Use cases · Codex control plane

Your control planefor Codex.

Connect tools, secure every interaction, distribute access by team, and observe usage and spend. One platform to govern Codex across your engineering org.

Gateway · Policy line

Live
github.create_pull_requestallow ✓
linear.update_issueallow ✓
sentry.list_issuesallow ✓
AWS key detected in diffblock · secret
notion.searchallow ✓

489

Sessions

4,412

Tool calls

12

Blocked

Trusted byVerizonMistralCloudinaryLaunchDarklyFivetranPlanetScale

01 · The problem

Codex adoption is outpacing engineering control

Without a control plane
How does it roll out?
Developers wire Codex to their own MCP servers and paste in their own keys. No central place to approve tools or give every engineer the same vetted setup
Who sees the usage?
Once Codex is connected, no shared view of which repos, APIs, and data it touches, what actions it runs, or who is running them
What does it cost?
Token spend climbs across teams with no budgets or limits. Costs surface on the invoice, long after the runs that drove them
On the control plane
How does it roll out?
One vetted catalog of MCP servers, provisioned team by team through your IdP
Who sees the usage?
Every session, tool call, and permission change in one searchable audit trail
What does it cost?
Budgets per team, enforced in real time, with every token attributed to a named engineer

The MCP server we built using Speakeasy just works. It made becoming AI-native much simpler than we expected.

Constantine Nathanson

Staff Software Engineer, Cloudinary

Cloudinary

02 · The control plane

Build your control plane for Codex

Speakeasy sits between Codex and every system it touches. Connect tools, secure every interaction, distribute access by team, and observe usage and spend from one platform.

Works with every identity providerOktaMicrosoft Entra IDAuth0WorkOSGoogle WorkspacePing IdentityAny SAML / OIDC

Every agent

One control plane for every agent

Teams rarely settle on a single agent. The same rollout, oversight, and cost controls apply across Anthropic, OpenAI, Google, and the agents your teams build themselves.

Anthropic
OpenAIThis page
GoogleCursor
GitHub Copilot
OpenCode
Devin
Custom agents

Speakeasy was critical in launching our MCP server. Now we're giving agents the ability to feature flag their releases.

Benjamin Woskow

LaunchDarkly

LaunchDarkly

Questions

What does a control plane for Codex do?
It sits between Codex and every system it touches, so the whole organization runs through one governed path. From a single platform you connect tools, secure every interaction, distribute access by team, and observe usage and spend. Codex usage scales without trading speed for safety.
How does Speakeasy connect Codex to enterprise systems?
Speakeasy provisions MCP servers for every tool and system Codex needs to reach. Pre-built connectors cover common SaaS like GitHub, Linear, and Sentry. Internal APIs become managed MCP servers from an API definition. Everything goes through one governed path.
How does Codex authenticate to internal systems?
Through your existing identity provider. Speakeasy plugs into Okta, Microsoft Entra ID, Auth0, WorkOS, Google Workspace, or any SAML or OIDC provider. Codex inherits the user's existing roles and permissions, so no new account model is created and access stays consistent with what the user already has.
Can I scope which tools each team or person can access?
Yes. Provision sub-catalogs per team so each group of engineers sees only the MCP servers and toolsets relevant to their work. Permissions can scope down to the individual tool, and credential management replaces the pattern of developers pasting API keys into Codex.
How is data exfiltration prevented?
Every prompt and response is inspected in real time. Source code, PII, and exfiltration patterns are actively blocked. Prompt injection and shadow MCPs are passively detected. Alerts integrate with your existing SIEM, and a full audit trail records who asked what, when, against which data.
Does this change how developers use Codex?
No. Speakeasy layers onto Codex without changing the client. Developers keep using Codex the way they already do; the control plane sits behind the scenes managing connections, identity, and policy.
What is the rollout pattern most companies follow?
Pick one team and one set of tools (often a platform team with GitHub and Linear), route them through Speakeasy, prove value, then expand. Per-team registries make it easy to roll out to one team at a time without blocking the rest of the organization.
How does Speakeasy control Codex costs?
Token use is attributed to a team, user, and tool, so spend is never a black box. Set monthly budgets per team and enforce them in real time, with alerts as a team approaches its limit and a hard cap when it hits it. Leadership sees spend trending before the invoice arrives, and chargebacks hold up because every cost traces back to who incurred it.

AI everywhere.

Control here.