- Unified AI Gateway - Single interface for 250+ LLMs with API key management (beyond Codex’s default model options)
- Centralized AI observability: Real-time usage tracking for 40+ key metrics and logs for every request
- Governance - Real-time spend tracking, set budget limits and RBAC in your Codex setup
- Security Guardrails - PII detection, content filtering, and compliance controls
1. Setting up Portkey
Portkey allows you to use 1600+ LLMs with your OpenAI Codex setup, with minimal configuration required. Let’s set up the core components in Portkey that you’ll need for integration.Create an Integration
- Find your preferred provider (e.g., OpenAI, Anthropic, etc.)
- Click Connect on the provider card
- In the “Create New Integration” window:
- Enter a Name for reference
- Enter a Slug for the integration
- Enter your API Key and other provider specific details for the provider
- Click Next Step

Configure Models
- Leave all models selected (or customize)
- Toggle Automatically enable new models if desired

Copy the Model Slug
- Go to Model Catalog → Models tab
- Find and click on your model (if your model is not visible, you need to edit your integration from the last step)
- Copy the slug (e.g.,
@openai-dev/gpt-4o)

@your-provider-slug/model-name and you’ll need it for configuring Codex CLI.Create Portkey API Key
- Go to API Keys in Portkey
- Create new API key
- Generate and save your API key

2. Integrate Portkey with OpenAI Codex CLI
Now that you have your Portkey components set up, let’s connect them to OpenAI Codex CLI. The integration leverages Codex’sconfig.toml file to define custom model providers that route all requests through Portkey’s AI Gateway.
Understanding wire_api: Chat vs Responses
OpenAI Codex CLI supports two API protocols via thewire_api setting:
Configure Codex with config.toml
OpenAI Codex CLI uses a TOML configuration file located at~/.codex/config.toml. Let’s set up Portkey as a custom model provider.
Option 1: Single Provider (Responses API)
If you’re only using models that support the Responses API (like GPT-5 or o3):Option 2: Single Provider (Chat Completions API)
If you’re using models that use the Chat Completions API (like GPT-4o, Claude, Gemini):Option 3: Multiple Providers (Both APIs)
For maximum flexibility, configure both providers and switch between them:Set Environment Variable
Set your Portkey API key as an environment variable:export line to your shell’s configuration file (e.g., ~/.zshrc, ~/.bashrc) for persistence.Test Your Integration
Run a simple command to verify everything is working:3. Set Up Enterprise Governance for OpenAI Codex
Why Enterprise Governance? If you are using OpenAI Codex inside your organization, you need to consider several governance aspects:- Cost Management: Controlling and tracking AI spending across teams
- Access Control: Managing team access and workspaces
- Usage Analytics: Understanding how AI is being used across the organization
- Security & Compliance: Maintaining enterprise security standards
- Reliability: Ensuring consistent service across all users
- Model Management: Managing what models are being used in your setup
Step 1: Implement Budget Controls & Rate Limits
Step 1: Implement Budget Controls & Rate Limits
Step 1: Implement Budget Controls & Rate Limits
Model Catalog enables you to have granular control over LLM access at the team/department level. This helps you:- Set up budget limits
- Prevent unexpected usage spikes using Rate limits
- Track departmental spending
Setting Up Department-Specific Controls:
- Navigate to Model Catalog in Portkey dashboard
- Create new Provider for each engineering team with budget limits and rate limits
- Configure department-specific limits

Step 2: Define Model Access Rules
Step 2: Define Model Access Rules
Step 2: Define Model Access Rules
As your AI usage scales, controlling which teams can access specific models becomes crucial. You can simply manage AI models in your org by provisioning model at the top integration level.
Step 3: Set Routing Configuration
Step 3: Set Routing Configuration
- Data Protection: Implement guardrails for sensitive code and data
- Reliability Controls: Add fallbacks, load-balance, retry and smart conditional routing logic
- Caching: Implement Simple and Semantic Caching. and more…
Example Configuration:
Here’s a basic configuration to load-balance requests to OpenAI and Anthropic:Step 4: Implement Access Controls
Step 4: Implement Access Controls
Step 4: Implement Access Controls
Create User-specific API keys that automatically:- Track usage per developer/team with the help of metadata
- Apply appropriate configs to route requests
- Collect relevant metadata to filter logs
- Enforce access permissions
Step 5: Deploy & Monitor
Step 5: Deploy & Monitor
Step 5: Deploy & Monitor
After distributing API keys to your engineering teams, your enterprise-ready OpenAI Codex setup is ready to go. Each developer can now use their designated API keys with appropriate access levels and budget controls. Apply your governance setup using the integration steps from earlier sections Monitor usage in Portkey dashboard:- Cost tracking by engineering team
- Model usage patterns for AI agent tasks
- Request volumes
- Error rates and debugging logs
Enterprise Features Now Available
Codex CLI now has:- Departmental budget controls
- Model access governance
- Usage tracking & attribution
- Security guardrails
- Reliability features
Portkey Features
Now that you have enterprise-grade Codex CLI setup, let’s explore the comprehensive features Portkey provides to ensure secure, efficient, and cost-effective AI operations.1. Comprehensive Metrics
Using Portkey you can track 40+ key metrics including cost, token usage, response time, and performance across all your LLM providers in real time. You can also filter these metrics based on custom metadata that you can set in your configs. Learn more about metadata here.
2. Advanced Logs
Portkey’s logging dashboard provides detailed logs for every request made to your LLMs. These logs include:- Complete request and response tracking
- Metadata tags for filtering
- Cost attribution and much more…

3. Unified Access to 250+ LLMs
You can easily switch between 250+ LLMs. Call various LLMs such as Anthropic, Gemini, Mistral, Azure OpenAI, Google Vertex AI, AWS Bedrock, and many more by simply changing the model slug in yourconfig.toml.
4. Advanced Metadata Tracking
Using Portkey, you can add custom metadata to your LLM requests for detailed tracking and analytics. Use metadata tags to filter logs, track usage, and attribute costs across departments and teams.Custom Metadata
5. Enterprise Access Management
Budget Controls
Single Sign-On (SSO)
Organization Management
Access Rules & Audit Logs
6. Reliability Features
Fallbacks
Conditional Routing
Load Balancing
Caching
Smart Retries
Budget Limits
7. Advanced Guardrails
Protect your Codex CLI’s data and enhance reliability with real-time checks on LLM inputs and outputs. Leverage guardrails to:- Prevent sensitive data leaks
- Enforce compliance with organizational policies
- PII detection and masking
- Content filtering
- Custom security rules
- Data compliance checks
Guardrails
FAQs
What's the difference between wire_api 'chat' and 'responses'?
What's the difference between wire_api 'chat' and 'responses'?
wire_api setting determines which OpenAI API protocol Codex uses:responses: Uses OpenAI’s newer Responses API, required for models like GPT-5, o3, and o4-mini that support advanced reasoning featureschat: Uses the standard Chat Completions API, compatible with most models including GPT-4o, Claude, Gemini, and others
responses for full feature support.How do I switch between models with different API types?
How do I switch between models with different API types?
config.toml:codex --model "@slug/model" --provider portkey-chatHow do I track costs for different teams?
How do I track costs for different teams?
- Create separate integrations for each team with unique slugs
- Use metadata tags in your API keys
- Set up team-specific API keys with metadata
- Monitor usage in the analytics dashboard
What happens if a team exceeds their budget limit?
What happens if a team exceeds their budget limit?
- Further requests will be blocked
- Team admins receive notifications
- Usage statistics remain available in dashboard
- Limits can be adjusted if needed
Can I use Portkey with the open source version of Codex CLI?
Can I use Portkey with the open source version of Codex CLI?
Where can I find more Codex CLI configuration options?
Where can I find more Codex CLI configuration options?

