# Monitor OpenAI Codex CLI Network Access on Mac with FireAI > OpenAI’s Codex CLI runs commands in a macOS Seatbelt sandbox with network off by default. What the docs say about sandbox modes and approvals, and how FireAI flags a new destination. FireAI Security & Research Team (HisnLabs) · Published 2026-10-04 Canonical: https://hisnlabs.com/en/blog/monitor-openai-codex-cli-network-mac-fireai Codex CLI is a coding agent from OpenAI that runs in your terminal. It reads a project, proposes changes and runs commands, and OpenAI documents a two-layer security model for it that combines a sandbox with approval policies. This article summarises that model as it applies to macOS, explains what it does and does not say about network traffic, and shows how FireAI watches the program. ## What Codex CLI is and how it is installed The project’s repository describes Codex CLI as a lightweight coding agent that runs in your terminal, made by OpenAI and licensed under Apache-2.0. It lists three install routes: `npm install -g @openai/codex`, `brew install --cask codex`, and a direct download through a shell script or the GitHub Releases page. It runs on macOS for both Apple Silicon and Intel, as well as Linux and Windows. *Terminal* ```console # the documented install routes $ npm install -g @openai/codex $ brew install --cask codex ``` ## The documented sandbox and approval model OpenAI’s agent approvals and security page describes sandbox modes and approval policies working together, and notes that neither alone provides complete protection. The sandbox modes are read-only, workspace-write and danger-full-access. In read-only, actions outside a restricted boundary need approval. In workspace-write, Codex can read, edit and run commands in the active workspace, while network access and edits outside it need approval. Danger-full-access removes the restrictions and is not recommended. The approval policies include on-request, the standard interactive mode; never, which disables approval prompts while keeping the sandbox constraints; and granular, which is selectively interactive for specific categories of action. ## Network access in the sandbox According to the same page, network connectivity is disabled by default. To enable it in workspace-write mode you set `network_access = true` under `[sandbox_workspace_write]` in the configuration file, and an optional `network_proxy` feature can constrain traffic to configured domain allowlists. On macOS, enforcement uses Seatbelt policies through `sandbox-exec`; on Linux it uses `bwrap` plus `seccomp`. *config.toml* ```toml [sandbox_workspace_write] network_access = true ``` This setting governs commands that run inside the sandbox. It is a useful limit, and it is worth stating what it is not: it is not a log of connections, and the agent’s own connection to a model service is a separate matter. This article does not list Codex’s own domains, because the pages reviewed here do not give a vendor-documented list. ## Why a network view still helps If you switch network access on to let tests download dependencies, or use danger-full-access, the sandbox no longer limits where commands connect. At that point a view of the destinations the program actually reached is the remaining check. It also covers the case in which you forgot you had changed the setting. > Codex keeps its own sandbox network off by default. FireAI watches the rest of the picture. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Watching Codex with FireAI FireAI is a firewall for macOS made by HisnLabs, and since version 1.0.2 it has a feature called [Agent profile](https://hisnlabs.com/en/docs/agent-profile). It recognises 19 AI agents, learns where each one normally connects, and flags unusual behaviour for you to review. Codex is a command-line agent, so FireAI recognises it by the name of its program. Codex is matched by the name of its program, codex, which means FireAI labels the match and does not verify it against a developer signature. Only Claude Code, Claude and Cursor are checked that way. FireAI also recognises the agent’s child processes, such as a shell, git or curl that the agent runs, by walking up the process’s parents until it reaches the agent. Those connections are therefore counted as the agent’s own. ## What FireAI flags 1. For the first 3 days FireAI learns the destinations the agent normally contacts, grouped by domain. Nothing is flagged during this learning period. 2. After that, a first-ever destination outside the learned baseline is flagged for review. 3. An upload spike is flagged too: an hour in which the agent sent at least 4 times its busiest hour so far, and never less than 25 MB. Agent profile uses only metadata, meaning host names and byte counts. FireAI never reads the payload of a connection, and it cannot read inside an encrypted one. ## Set it up for Codex 1. Install FireAI and finish the setup, then keep using Codex as you normally do. The 3-day learning period starts from what FireAI sees. 2. Open Suggestions and look at the AI agents card. It lists the agents FireAI has recognised and what it has learned about each. 3. When Codex reaches a destination it has never contacted, the flag appears in the AI agents card and in [Quick Review](https://hisnlabs.com/en/docs/quick-review-suggestions). Swipe left to block, or right for “It’s fine”. 4. Block creates a rule for the process that connected. “It’s fine” adds the destination to the agent’s baseline so it is not flagged again. 5. If you want the agent kept to the places it already uses, choose Agent profile in the security mode menu, next to Home, Coffee shop, Paranoid and Under attack. Once the agent has finished learning, a connection to a destination outside its baseline is blocked instead of flagged. 6. A blocked destination shows in the AI agents card with Allow and Keep blocked. Allow adds it to the baseline and the agent can reach it right away. Keep blocked creates a block rule, so the destination stays blocked in every mode. > **Note:** The Agent profile security mode arrived in FireAI 1.0.3. While an agent is still learning nothing is blocked, and upload spikes are flagged, not blocked. An allow rule you wrote yourself for a website, domain or address still wins, and DNS and your local network are never blocked. > Want to see where Codex connects on your Mac? FireAI is free to try. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## Limits - FireAI does not prevent prompt injection. A prompt hidden in a web page or a file can still steer an agent. What FireAI can do is flag, and let you block, the path data would take out of your Mac. - FireAI cannot see prompts, the contents of MCP tools, or which files Codex reads, such as ~/.ssh. TLS hides the payload, and FireAI is not inside the agent. - Child processes that exit very quickly may be missed, and child processes are matched by path, not by signature. - During the 3-day learning period nothing is flagged. - In the Agent profile mode, a connection to a bare IP address with no host name is matched by its address. If a service the agent normally uses answers from a new address, it is blocked until you allow it. - FireAI’s plain-words explanation of a flag is written from facts it measured. It never says a destination is safe or dangerous. The decision is yours. ## Related guides The same approach applies to the other agents FireAI recognises: [Claude Code](https://hisnlabs.com/en/blog/monitor-claude-code-network-mac-fireai), [the Claude desktop app](https://hisnlabs.com/en/blog/monitor-claude-desktop-app-network-mac-fireai), [Cursor](https://hisnlabs.com/en/blog/monitor-cursor-network-mac-fireai), [the ChatGPT Mac app](https://hisnlabs.com/en/blog/monitor-chatgpt-mac-app-network-fireai), [OpenClaw](https://hisnlabs.com/en/blog/monitor-openclaw-network-mac-fireai), [Hermes Agent](https://hisnlabs.com/en/blog/monitor-hermes-agent-network-mac-fireai), [Gemini CLI](https://hisnlabs.com/en/blog/monitor-gemini-cli-network-mac-fireai), [GitHub Copilot CLI](https://hisnlabs.com/en/blog/monitor-github-copilot-cli-network-mac-fireai), [Amp](https://hisnlabs.com/en/blog/monitor-amp-agent-network-mac-fireai), [Qwen Code](https://hisnlabs.com/en/blog/monitor-qwen-code-network-mac-fireai), [opencode](https://hisnlabs.com/en/blog/monitor-opencode-network-mac-fireai), [Aider](https://hisnlabs.com/en/blog/monitor-aider-network-mac-fireai), [Goose](https://hisnlabs.com/en/blog/monitor-goose-agent-network-mac-fireai), [Crush](https://hisnlabs.com/en/blog/monitor-crush-agent-network-mac-fireai), [Windsurf](https://hisnlabs.com/en/blog/monitor-windsurf-network-mac-fireai), [Kiro](https://hisnlabs.com/en/blog/monitor-kiro-network-mac-fireai), [Trae](https://hisnlabs.com/en/blog/monitor-trae-network-mac-fireai), [Muse from Meta](https://hisnlabs.com/en/blog/monitor-muse-meta-network-mac-fireai), [any other AI agent run by Python or Node](https://hisnlabs.com/en/blog/monitor-any-ai-agent-mac-python-node-fireai). The full feature description is in the [Agent profile documentation](https://hisnlabs.com/en/docs/agent-profile). > FireAI is built by HisnLabs and runs on your Mac, with no cloud account. Download it and see which destinations your agents have contacted. [Download FireAI for Mac](https://hisnlabs.com/en/download) ## How FireAI and HisnLabs fit in Codex keeps its own sandbox network off by default. FireAI watches the rest of the picture. FireAI is HisnLabs’ own product: an on-device AI firewall for Mac. It shows every connection your apps make, in plain language, and lets you decide what leaves your Mac — its AI runs locally, so your traffic is never sent to us or anyone else. HisnLabs’ security research team is the group that keeps that decision-making accurate: cataloguing which domains are ordinary telemetry versus a real product, tracking the country and network behind a connection, and training the on-device model (its FireAI Pilot feature) on real traffic patterns, all without any of it leaving your Mac. You can read the technical decisions behind it, or try FireAI for 17 days, at [FireAI, by HisnLabs](https://hisnlabs.com/en/download). ## Sources - [OpenAI Codex: repository and README (GitHub)](https://github.com/openai/codex) - [OpenAI Codex documentation: Agent approvals and security](https://developers.openai.com/codex/agent-approvals-security) - [OpenAI Codex documentation: Security](https://developers.openai.com/codex/security) - [FireAI docs: Agent profile](https://hisnlabs.com/en/docs/agent-profile) - [FireAI docs: Quick Review and Suggestions](https://hisnlabs.com/en/docs/quick-review-suggestions) - [FireAI docs: Security modes](https://hisnlabs.com/en/docs/security-modes)