Skip to evidence

MEASURED · TESTED Aug 14, 2026

Does Codex CLI phone home?

Startup contacted OpenAI and GitHub infrastructure in 3/3 final runs; two OpenAI routes varied across batches.

RETEST QUEUEDUpstream 0.158.0 was detected Sep 28, 2026. Every result on this page remains scoped to tested build 0.147.0.

PREVIOUS TESTED BUILD 0.146.0 · Aug 13, 2026
BUILD 0.147.0 REPEATS 3/3 DECODED HOSTS 5 PLATFORM macOS 26.2 arm64 (Darwin 25.2.0)

Exact official npm native binary, fresh CODEX_HOME and workspace, ignored user config and rules, ephemeral read-only run, fixed prompt, deliberately invalid API key, up to a 45-second observation window. Authentication failed as designed.

RELEASE CHANGE · 0.146.0 → 0.147.0

Not comparable across this protocol change.

The previous build used 1.0.0-legacy-response-only; this build uses 2.0.0 with a fixed window and request-time capture. Showing a version delta would mix tool behavior with measurement changes.

default

Documented defaults

RUNS
3/3
REQUESTS
20 · 20 · 20
DestinationRouteObservedCountsClass
api.github.comGitHub GET /repos/openai/plugins OBSERVED 1 / 1 / 1 third party
api.github.comGitHub GET /repos/openai/plugins/git/ref/heads/main OBSERVED 1 / 1 / 1 third party
api.github.comGitHub GET /repos/openai/plugins/zipball/:opaque OBSERVED 1 / 1 / 1 third party
api.openai.comOpenAI GET /v1/responses OBSERVED 7 / 7 / 7 first party
api.openai.comOpenAI POST /v1/responses OBSERVED 6 / 6 / 6 first party
chatgpt.comOpenAI GET /backend-api/plugins/export/curated OBSERVED 1 / 1 / 1 first party
chatgpt.comOpenAI GET /backend-api/plugins/featured OBSERVED 1 / 1 / 1 first party
codeload.github.comGitHub GET /openai/plugins/legacy.zip/:opaque OBSERVED 1 / 1 / 1 third party
files.openai.comOpenAI GET /content OBSERVED 1 / 1 / 1 first party

WHAT THIS SUPPORTS

The final batch contacted OpenAI API/ChatGPT/file hosts plus GitHub API and codeload in 3/3 runs. A prior same-version validation batch observed the curated-plugin and files.openai.com routes in only 1/3 runs, so those routes are explicitly variable across batches, not universal.

WHAT IT DOES NOT SUPPORT

  1. The API key was intentionally invalid, so no successful model response or tool execution occurred.
  2. The final evidence uses macOS arm64 and one network path behind the operator's existing VPN.
  3. Two routes reproduced 3/3 in the final batch but only 1/3 in a prior same-version validation batch; they are variable across batches.
  4. The process exited on authentication failure before the 45-second ceiling in all final runs.
  5. Host contact does not establish payload purpose, server retention, training use or privacy impact.

EVIDENCE CHAIN

Hashes identify the private raw captures and public sanitized manifests.

Raw captures are withheld because they contain request and response bodies. Sanitized manifests contain route facts only.

Binary SHA-25619c4f144c5226a9f17c58e6f0fa854843b0f77a6eb420f40e2745a12f10f5d37
Raw capture SHA-256ef8618eb79666075ff208acfcd76e838a470e80fa89c8ad606b855e5726a6239 3d716d7656f2a87677c7f75a1fa4cdeb50ce586f7e42cafb12b71bdb6a71f93b 3439cdd288c8b3f9dc5d157894c5a35ca9b515d1e42b4321574091d5278b2f0a
Sanitized manifest SHA-25669052b8fa700b1d5c8f2f43f9b3be053d4796aa910ccc970c6e395e0bd378a42 9e68b2ed6dbed5875ee0d1046a15cc3fbd4adeba715f81ee185a17178ed66672 22d453bb7529e20e07dba7a1f1f136f7d7d3259d47152ac3eb8c08f6f7238810
Open public sanitized runsRUN 1 RUN 2 RUN 3

OPEN MACHINE-READABLE MANIFEST