Codex Dispatch Gateway Checklist: Programmatic Tokens, SSH Egress, and CI Routing
A Codex dispatch gateway checklist for enterprise teams using programmatic access tokens, Remote SSH, and CI agents: route devbox egress, separate token ledgers, and catch background-agent spend before it becomes invisible.
Archive item produced with AI assistance from the cited source and published without individual review. Editor of record: Joe Werner.

The assumption baked into most AI API gateway deployments is that a developer is present: they open their editor, fire off a request, and the model responds. That assumption is quietly being dismantled. OpenAI's latest Codex update—mobile app access, Remote SSH generally available, programmatic access tokens, and hooks—shifts the coding agent from a keyboard-local tool to something closer to a background infrastructure process. For teams that route AI traffic through a gateway, this changes where you place the gateway, how you scope credentials, and what your token-budget planning needs to look like.
What happened
On May 14, 2026, OpenAI shipped a cluster of Codex capabilities under one announcement:
- Codex in the ChatGPT mobile app: A fully-featured remote experience that connects to any machine where the Codex desktop app is running—laptop, dedicated Mac mini, or managed remote environment. Developers can start threads, approve commands, review diffs, and change models from their phone, while execution stays on the original machine. A secure relay layer (not direct port forwarding) keeps those machines reachable without public internet exposure.
- Remote SSH now generally available: Codex can connect directly into enterprise-managed environments via the SSH configuration on the developer's desktop. Projects and threads run inside those remote machines; credentials, policies, and compute stay where the organization controls them.
- Programmatic access tokens: Scoped credentials issued from ChatGPT workspace settings, purpose-built for CI pipelines, release workflows, and automation. These are not the user's personal session token—they are workspace-issued, revokable, and scopable.
- Hooks generally available: Repository-scoped and directory-scoped behaviors that run on Codex events—scan prompts for secrets, run validators, log conversations, inject memory, or customize Codex behavior per repo.
- HIPAA-compliant local operation: Eligible ChatGPT Enterprise workspaces can use Codex locally (CLI, IDE, app) for healthcare workflows.
The "Locked Use" feature announced the week prior (allowing Codex to operate Mac apps while the screen is locked) is the same architectural shift at the desktop level: the agent is decoupled from the user's presence.
Why it matters for AI engineering teams
The execution model is no longer tied to a session. Until now, most Codex usage happened in short, interactive loops: developer writes a prompt, agent acts, developer reviews. The new model enables Codex to run across multiple threads over hours, with human input flowing in asynchronously from any device. This changes the cost profile of a single "task": what was previously a 5-minute interactive session can now be a 2-hour background job with intermittent human touchpoints.
Access tokens change the threat surface at the API layer. Programmatic access tokens issued for CI pipelines are a materially different credential type than developer session tokens. They are scoped to a workspace but can be used non-interactively. If your team routes Codex API traffic through a gateway for visibility or budget control, these tokens introduce a new credential lifecycle to track: issuance, scope, rotation, and revocation all need governance that a gateway is well-positioned to log.
Hooks are the first official extensibility surface between agent and policy. Hooks let organizations intercept and influence Codex behavior at the repo or directory level—before prompts leave the developer's machine, in theory. For enterprise governance teams, this is significant: rather than hoping the model declines a sensitive action, you can assert a hook-level validator. However, hooks run locally on the developer's machine, not at the API gateway level, so they are not a substitute for network-layer observability.
Remote SSH in managed environments shifts where you need gateway coverage. If developers are routing Codex through a corporate SSH-managed devbox, the API calls may now originate from a shared compute environment rather than individual laptops. That changes the egress IP, the credential surface, and potentially the routing policy: one devbox used by five developers may have different compliance requirements than five independent laptops.
The router/operator angle
Token budget planning needs a long-horizon model. When Codex runs as a background process across a two-hour task with human interruptions, total token consumption is spread across many small exchanges—approvals, redirections, context refreshes—rather than one large generation. At scale, this flattens your peak-to-trough traffic variance but increases sustained baseline load. Routing policies that were tuned for bursty short sessions may underprovision for persistent low-traffic background agents.
Credential scoping is now a first-class routing concern. Programmatic access tokens for CI use cases carry a different risk profile than interactive developer tokens. If you're using a gateway to mediate Codex API traffic, you should track token type in your request ledger: which requests originated from a scoped CI token vs. an interactive session token. This isn't about blocking—it's about auditability and anomaly detection.
Hooks are local; your gateway sees the network. The two observability layers are complementary, not interchangeable. Hooks give policy enforcement at the edge (repo-level, pre-network). A routing gateway captures everything that makes it to the API. For enterprise teams, the right posture is: hooks for prompt-level guardrails, gateway logging for network-level audit trail. Neither replaces the other.
Remote SSH + relay layer introduces a new egress topology. If your AI governance policy ties compliance posture to egress origin (as many enterprise network policies do), you should verify that Codex traffic from SSH-connected remote environments is routed through your existing API gateway. The relay is OpenAI-managed; the SSH connection is local; the actual model API calls still go to api.openai.com. Make sure your gateway configuration covers compute environments, not just developer laptops.
Checklist for teams adopting remote Codex dispatch:
- Audit which environments (laptops, Mac minis, devboxes) are being used as Codex hosts and confirm they route outbound AI API traffic through your gateway.
- Configure your gateway to log
chatgpt-enterprise-access-tokencredential patterns separately from interactive user tokens once programmatic tokens appear in your traffic. - Review hooks configuration per repo to understand what pre-flight validation is running locally—and what is not.
- If using Remote SSH, verify that compute node API egress policies match your laptop policies.
- Set token budget alerts for background agent traffic: sustained low-level usage is easier to miss than a spike.
What TheRouter users should watch or try
For teams using TheRouter to route OpenAI-compatible traffic, the Codex remote dispatch model raises a practical question: where is the agent running, and is that origin inside your gateway perimeter?
If you're using TheRouter's provider routing to mediate calls to api.openai.com, ensure that routing rules apply not just to IDE/laptop egress but also to devbox or CI environments where programmatic access tokens will be used. The API endpoint is the same; the origin machine and credential are different.
Watch for programmatic access token patterns in your request logs once your team adopts CI-based Codex automation. Scoped tokens with unusual usage patterns (e.g., high context input with no corresponding output approval) may signal runaway agent loops—worth catching early at the gateway layer.
Source: Work with Codex from anywhere — OpenAI, May 14, 2026.

OpenAI Codex Enterprise Deployment Routing and Governance: Lessons from Samsung's 5M-User Scale
Samsung Electronics is deploying Codex to its entire global workforce — one of OpenAI's largest enterprise launches ever. Here is the routing and governance architecture every operator needs before reaching that scale.

Codex Expands to Every Role: What Six Role Plugins, Sites, and 5 Million Weekly Users Mean for Your AI Routing Architecture
OpenAI Codex now ships six role plugins—analytics, creative, sales, design, investing, banking—plus Sites, a hosted web-app generator. For routing teams, the multi-role shift changes context budgets, tool call patterns, and upstream model requirements.

OpenAI Codex Goes On-Premises: What the Dell Partnership Means for Enterprise AI Routing
OpenAI and Dell are bringing Codex inside enterprise data centers. When your coding agent runs on-prem, the routing architecture changes: data locality, session affinity, cost accounting, and governance controls all need rethinking.