Codex GitHub Integration

Codex deeply integrates with GitHub, allowing you to review code directly in pull requests. This section details how to configure and use the GitHub integration.


Feature Overview

With the GitHub integration, you can:

  • Request Codex review directly in a PR comment
  • Automatically review every pull request
  • Have Codex fix CI failures
  • Review code changes and provide suggestions
Without leaving GitHub, Codex will reply with review comments just like a teammate.

Set Up GitHub Integration

Prerequisites

  • Codex Cloud subscription
  • GitHub account

Configuration Steps

  1. SettingsCodex Cloud
  2. Go toCodex Settings
  3. Enable for the repositoryCode reviewFeatures
  4. Authorize Codex to access your repositories
You need to grant Codex permission to read repositories and create pull requests.

Requesting Code Review

Manually Triggering a Review

Mention Codex in a pull request comment@codex review:

Request Review

# Enter this in the PR comment
@codex review

# Or specify a review focus
@codex review for security regressions

Codex Response

Codex will:

  1. React to the PR (👀)
  2. Analyze the code changes
  3. Post review comments
  4. Flag issues found (P0 and P1)
Codex will post review comments on the PR just like a human reviewer.

Automatic Review

Enable in SettingsAutomatic reviews:

  1. Go toCodex Settings
  2. EnableAutomatic reviews
  3. Automatically post a review when a new PR is opened

Customize Review Content

Set Up Repository Review Guidelines

In the repository'sAGENTS.mdadd review guidelines:

Add Review Guidelines

## Review guidelines

- Don't log PII (Personally Identifiable Information)
- Verify that authentication middleware wraps every route
- Check for SQL injection vulnerabilities
- Ensure error messages don't leak sensitive information

Module-Specific Rules

Place more specific review rules in subdirectories:

Module-Specific Rules

# src/payment/ module-specific review rules

## Payment-specific reviews
- Verify payment processing follows PCI compliance
- Check for proper amount validation
- Ensure transaction logging
More specific rules are automatically applied to code changes in the corresponding module.

One-Time Review Focus

Specify a review focus in a comment:

Specify Review Focus

# Example comment
@codex review for security issues
@codex review for performance regressions
@codex review for documentation completeness

Give Codex Other Tasks

Mention Codex in a comment@codex(not 'review') starts a cloud task:

Other Tasks

# Fix CI failures
@codex fix the CI failures

# Add tests
@codex add tests for the new API endpoints

# Refactor code
@codex refactor this function to use async/await
Using Codex's other features is as simple as @-mentioning it in a comment.

GitHub Actions Integration

You can also use Codex in GitHub Actions:

GitHub Actions Workflow

span style="color: green;">
name: Codex Review

on
: [pull_request]

jobs
:
  codex-review
:
    runs-on
: ubuntu-latest
    steps
:
      - uses
: actions/checkout@v4

      - name
: Run Codex Review
        run
: |
         codex exec "Review code changes in this PR" --output review.md

      - name
: Post Review
        uses
: actions/github-script@v7
        with
:
          script
: |
           const fs = require('fs');
            const review = fs.readFileSync('review.md', 'utf8');
            github.rest.pulls.createReview({
              owner: context.repo.owner,
              repo: context.repo.repo,
              pull_number: context.issue.number,
              body: review,
              event: 'COMMENT'
            });

Integrating Codex into your CI/CD pipeline can automate code review.

Best Practices

Review Guidelines

  • Clearly define review standards in AGENTS.md.
  • Set specific rules for different modules
  • Specify issue priorities (P0/P1)

Automation

  • Enable automatic review for regular PRs
  • Use manual trigger for large changes
  • Use in conjunction with automated workflows
A good configuration can make Codex's reviews more accurate and efficient.

FAQ

Q: Do I need to pay for Codex review?

GitHub integration requires a Codex Cloud subscription.

Q: Can Codex access private repositories?

You need to authorize Codex to access your private repositories.

Q: Can I restrict which repositories Codex can review?

Yes, you can selectively authorize repositories in the settings.

Q: What levels of issues does Codex flag?

Issues are flagged as P0 (critical) and P1 (major) by default.

other extensions