Codex managed agents are the shape most people now expect OpenAI to unveil at DevDay on 29 September 2026: one place to write an agent, one button to put it into production, and the coding harness developers already have open as the front door. It is a tidy story. It is also, on the published record, an inference rather than a report.

The single source behind the current wave of coverage is a codebase reading published by TestingCatalog on 7 September 2026. Its body runs to 405 words. The word “Codex” appears in it zero times. What it describes is an agents interface — agents, environments, skills and plugins — that is explicitly “not available yet”. The jump from that to a Codex managed agent pipeline is something readers have supplied, not something OpenAI or the report has said. Teams that already budget separately for AI models and AI agents will recognise why the distinction matters.

That gap is worth measuring rather than asserting, so this article counts it. We took eight published pages from OpenAI and AWS, and looked for a single sentence that puts the two things together as a build-and-deploy path. This piece is the spoke on the Codex question, off our earlier coverage of the DevDay Managed Agents leak itself and of where those agents would actually execute.

What the Codex Managed Agent Story Actually Says

codex managed agents build deploy b magnifying glass round rim straight handle

The report everyone is citing

Every current write-up traces back to one article: Alexey Shabanov’s 7 September 2026 piece for TestingCatalog, reporting that OpenAI is preparing an implementation of Managed Agents that “broadly follows what Anthropic currently offers”. It is a codebase reading, not a briefing, and it says so. The value is in what strings exist in shipped code, not in what a product manager promised.

Four hundred and five words, and none of them is Codex

The body of that report is 405 words long. It uses “Managed Agents” once and “managed agent” twice. It mentions DevDay three times and Anthropic three times. It mentions Codex exactly zero times. Any article describing a Codex managed agent as reported is adding a product name the source never used. That is the first thing to be clear about before a procurement conversation starts. This is not cloud computing folklore; it is a countable property of a public document.

What the codebase reading does describe

The report describes four things found in the code: creating different agents, creating environments, managing them, and enabling specific skills and plugins. It adds that access to the agents UI is not available yet. Separately it reports work on ads in ChatGPT resolving directly to an agent, which it flags as speculation worth watching. None of those four nouns is tied to a surface, and a surface is precisely what “via Codex” claims.

Where “via Codex” comes from

The inference is reasonable. Codex is the OpenAI product that already runs long, unattended work, already has skills, and already has plugins. If you read “skills and plugins” in a leak and then open the Codex documentation, you find both words. That vocabulary overlap is the strongest argument for the Codex managed agent reading, and it is dealt with honestly further down. It is an argument from coincidence of naming, not from a published roadmap.

What OpenAI Already Shipped Under Both Names

codex managed agents build deploy c two thick cubes standing side by side

Codex on Amazon Bedrock

On 28 April 2026 OpenAI and AWS announced an expanded partnership with three offerings, all in limited preview. One was Codex on Amazon Bedrock. OpenAI’s own page calls Codex “OpenAI’s frontier coding harness and product suite”, and says customers get started by configuring Codex to use Bedrock as the provider, starting with the Codex CLI, the Codex desktop app and the Visual Studio Code extension. Usage can be applied toward existing AWS cloud commitments.

Bedrock Managed Agents, powered by OpenAI

The second relevant offering that day was Amazon Bedrock Managed Agents, powered by OpenAI. AWS describes it as built with the OpenAI harness, with every agent carrying its own identity, logging each action, and running in your environment with all inference on Amazon Bedrock. Amazon Bedrock AgentCore provides the default compute environment. A managed-agent product bearing OpenAI’s name has therefore existed since April — just not on openai.com, and not inside Codex.

Three offerings, one day, one announcement

The detail that matters for the Codex managed agent question is structural. OpenAI models, Codex and Managed Agents were announced together and described separately. They share a press release and a cloud, not a workflow. Nothing in either announcement says you build the managed agent inside Codex, and nothing says the Codex harness deploys one.

Offering (28 April 2026)What it isNamed surfacesStatus
OpenAI models on BedrockFrontier models incl. GPT‑5.5Bedrock APILimited preview
Codex on BedrockCoding harness and product suiteCodex CLI, desktop app, VS Code extensionLimited preview
Bedrock Managed AgentsDeployment runtime for OpenAI agentsAgentCore default computeLimited preview
A Codex managed agent pathBuild and deploy in one surfaceNone publishedNot announced
codex managed agents build deploy d upright toolbox with curved carry handle

The method

We took eight published pages — five from openai.com, two from aws.amazon.com, and the Codex product page — extracted the body text of each, and counted three things: occurrences of “Codex”, occurrences of “Managed Agent” or “Managed Agents”, and sentences containing both. The eight pages carry 5,426 words of body text between them. The method is crude on purpose, because a crude count is reproducible.

The result

Across those 5,426 words, “Codex” appears 86 times and “Managed Agents” 20 times. Both terms appear in the same sentence 4 times. That is the entire documented overlap between the two products, and it is smaller than the Codex managed agent narrative implies.

Published pageWords“Codex”“Managed Agents”Both in one sentence
Work with Codex from anywhere1,0113000
Gartner coding-agents Leader6431900
Codex product page4361800
OpenAI models, Codex and Managed Agents come to AWS6561272
AWS What’s New (Bedrock)295642
The next evolution of the Agents SDK1,112110
Bedrock Managed Agents, powered by OpenAI345080
Introducing AgentKit928000
Total5,42686204

Codex is discussed heavily, and never as a deployment surface

The Codex mentions cluster exactly where you would expect: the mobile and Remote SSH announcement, the Gartner post, and the product page. Those three pages carry 67 of the 86 mentions between them and 0 mentions of Managed Agents.

Bars below scale each page’s Codex count against the highest, 30 on the mobile announcement.

Mentions of “Codex” per published page, scaled against 30
Work with Codex from anywhere — 30
Gartner coding-agents Leader — 19
Codex product page — 18
OpenAI on AWS — 12
AWS What’s New — 6
Agents SDK evolution — 1

All four co-occurrences are the same list

This is the finding that decides the question. Of the 4 sentences containing both terms, 4 are the same construction: “OpenAI models, Codex, and Managed Agents”. Two are headlines and two are summary sentences, on the two AWS partnership pages. In every case Codex and Managed Agents are separated by a comma in a list of three products. Not one of the 4 describes building an agent in Codex, deploying an agent from Codex, or a Codex managed agent of any kind. The number of sentences connecting them as a workflow is 0.

Bars below scale each count against the 86 Codex mentions.

What the 8-page corpus actually contains, scaled against 86
Mentions of “Codex” — 86
Mentions of “Managed Agents” — 20
Sentences containing both — 4
Sentences linking them as build-and-deploy — 0

Why a Codex Managed Agent Is Still a Reasonable Guess

codex managed agents build deploy e tall filing folder standing upright with tab

The vocabulary matches

The honest counter-argument is strong. The leak names skills and plugins. Codex has Skills, which the product page describes as teaching Codex “your team’s standards, workflows, and ways of working”, and it has plugins, which appear in the mobile announcement alongside threads and approvals. Two of the four leaked nouns are live Codex features today. That is not proof, but it is not nothing either.

Codex already runs long, unattended work

The second argument is behavioural. Codex is already scheduled for “always-on background work” such as issue triage, alert monitoring and CI/CD. It already runs in cloud environments and worktrees, in parallel, across projects. An agent runtime needs exactly those properties, and building a second one beside Codex would be duplicated engineering.

Codex already has the enterprise surface

The third is commercial. Gartner named OpenAI a Leader in its Magic Quadrant for Enterprise AI Coding Agents, in a report dated 20 May 2026, citing approval gates, RBAC, customisable policies, OS-level sandboxing and auditable workspace governance. Codex has more than 4 million weekly users and, in OpenAI’s words, is “one of OpenAI’s fastest-growing enterprise products”. Those governance controls are the hard part of shipping a managed agent to an enterprise.

Leaked conceptExists in Codex today?Published evidence
SkillsYesCodex product page
PluginsYesCodex mobile announcement
EnvironmentsPartlyCloud environments, Remote SSH
Agents you create and manageNot publishedAgents UI “not available yet”
Deploying an agent to end usersNoNo page describes it

Where OpenAI's Own Succession Plan Points Instead

codex managed agents build deploy f calendar block standing upright blank face

AgentKit’s wind-down names two successors

There is one place where OpenAI has written down what replaces its agent-building tooling, and it is not a rumour. The AgentKit announcement page carries an update dated 3 June 2026: Agent Builder and Evals will no longer be available on the OpenAI platform from 30 November 2026. For workflows that should continue as code, OpenAI recommends the Agents SDK. For use cases better suited to natural language prompting, it recommends Workspace Agents in ChatGPT.

Neither successor is Codex

That is OpenAI’s own migration guidance for the exact audience a Codex managed agent would serve, published on its own site, and it names two products. Codex is not one of them. A buyer planning around the November deadline is being pointed at the Agents SDK and Workspace Agents, and should plan around those until a keynote says otherwise.

Bars below count days from the 28 April 2026 AWS announcement, scaled against the 216 days to the AgentKit deadline.

Days from 28 April 2026, scaled against 216
To the TestingCatalog report, 7 Sep 2026 — 132 days
To DevDay, 29 Sep 2026 — 154 days
To the AgentKit wind-down, 30 Nov 2026 — 216 days

The Agents SDK Sentence That Cuts Against a Codex Managed Agent

What OpenAI wrote in April

The Agents SDK announcement contains a sentence that reads very differently now. Listing the tradeoffs teams hit moving from prototype to production, OpenAI wrote that “managed agent APIs can simplify deployment but constrain where agents run and how they access sensitive data”. That is OpenAI naming the drawback of the category it is now reported to be entering.

Why that is not a contradiction

It is a design constraint, not a reversal. The same page separates harness from compute, on the premise that “agent systems should be designed assuming prompt-injection and exfiltration attempts”, and lets developers bring their own sandbox. A Codex managed agent that inherited that separation would answer OpenAI’s own objection. One that did not would fail it in public.

What it implies for the keynote

So the useful question on 29 September is not whether managed agents appear. It is whether the announcement says where the agent runs and how it reaches sensitive data. If the keynote is silent on both, OpenAI has shipped the thing it criticised five months earlier, and the criticism is on its own website in its own words.

What a Codex Managed Agent Would Have to Run On

Seven sandbox providers and four storage backends

The Agents SDK already ships the execution layer such a product would need. Developers can bring their own sandbox or use built-in support for seven providers — Blaxel, Cloudflare, Daytona, E2B, Modal, Runloop and Vercel — and a Manifest abstraction describes the workspace so it stays portable. Data can be mounted from four storage backends: AWS S3, Google Cloud Storage, Azure Blob Storage and Cloudflare R2.

Durability is already solved in the SDK

Because agent state is externalised, losing a sandbox container does not lose the run. The SDK snapshots and rehydrates, restoring state in a fresh container and continuing from the last checkpoint. Any Codex managed agent worth buying needs that property, and OpenAI has already generally released it under standard API pricing, in Python, with TypeScript support planned.

AgentCore on the AWS side

On Bedrock the equivalent layer is AgentCore, which AWS names as the default compute environment for Managed Agents, adding authorisation policy enforcement, agent and tool discovery, observability and evaluation as an estate grows. Two runtimes therefore already exist for OpenAI agents. Neither is Codex.

The Codex Managed Agent Price Nobody Has Published

What is priced today

The Agents SDK capabilities are generally available at standard API pricing, based on tokens and tool use. Codex is sold through ChatGPT plans and, on Bedrock, can be drawn against an existing AWS commitment. Those are real, checkable commercial terms.

What is not

There is no published price for Bedrock Managed Agents, which remains in limited preview, and there is obviously no published price for a Codex managed agent that has not been announced. TestingCatalog’s report raises the pricing question directly, calling it “a major question” whether OpenAI can hit a price point that makes its offering more attractive, and notes many users still rely on cheaper alternatives.

Why the gap matters

A managed runtime is billed differently from a coding seat. Seats are per-user and predictable; agent runtimes bill on execution, which scales with usage you do not control. Anyone budgeting for a Codex managed agent on the assumption that it extends a Codex subscription is guessing at the most expensive variable in the deal.

What Enterprise Buyers Should Do About Codex Managed Agents Before DevDay

Separate the two purchases

Treat the coding harness and the agent runtime as two line items, because that is how OpenAI and AWS have shipped them. A Codex rollout justified on developer productivity should not carry an unpriced agent runtime inside its business case.

Ask the residency question early

Bedrock Managed Agents leads with residency: all inference on Amazon Bedrock, every agent with its own identity, every action logged. If OpenAI announces a first-party equivalent, the comparable questions are where execution happens, which credentials the sandbox holds, and what is retained. Those answers determine whether the product clears your review at all.

Keep the AgentKit deadline on the plan

Agent Builder and Evals stop being available on 30 November 2026, which is 62 days after DevDay. Any team still on those tools has a migration to run regardless of what is announced, and OpenAI’s published advice today is the Agents SDK or Workspace Agents.

ClaimStatusSource
OpenAI is building Managed AgentsReported (codebase reading)TestingCatalog, 7 Sep 2026
Agents, environments, skills, plugins in the codeReportedTestingCatalog, 7 Sep 2026
A managed-agent product with OpenAI’s name existsConfirmedAWS, 28 Apr 2026
Agent Builder and Evals end 30 Nov 2026Confirmedopenai.com, 3 Jun 2026
Codex is the build-and-deploy surface for themInferred onlyNo published source
Price of any managed tierUnpublished—

Codex Managed Agent Claims to Put in Writing

Three questions for the account team

Ask them in this order, and keep the answers. First: is the managed agent runtime billed separately from Codex seats, and on what unit? Second: where does agent code execute, and does the harness hold the credentials the sandbox uses? Third: what is the supported migration path from Agent Builder before 30 November 2026, in writing, naming a product.

Why writing matters here

The Codex managed agent story is currently one 405-word codebase reading, amplified. That is a legitimate signal about engineering direction and a poor basis for a purchase order. A vendor happy to confirm the story verbally may be unwilling to confirm it in a contract, and the difference is the whole risk.

What Would Confirm the Codex Managed Agent Plan

The signals to watch on 29 September

DevDay runs on Tuesday 29 September 2026 at Fort Mason in San Francisco, with the keynote at 10:00 a.m. Pacific. Three things would turn the inference into fact: an agents UI reachable from a Codex surface, a published price or billing unit for the runtime, and a statement about where execution happens. A demo alone confirms none of them.

The signals that would refute it

Equally, a managed agent announced only inside the API and the Agents SDK, with Codex left as a coding harness, would match every published page and end the Codex managed agent reading. So would an announcement that routes enterprise deployment through Bedrock, where a managed-agent product already exists in limited preview with AgentCore beneath it.

What we will do

We will re-count after the keynote. The 8-page corpus, the 86 and 20 mentions and the 4 list-only co-occurrences are a baseline, and the honest version of this story is whether that baseline moves on the day. Until it does, “OpenAI plans to build and deploy managed agents via Codex” is a plausible reading of a leak that never says Codex.

References