so the Sandbox is not stopped while the agent is working, and configure a lifetime limit so interrupted runs do not leave compute running indefinitely.34The executor's connection to OpenAI is outbound and long-lived, and Daytona's inactivity tracking does not observe it. Set `auto_stop_interval=0` so the Sandbox is not stopped while the agent is working, and configure a lifetime limit so interrupted runs do not leave compute running indefinitely.

35 35 

Details

16 16 

17You need a sandbox-enabled DigitalOcean account with access to `codex-agentapi` and an OpenAI project with Agents API access.17You need a sandbox-enabled DigitalOcean account with access to `codex-agentapi` and an OpenAI project with Agents API access.

18 18 

19Set `OPENAI_API_KEY` for your application or CLI and a separate restricted `OPENAI_EXECUTOR_API_KEY` for the sandbox. The keys must have the same owner, organization, and project. Store only the executor key in the sandbox's `CODEX_API_KEY` secret. See [executor authentication](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication).19Use `OPENAI_API_KEY` for your application or CLI. Set `OPENAI_EXECUTOR_API_KEY` to an [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication). Pass only the environment key into the sandbox as `CODEX_API_KEY`.

20 20 

21For webhook controllers or Python applications, set `DIGITALOCEAN_TOKEN` and install the [PyDo beta SDK](https://github.com/digitalocean/pydo/releases/tag/v0.40.0-beta.7) with async support (`pydo[aio]`). Use the [OpenAI SDK](https://developers.openai.com/api/docs/libraries#install-an-official-sdk) for Agents API requests. CLI installation is needed only for the CLI flow.21For webhook controllers or Python applications, set `DIGITALOCEAN_TOKEN` and install the [PyDo beta SDK](https://github.com/digitalocean/pydo/releases) with async support (`pydo[aio]`). Use the [OpenAI SDK](https://developers.openai.com/api/docs/libraries#install-an-official-sdk) for Agents API requests. CLI installation is needed only for the CLI flow.

22 22 

23## Webhook-managed23## Webhook-managed

24 24 


33 33 

34The CLI creates both resources and lets you interact with the agent from your terminal. It provisions the sandbox directly, without a webhook controller.34The CLI creates both resources and lets you interact with the agent from your terminal. It provisions the sandbox directly, without a webhook controller.

35 35 

36Install the [`doctl` beta release](https://github.com/digitalocean/doctl/releases/tag/v1.168.0-beta.8) that includes `harness-runtime`, then authenticate:36Install the [`doctl` beta release](https://github.com/digitalocean/doctl/releases) that includes `harness-runtime`, then authenticate:

37 37 

38```bash38```bash

39doctl auth init39doctl auth init


60 CODEX_API_KEY: ${OPENAI_EXECUTOR_API_KEY}60 CODEX_API_KEY: ${OPENAI_EXECUTOR_API_KEY}

61```61```

62 62 

63The `config` block is the OpenAI create-session request. The CLI authenticates that request with `OPENAI_API_KEY`, fills `${ENV_ID}` from the response, and passes only the restricted executor key to the sandbox. Keep resolved manifests out of logs and source control. Add any destinations your tools need to `egress`.63The `config` block is the OpenAI create-session request. The CLI authenticates that request with `OPENAI_API_KEY`, fills `${ENV_ID}` from the response, and passes only the environment key to the sandbox. Keep resolved manifests out of logs and source control. Add any destinations your tools need to `egress`.

64 64 

65Create the session and sandbox:65Create the session and sandbox:

66 66 


222 222 

223## References223## References

224 224 

225- Read [DigitalOcean sandbox setup](https://github.com/digitalocean/pydo/tree/v0.40.0-beta.7/examples/agents/doc_python_sdk)225- Read [DigitalOcean sandbox setup](https://github.com/digitalocean/pydo/tree/v0.40.0-beta.8/examples/agents/doc_python_sdk)

226- Read [DigitalOcean Python SDK](https://github.com/digitalocean/pydo)226- Read [DigitalOcean Python SDK](https://github.com/digitalocean/pydo)

227- Read [DigitalOcean CLI beta release](https://github.com/digitalocean/doctl/releases/tag/v1.168.0-beta.8)227- Read [DigitalOcean CLI beta release](https://github.com/digitalocean/doctl/releases)

Details

13 13 

14## Before you begin14## Before you begin

15 15 

16Set `E2B_API_KEY`, `OPENAI_API_KEY`, and a separate restricted `OPENAI_EXECUTOR_API_KEY`. Keep the application key outside the worker sandbox. The executor key must match the session owner's organization, project, and user or service account. See [executor authentication](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication).16Set `E2B_API_KEY` and use `OPENAI_API_KEY` for application requests. Set `OPENAI_EXECUTOR_API_KEY` to an [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication), and pass only that key into the sandbox as `CODEX_API_KEY`.

17 17 

18## Webhook-managed18## Webhook-managed

19 19 


27 27 

281. [Create a self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID.281. [Create a self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID.

292. Create an isolated E2B sandbox with the session's working directory and install the Codex CLI inside it.292. Create an isolated E2B sandbox with the session's working directory and install the Codex CLI inside it.

303. [Start the executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) in the sandbox using the environment ID and restricted executor key.303. [Start the executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) in the sandbox using the environment ID and environment key.

314. Use [Run and continue sessions](https://developers.openai.com/api/docs/guides/agents-api/sessions) to send input and check the turn's outcome.314. Use [Run and continue sessions](https://developers.openai.com/api/docs/guides/agents-api/sessions) to send input and check the turn's outcome.

325. [Delete the session](https://developers.openai.com/api/docs/guides/agents-api/sessions/manage#delete-a-session) and stop the E2B sandbox when finished.325. [Delete the session](https://developers.openai.com/api/docs/guides/agents-api/sessions/manage#delete-a-session) and stop the E2B sandbox when finished.

33 33 

Details

17 17 

18You need an OpenAI project API key, a Modal token ID and secret, and the Codex CLI package.18You need an OpenAI project API key, a Modal token ID and secret, and the Codex CLI package.

19 19 

20Set `OPENAI_API_KEY` for application requests and a separate restricted `OPENAI_EXECUTOR_API_KEY` for sandbox registration. Grant the application key `api.agents.read` and `api.agents.write` for session operations, plus `api.responses.write` for model inference. Add `api.vaults.read` and `api.vaults.write` if your application manages vaults. Create the executor's [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication) and use the same organization, project, and user or service account for both keys. Only the restricted executor key enters the sandbox.20Use `OPENAI_API_KEY` for application requests. Set `OPENAI_EXECUTOR_API_KEY` to an [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication), and pass only that key into the sandbox as `CODEX_API_KEY`.

21 21 

22## 1. Set up the Modal environment22## 1. Set up the Modal environment

23 23 

24Create a [self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID. Use the Modal SDK or API to create an isolated sandbox with the configured working directory. Install the Codex CLI in the sandbox, then [start its executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) with that environment ID and the restricted executor key.24Create a [self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID. Use the Modal SDK or API to create an isolated sandbox with the configured working directory. Install the Codex CLI in the sandbox, then [start its executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) with that environment ID and the environment key.

25 25 

26## 2. Run the session26## 2. Run the session

27 27 

Details

58export OPENAI_EXECUTOR_API_KEY="..."58export OPENAI_EXECUTOR_API_KEY="..."

59```59```

60 60 

61Use the application key for Agents API requests. Pass only the separate restricted executor key into the sandbox as `CODEX_API_KEY`. Both keys must have the same owner, organization, and project. See [executor authentication](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication).61Use `OPENAI_API_KEY` for application requests. Set `OPENAI_EXECUTOR_API_KEY` to an [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication), and pass only that key into the sandbox as `CODEX_API_KEY`.

62 62 

63Oracle's example reads the `Sandbox` profile and uses `us-chicago-1`. To override its defaults:63Oracle's example reads the `Sandbox` profile and uses `us-chicago-1`. To override its defaults:

64 64 


851. Create a self-hosted Agents API session with `/workspace` as its working directory. Save the session ID and environment ID.851. Create a self-hosted Agents API session with `/workspace` as its working directory. Save the session ID and environment ID.

862. Create an OCI GenAI Sandbox and wait for it to reach `RUNNING`.862. Create an OCI GenAI Sandbox and wait for it to reach `RUNNING`.

873. Install Codex and write `/workspace/brief.txt` into the sandbox.873. Install Codex and write `/workspace/brief.txt` into the sandbox.

884. Start `codex exec-server` using the session's environment ID and the restricted executor key.884. Start `codex exec-server` using the session's environment ID and the environment key.

895. Open the session event stream, then send input asking the agent to turn `brief.txt` into a migration plan. Wait for completion and read the generated `/workspace/plan.md`.895. Open the session event stream, then send input asking the agent to turn `brief.txt` into a migration plan. Wait for completion and read the generated `/workspace/plan.md`.

906. Stop and delete the OCI sandbox, then [delete the Agents API session](https://developers.openai.com/api/docs/guides/agents-api/sessions/manage#delete-a-session). Attempt both cleanup operations even if one fails.906. Stop and delete the OCI sandbox, then [delete the Agents API session](https://developers.openai.com/api/docs/guides/agents-api/sessions/manage#delete-a-session). Attempt both cleanup operations even if one fails.

91 91 

Details

10 10 

11Use the Runloop SDK or API to manage a Devbox, and HTTP requests to manage Agents API sessions.11Use the Runloop SDK or API to manage a Devbox, and HTTP requests to manage Agents API sessions.

12 12 

13Set `RUNLOOP_API_KEY`, `OPENAI_API_KEY`, and a separate restricted `OPENAI_EXECUTOR_API_KEY`. The OpenAI keys must have the same owner, organization, and project. Only the executor key enters the Devbox. See [executor authentication](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication).13Set `RUNLOOP_API_KEY` and use `OPENAI_API_KEY` for application requests. Set `OPENAI_EXECUTOR_API_KEY` to an [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication), and pass only that key into the Devbox as `CODEX_API_KEY`.

14 14 

15## Application-managed15## Application-managed

16 16 

171. [Create a self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID.171. [Create a self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID.

182. Create a Runloop Devbox with the session's working directory and install the Codex CLI inside it.182. Create a Runloop Devbox with the session's working directory and install the Codex CLI inside it.

193. [Start the executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) in the background with the environment ID and restricted executor key.193. [Start the executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) in the background with the environment ID and environment key.

204. [Send input and inspect the result](https://developers.openai.com/api/docs/guides/agents-api/sessions). For a file task, create `brief.txt` in the workspace and ask the agent to write a migration plan to `plan.md`.204. [Send input and inspect the result](https://developers.openai.com/api/docs/guides/agents-api/sessions). For a file task, create `brief.txt` in the workspace and ask the agent to write a migration plan to `plan.md`.

215. Check that the turn completed, retrieve any files you need, then shut down the Devbox and [delete the session](https://developers.openai.com/api/docs/guides/agents-api/sessions/manage#delete-a-session).215. Check that the turn completed, retrieve any files you need, then shut down the Devbox and [delete the session](https://developers.openai.com/api/docs/guides/agents-api/sessions/manage#delete-a-session).

22 22 

Details

20- **Running locally:** set `VERCEL_TOKEN`, `VERCEL_TEAM_ID`, and `VERCEL_PROJECT_ID` in your environment.20- **Running locally:** set `VERCEL_TOKEN`, `VERCEL_TEAM_ID`, and `VERCEL_PROJECT_ID` in your environment.

21- **Deployed on Vercel:** use Vercel OIDC.21- **Deployed on Vercel:** use Vercel OIDC.

22 22 

23Set `OPENAI_API_KEY` for application requests and a separate restricted `OPENAI_EXECUTOR_API_KEY` for sandbox registration. Grant the application key `api.agents.read` and `api.agents.write` for session operations, plus `api.responses.write` for model inference. Add `api.vaults.read` and `api.vaults.write` if your application manages vaults. Create the executor's [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication) and use the same organization, project, and user or service account for both keys. Only the restricted executor key enters the sandbox.23Use `OPENAI_API_KEY` for application requests. Set `OPENAI_EXECUTOR_API_KEY` to an [environment key](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#authentication), and pass only that key into the sandbox as `CODEX_API_KEY`.

24 24 

25## 1. Set up the Vercel environment25## 1. Set up the Vercel environment

26 26 

27Create a [self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID. Use the Vercel SDK or API to create an isolated sandbox with the configured working directory. Install the Codex CLI in the sandbox, then [start its executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) with that environment ID and the restricted executor key.27Create a [self-hosted session](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#create-or-reuse-a-session) and save its environment ID. Use the Vercel SDK or API to create an isolated sandbox with the configured working directory. Install the Codex CLI in the sandbox, then [start its executor](https://developers.openai.com/api/docs/guides/agents-api/environments/self-hosted#start-the-executor) with that environment ID and the environment key.

28 28 

29For regular use, put Codex in a Vercel snapshot so the sandbox can connect sooner.29For regular use, put Codex in a Vercel snapshot so the sandbox can connect sooner.

30 30 

Details

23 <img src="https://developers.openai.com/images/api/agents-api/self-hosted-sandboxes-1.webp"23 <img src="https://developers.openai.com/images/api/agents-api/self-hosted-sandboxes-1.webp"

24 width="1400"24 width="1400"

25 height="444"25 height="444"

26 alt="The sandbox executor initiates an outbound connection to the Agents API and exchanges commands and results. The sandbox holds the restricted executor key and environment ID."26 alt="The sandbox executor initiates an outbound connection to the Agents API and exchanges commands and results. The sandbox holds the environment key and environment ID."

27 loading="lazy"27 loading="lazy"

28 />28 />

29</picture>29</picture>


54 54 

55### Authentication55### Authentication

56 56 

57Create a separate restricted executor key. It must belong to the same organization, project, and user or service account that owns the session.57Use `OPENAI_API_KEY` for application requests. Grant it `api.agents.read` and `api.agents.write` for session operations, plus `api.responses.write` for model inference. Add `api.vaults.read` and `api.vaults.write` if your application manages vaults.

58 58 

59Create an environment key on the [Agents tab](https://platform.openai.com/agents?tab=environments&environment_view=keys) in the platform dashboard. Set every other permission to **None**. Supply this key to the environment as `CODEX_API_KEY`. Keep your broader application API key outside the environment.59Create a separate environment key on the [Agents tab](https://platform.openai.com/agents?tab=environments&environment_view=keys) in the platform dashboard. It must belong to the same organization, project, and user or service account that owns the session. Set every other permission to **None**.

60 60 

61Agent-generated code can read the executor key, but the key only permits connecting environments. It cannot authorize any other API action. Keep it out of source code, container images, and logs. Rotate or revoke it when needed.61Set `OPENAI_EXECUTOR_API_KEY` to this environment key in your application or provisioning service. Pass its value into the sandbox as `CODEX_API_KEY`, which `codex exec-server` reads. Keep your application's `OPENAI_API_KEY` outside the sandbox.

62 

63Agent-generated code can read the environment key, but the key only permits connecting environments. It cannot authorize any other API action. Keep it out of source code, container images, and logs. Rotate or revoke it when needed.

62 64 

63 65 

64 66 


185 187 

186## Start the executor188## Start the executor

187 189 

188Open the [session event stream](https://developers.openai.com/api/docs/guides/agents-api/sessions/events#consume-a-stream) from your application to receive connection events. Then run this command inside the environment with the restricted `CODEX_API_KEY` configured above. Replace the placeholders with the environment values returned by the API:190Open the [session event stream](https://developers.openai.com/api/docs/guides/agents-api/sessions/events#consume-a-stream) from your application to receive connection events. Then run this command inside the environment with the environment key configured as `CODEX_API_KEY` above. Replace the placeholders with the environment values returned by the API:

189 191 

190```bash192```bash

191codex exec-server \193codex exec-server \

Details

305 305

306 306 

307 307 

308**Don't need a sandbox?** Set `environment.type` to `none` for agents that

309 answer questions or call external tools without running commands or working

310 with local files. [Learn

311 more](https://developers.openai.com/api/docs/guides/agents-api/architecture#start-without-an-environment).

312 

308## 2. Follow progress313## 2. Follow progress

309 314 

310The terminal shows streamed events. The SDK examples print JSON; cURL shows the raw event stream. On a successful run, the agent creates `tree.py`, executes it, and reports a directory tree containing that file. Other files and output depend on the sandbox.315The terminal shows streamed events. The SDK examples print JSON; cURL shows the raw event stream. On a successful run, the agent creates `tree.py`, executes it, and reports a directory tree containing that file. Other files and output depend on the sandbox.

Details

6 6 

7The `omni-moderation-latest` model accepts text and image inputs. It doesn't classify audio. The moderation endpoint is free to use, and image files can be up to 20 MB.7The `omni-moderation-latest` model accepts text and image inputs. It doesn't classify audio. The moderation endpoint is free to use, and image files can be up to 20 MB.

8 8 

9**Child safety:** Do not send known or suspected child sexual abuse material (CSAM) to the Moderation API. The API is not designed for CSAM detection or handling and is not a substitute for dedicated child-safety safeguards. See our [CSAM guidance](https://developers.openai.com/api/docs/guides/csam-guidance) for steps to prevent, detect, respond to, and report CSAM.

10 

9## Choose a moderation workflow11## Choose a moderation workflow

10 12 

11| Workflow | Use when |13| Workflow | Use when |

libraries.md +1 −1

Details

173<dependency>173<dependency>

174 <groupId>com.openai</groupId>174 <groupId>com.openai</groupId>

175 <artifactId>openai-java</artifactId>175 <artifactId>openai-java</artifactId>

176 <version>4.63.1</version>176 <version>4.63.2</version>

177</dependency>177</dependency>

178```178```

179 179 

quickstart.md +1 −1

Details

190<dependency>190<dependency>

191 <groupId>com.openai</groupId>191 <groupId>com.openai</groupId>

192 <artifactId>openai-java</artifactId>192 <artifactId>openai-java</artifactId>

193 <version>4.63.1</version>193 <version>4.63.2</version>

194</dependency>194</dependency>

195```195```

196 196