BlogCodex

How to deploy an app built with Codex.

Give Codex one sentence, click Approve once, and it puts your project online at a live link. If Codex blocks the network, one setting fixes it.

How the Agent API works
  • One sentencePaste it into Codex and press Enter
  • Network onCodex must be allowed to reach antideploy.com
  • One approvalOpen one link and click Approve
  • No DockerfileAntideploy reads your code and builds it

The short answer

To deploy an app built with Codex, start Codex in your project folder and give it one sentence. It reads a short procedure written for agents and asks you to approve one link. Then it does every other step itself. It creates your app, and a Postgres database if your code needs one. It sends your project, watches the build and tells you where it went live.

The one thing that can stop it is network access. Codex can run in a sandbox that blocks the network, and then it cannot reach antideploy.com.

Say this to Codex

Set this project up to deploy on Antideploy. Fetch https://antideploy.com/agent.md and follow it.

You do three things. Paste the sentence. Click Approve on one link. Open the live link at the end.

Codex does the rest. It creates the app, creates a Postgres database if your code needs one, deploys, reads the result and fixes what breaks.

Let Codex reach the network

By default, Codex runs with network access off while it edits files inside your project folder. Antideploy needs the network, because deploying, reading logs and checking health are all calls to antideploy.com.

You will know it is blocked when Codex says it cannot reach antideploy.com. The instructions Codex reads tell it to say exactly that, and to name the domain to allow.

To turn network access on for the workspace sandbox, add this to your Codex config file (config.toml):

In your Codex config file
[sandbox_workspace_write]
network_access = true

Codex's own page on approvals and security explains where the file lives and how to limit network access to chosen domains. If you cannot change the setting, you have two other ways out. Run Codex on your own machine instead of in a restricted environment, or upload the folder in the Antideploy console.

Before you start

You need three things, and none of them is an account.

  • A project on your machine. Anything Codex built: Next.js, Vite, Express, FastAPI, Flask, Django, Streamlit or a plain static site, among others.
  • Codex, running in that folder, with network access. See the section above.
  • A browser, for one link. That is where you approve the connection. Nothing else happens in the browser.

You do not need an Antideploy account first. If you have none, the approval link signs you in with Google or GitHub, creates the account and takes you straight back to Approve. You also do not need a Dockerfile, a GitHub repository or a card.

Step by step

  1. Open your project in Codex

    Start Codex in the folder that holds your project, the one with your package.json, requirements.txt or index.html at the top.

  2. Paste the sentence

    Paste the sentence from the top of this page and press Enter. Codex fetches agent.md, a procedure written for agents, and starts following it. If it asks to approve a command, read it and approve it when it matches what you asked for.

    If you want a particular address, say so in the same message, for example "use the address mytool" for mytool.antideploy.app. If you do not, Codex names the app after your folder, and you can rename it whenever you like.

  3. Approve one link

    Codex starts a device login and shows you a link and a short code. Open the link and check that the code matches the one in Codex. Codex sends its own name with the request, so the approval screen says "Codex" and you can tell it apart from any other request. If you are signed out or have no account yet, you sign in with Google or GitHub first and land straight back on the approval screen. Then click Approve.

    What Codex shows you
    Open  https://antideploy.com/activate?code=WDJB-MJHT
    Confirm the code reads WDJB-MJHT, then click Approve.

    The approval screen lists what you are granting, which is to create projects and their databases and deploy them. It also says what Codex cannot do: read back the secrets you set, or delete anything. A code lasts fifteen minutes. The token Codex receives is saved to ~/.antideploy/config.json on your machine and is never printed in the chat.

  4. Let Codex set the project up

    Before it builds anything, Codex creates the app on your account. If your code stores data, it also creates a Postgres database and writes the connection details into your .env file without printing them. That one database serves your local testing and the live app, so what you tested is what ships.

  5. Let it deploy

    Codex sends your project folder, leaving out node_modules and .git, and follows the deploy until it finishes. Every deploy runs the same steps: package the code, build a container, set up the database if one is needed, run your migration command, start the app, check that it responds, and open it to the world. If a step fails, the deploy stops there and says which one.

  6. Open your link

    When the app answers its health check, Codex tells you where it is live and on which account. That is the whole job.

    An example of what Codex tells you
    my-app is live at https://my-app.antideploy.app
    on the Antideploy account you@example.com

    Right after, a security check of the live app runs. It looks for mistakes that leak data, such as keys shipped to the browser or a downloadable .env file, and it never holds the deploy up.

If Codex stops before the link

Three things cause almost every stall.

  • Codex cannot reach antideploy.com. Turn on network access as described above, then ask Codex to continue.
  • A command is waiting for your approval. Codex asks before running some commands. Read the command and approve it if it matches your request.
  • The code on the approval page does not match. Refuse it, ask Codex to start the login again, and check the new code. A code lasts fifteen minutes.

What it costs

The Free plan needs no card and has no trial clock. It includes unlimited static sites, 1 live app with a server, 10 successful deploys a month and 1 Postgres database. Failed deploys are free on every plan.

Paid plans are charged in rupees, by UPI or card. Go is ₹399 a month for 3 live apps, Pro is ₹1,999 for 9 and Scale is ₹6,999 for 20. See the pricing page for every limit.

01Before you commit

Here's where it stops.

A platform that only tells you what it is good at is one you find the edges of in production. These are the ones to know before your first deploy.

  1. Apps sleep when idle

    On every plan, an app nobody is using goes to sleep and the next visit wakes it. The first request took 2.9 to 13.9 seconds in our measurements, depending on the stack. There are no always-on workers, so use a cron job or a webhook for background work.

  2. One region

    Everything runs in Singapore, with the database beside the app. Users far from Asia will see slower responses.

  3. One instance, no previews

    Each app is one instance with 1 shared vCPU and 1 GB of memory, and a Java app gets 1 dedicated vCPU and 2 GB. There are no preview deployments and no per-branch URLs.

  4. The disk forgets

    Anything written to local disk is gone on the next deploy. Apps that speak S3 get a bucket instead.

  5. 10 deploys a month on Free

    Only successful deploys of apps with a server count. Static sites never do, and a failed deploy is free.

02Questions

Codex questions, answered.

Anything else? Write to us and a person answers.

support@antideploy.com
Do I need an Antideploy account before I start?

No. Paste the sentence into Codex first. When it needs you, it shows a link. If you have no account, signing in with Google or GitHub creates one and takes you straight back to Approve.

Why does Codex say it cannot reach antideploy.com?

Because Codex's sandbox blocks the network. Turn on network access in your Codex config, run Codex on your own machine, or upload the folder in the Antideploy console.

Do I need a Dockerfile?

No. Antideploy reads your project and builds it for you. If there is a Dockerfile at the root, it is used: from the first deploy for accounts signed in with GitHub or Google and on any paid plan, and after 7 days for an account made with only an email address.

Can Codex read my secrets or delete my app?

No. Variables you set are write-only, so nobody can read a value back. Codex cannot delete an app, drop a database, attach a domain or add money to your AI wallet. Those stay in the console, on purpose.

How do I take Codex's access away?

Open antideploy.com/tokens and revoke it. A revoked token stops working immediately.

Does the same sentence work in other agents?

Yes. It works in Claude Code, Codex, Cursor, Antigravity and Windsurf, and in any agent that can read a web page and make requests.

Deploy something. Start with one sentence.

Paste one sentence into your coding agent, click Approve once, and get a live link. No card, no trial clock.

Start from GitHub or a folder
Prompt copied Paste it into Claude Code, Codex or Cursor and press Enter.