Your key, your box
Codex CLI is Apache 2.0 and runs on your own OpenAI credentials. Self-host the box too and no one else sits between the model and your code.
Codex already sandboxes its commands on your machine. A box goes one step further: the work happens on a different machine, one that keeps its state and holds none of your credentials.
# 1. create a box and write its SSH config
$ containarium create codex-box
$ containarium ssh-config sync
# 2a. register the box's MCP server with Codex
$ codex mcp add codex-box -- ssh codex-box agent-box
# 2b. …or run Codex inside the box itself
$ containarium connect codex-box
shell + file tools, scoped to the box
Blast radius
Codex CLI ships approval modes and an OS-level sandbox, and they're good defaults. But in full-auto the agent is still running on the machine that holds your SSH keys, your cloud credentials, and every other repo you have checked out.
Sandboxed, but on your machine: the same disk, the same network, and a sandbox policy you have to get right for every project. Close the lid and the run stops.
A disposable Linux machine holding one repo. Worst case, you delete it and create another. The run keeps going when your laptop sleeps, and the box is still there tomorrow.
Codex CLI is Apache 2.0 and runs on your own OpenAI credentials. Self-host the box too and no one else sits between the model and your code.
Toolchains, dependency caches and build output survive, so the next session starts where the last one stopped.
Run several Codex sessions in parallel without them sharing ports or package state. We run five agents this way.
Connecting
Codex reads MCP servers from ~/.codex/config.toml. Add a [mcp_servers.codex-box] entry with command = "ssh" and args = ["codex-box", "agent-box"] — or run the codex mcp add line above. Codex gets shell and file tools that act on the box, while Codex itself stays local.
Open a shell with containarium connect codex-box, install Codex there, and run it. Everything it touches lives in the container, and with --session the terminal survives disconnects.
Using another agent? The same box works with Claude Code, Cursor, Cline, Gemini CLI, Aider, Goose, OpenHands, or your own agent. Need a GPU in it? That works too.
FAQ
Create a Containarium box, run containarium ssh-config sync, then register the box's MCP server with codex mcp add codex-box -- ssh codex-box agent-box. Codex then gets shell and file tools that run on the box. Alternatively, SSH into the box and run Codex there.
Yes. Codex restricts what its commands can do on your own machine. A Containarium box is a different layer: the commands run on a separate, disposable Linux machine that holds none of your credentials and keeps its state between sessions.
Yes. A box is a long-lived LXC container or Kubernetes pod, so installed tools, caches and files survive until you delete it.
Yes. Containarium is Apache 2.0 and installs on any Ubuntu VM, so Codex's work can stay inside your own network.
Start free on the hosted cloud, or self-host the open source on your own VM.