OpenAI's Windows Sandbox Solution

OpenAI details its custom-built sandbox for Codex on Windows, overcoming limitations of native tools with an 'elevated' approach for enhanced security.

Diagram illustrating the architecture of OpenAI's Codex Windows sandbox.
A conceptual overview of OpenAI's custom sandbox solution for Codex on Windows.· OpenAI News
Visual TL;DR
Codex on WindowsCore
OpenAI's AI model needing secure execution environment
From the article 6 mentionsOpenAI has detailed its journey in building a secure sandbox environment for its Codex on Windows sandbox, aiming to balance developer productivity with system security.
Native tools inadequateDriver
AppContainer too restrictive, Windows Sandbox lacks file access
From the articleExisting Windows tools like AppContainer and Windows Sandbox proved inadequate for Codex's dynamic, open-ended workflows, which require interacting with user-owned files and tools.
Unelevated sandbox attemptContext
Initial prototype without admin privileges, limited functionality
From the articleOpenAI's initial prototype, the 'unelevated sandbox,' aimed to operate without requiring administrator privileges.
Elevated sandbox solutionCore
More robust approach for enhanced security and access
From the articleRecognizing the limitations, OpenAI pivoted to an 'elevated sandbox' requiring admin privileges during setup.
Developer productivityContext
Balancing security with ability to run tools and access files
From the article 2 mentionsOpenAI has detailed its journey in building a secure sandbox environment for its Codex on Windows sandbox, aiming to balance developer productivity with system security.
Secure executionEffect
Custom-built environment overcoming native tool limitations
From the articleOpenAI has detailed its journey in building a secure sandbox environment for its Codex on Windows sandbox, aiming to balance developer productivity with system security.
System securityEffect
Ensuring safe operation of Codex on user machines
From the article 5 mentionsOpenAI has detailed its journey in building a secure sandbox environment for its Codex on Windows sandbox, aiming to balance developer productivity with system security.
Contents(3)

OpenAI has detailed its journey in building a secure sandbox environment for its Codex on Windows sandbox, aiming to balance developer productivity with system security.

Existing Windows tools like AppContainer and Windows Sandbox proved inadequate for Codex's dynamic, open-ended workflows, which require interacting with user-owned files and tools.

Native Windows Tools Fell Short

AppContainer, while offering strong isolation, is too restrictive for Codex's need to run various developer tools like shells, Git, and package managers.

Windows Sandbox provides a disposable VM, but it doesn't allow Codex to directly access the user's actual project files and environment.

Mandatory Integrity Control (MIC) labeling offered a potential path, but modifying host filesystem integrity at a broad level introduced significant security risks.

The First Attempt: Unelevated Sandbox

OpenAI's initial prototype, the 'unelevated sandbox,' aimed to operate without requiring administrator privileges.

This design used Security Identifiers (SIDs) and write-restricted tokens to control file writes, allowing modifications only within designated areas like the current working directory.

Network access control proved more challenging. The team resorted to environment variable manipulation and stub scripts to redirect or block common network protocols like HTTP(S) and SSH.

However, this approach was largely advisory, easily bypassed by applications not adhering to environment settings or implementing custom network stacks.

Performance issues related to applying file system Access Control Lists (ACLs) and the difficulty in changing sandbox semantics also surfaced.

The Elevated Sandbox: A More Robust Solution

Recognizing the limitations, OpenAI pivoted to an 'elevated sandbox' requiring admin privileges during setup.

This iteration runs child processes under restricted tokens, similar to the unelevated version, but crucially, these tokens are associated with dedicated local user accounts: 'CodexSandboxOffline' and 'CodexSandboxOnline'.

This segregation allows for more precise network control via Windows Firewall rules, targeting specific sandbox instances rather than the general user or specific binaries.

This redesign enables the OpenAI Codex Windows sandbox to offer a safer and more effective experience on Windows, aligning it with capabilities on other operating systems.

© 2026 StartupHub.ai. All rights reserved. You may not republish this article in full without a license. Search engines and AI research tools may crawl and summarize for reference. Bulk reproduction or model training requires a license. See our terms.
Daniel Singer

Written by

Daniel Singer

Editor, StartupHub.ai

Daniel Singer is the editor of StartupHub.ai, a technology expert and thought leader on AI and its applications across sectors, from fintech and healthcare to developer tooling and consumer software. He writes and tests the tools covered here thoroughly and regularly, and built StartupHub.ai to give founders, operators and buyers a clearer read on what they are actually being sold.