How-to · Tools and permissions
Set a Codex sandbox
Choose what every Codex session is allowed to read, write and reach on the network, before it starts.
You want every Codex session to run under a specific sandbox mode, with or without network access, or writing to an extra directory.
- Open Settings and the Codex tab.
- Scroll to Permissions.
- Choose Read only, Workspace write or Full access.
- Check Allow network access to let a session reach the network.
- Type a path and press Add to give every session another writable directory.
- Press an added directory's own remove control to take it back out.
Every change saves the moment you make it. There is no separate save control. The setting applies to every Codex session on this machine, rather than to a single session.
See Settings for what each sandbox mode permits.