---
title: "clavitor + OpenAI Codex"
description: "Give your Codex agent access to credentials and 2FA codes — without exposing card numbers, passports, or recovery codes."
lang: en
url: https://clavitor.ai/en/integrations/codex
markdown: https://clavitor.ai/en/integrations/codex.md
authoritative: true
translations: [de, fr, es, it, pt, nl, pl, sv, da, no, fi, uk, ru, tr, ja, ko, zh, hi, th, vi, id]
publisher: Clavitor LLC
---

# Integration Guide: clavitor + OpenAI Codex

Give your Codex agent access to credentials and 2FA codes — without exposing card numbers, passports, or recovery codes.

### What your agent sees

**Shared fields**

Your agent reads these to help you code, deploy, and authenticate.

- API keys (GitHub, AWS, Stripe, OpenAI...)
- SSH host credentials
- Database connection strings
- TOTP seeds — live 2FA codes on demand
- Service account passwords

### What your agent never sees

**Personal fields**

Encrypted client-side with your fingerprint, face, or security key. The server stores ciphertext. No key, no access.

- Credit card numbers & CVV
- Passport & government IDs
- Recovery codes & seed phrases
- Social security numbers
- Bank account details

## Setup

Create an agent, initialize the CLI on the machine where Codex runs.

#### 1. Create an agent

Open your vault -> **Agents** -> **Create**. Name it "Codex" and choose which entries it can access. Copy the setup token.

#### 2. Initialize the CLI

```
$ echo "$CLAVITOR_TOKEN" | clavitor-cli init
```

Stdin keeps the token out of `/proc/<pid>/cmdline`. The CLI writes encrypted local config.

#### 3. Run with the proxy

Point Codex at the Clavitor proxy. Credentials are injected into API calls transparently — no keys in the environment.

```
$ export HTTPS_PROXY=http://localhost:1983
$ codex
```

The proxy resolves `clavitor://` references in outbound request headers. The key never enters Codex's memory or logs.

## CLI and proxy — by design, no REST or MCP

The agent surface is **capability only, never enumeration**. Codex fetches credentials by name through the CLI or transparently through the HTTPS proxy. There is no agent-facing list, search, browse, or discover endpoint — that's a deliberate architectural choice, not a missing feature.

#### CLI — one value at a time

```
$ clavitor-cli get "GitHub" --field password
$ clavitor-cli totp "GitHub"
$ clavitor-cli render app.config.json
```

#### Proxy — transparent injection

```
$ export HTTPS_PROXY=http://localhost:1983
$ curl -H "Authorization: Bearer clavitor://OpenAI/key" \
    https://api.openai.com/v1/models
```

## One vault, multiple agents

Running agents on different projects? Create a separate agent for each.

#### Work agent

Scoped to GitHub, AWS, Jira, and Slack credentials

#### Personal agent

Scoped to email, social media, and cloud storage

#### Deploy agent

Scoped to SSH keys, database creds, and API tokens

## Every access is logged

The audit log records which agent accessed which credential, when, and from where.

```
# TIME                 ACTION  ENTRY               ACTOR

2026-03-08 10:23:14  read    github.com          cli:codex
2026-03-08 10:23:15  totp    github.com          cli:codex
2026-03-08 11:45:02  read    openai-prod         proxy:codex
2026-03-08 14:12:33  read    aws-production      cli:deploy-agent
```

## Get started

[Start free](https://clavitor.ai/en/checkout)
[See plans](https://clavitor.ai/en/pricing)
