Governed Codex transactions for safer coding-agent changes.
OpenAI Build Week 2026 — Developer Tools submission. THEKEY is a pre-existing project reported by its owner and meaningfully extended during the Submission Period. This repository distinguishes the documented Build Week extension from prior-work claims and does not invent missing historical proof.
Español · Judge path · Build Week delta · Codex/GPT-5.6 usage · Provenance · MIT License
Download THEKEY-Portable-Windows-x64.zip
The GitHub Release asset is preferred. The identical, tag-pinned emergency fallback is versioned in the repository.
Windows 10/11 x64 · no build · no Python · no Git · no API key · no account
SHA-256:
589cdb85a7c478148b72d0337cfdb8b8454acc4e4c7c782b6e9a05b3969e2f0f
Get-FileHash .\THEKEY-Portable-Windows-x64.zip -Algorithm SHA256The portable binaries are not Authenticode-signed. Windows may show Unknown publisher; verify the published SHA-256 before running.
- Download, verify, and fully extract the ZIP to a short writable folder.
- Run
THEKEY.exe. - Click Demo para jueces / Judge demo.
- Inspect the persisted result in Ver resultados / View results.
- For the product flow, choose
SAMPLE-PYTHON-APP, thenSAMPLE-REPAIRABLE-PYTHON-APPfor a bounded repair and re-test.
The bundle contains the runtime, samples, a manifest, and first-run guidance. It does not require Python, Git, PowerShell, Docker, WSL, API keys, a GPU, payment, or a test account. Read JUDGES.md for the five-minute path and testing instructions for the full procedure.
Coding agents can edit code quickly, but teams still need to know which plan was approved, what was permitted to run, which checks passed, and how to review a result later. THEKEY treats those controls as one transaction rather than an after-the-fact narrative.
THEKEY binds a plan, CHECKMATE pre-action review, explicit scoped human authorization, deterministic policy, physical dispatch, verification gates, and persisted evidence to one run and transaction.
- THEKEY is the governed-transaction product.
- THE KING orchestrates phases and context; it cannot self-approve.
- CHECKMATE reviews risk before execution and does not perform physical writes.
- Codex with GPT-5.6 was used to develop and review the project; it is not a runtime dependency.
THEKEY uses an isolated workflow copy for verification and repair. That is not an operating-system sandbox: selected project tests remain trusted local code. Repair is deliberately bounded, never changes tests or installs dependencies, and only applies bytes that passed the configured gates with separate consent.
The documented extension includes strict receipt/context contracts, a fail-closed physical authorization boundary, adversarial denial coverage, Judge Mode with evidence, portable Windows delivery, WPF integration, included samples, and retained smoke/verification material. Review the factual Build Week delta, contribution record, and final smoke report.
Codex with GPT-5.6 accelerated codebase inspection, authorization and receipt
design, adversarial tests, regression/rollback checks, Judge Mode evidence, the
portable path, and judge documentation. The verified primary /feedback
Session ID is 019f79f2-6a7e-74f0-b1fa-d65335b29a7c.
The owner retained product and authority decisions, including bounded scope, no production reuse of the Judge Mode grant, and separate approval for release, video publication, and Devpost submission. Details and limitations are in Codex/GPT-5.6 usage.
The package manifest records its source state and hashes every distributed file; the outer ZIP hash above anchors the whole package. The final evidence retains a Windows 11 owner-verified WPF smoke, packaged backend execution, and automated test results. The smoke record is explicitly separate from automated testing. See artifact verification and FINAL_REPORT.md.
Source reproduction is documented in Judge Quickstart. It requires Windows 11, PowerShell 7, Python 3.11+, and Git; judges do not need this path to evaluate the portable build.
The owner reports that THEKEY existed before Build Week. The reachable Git history in this checkout begins after the Submission Period, so it cannot independently prove the earlier project history. The repository does not claim otherwise and does not fabricate chats. See the provenance index and the owner-evidence request.
THEKEY is distributed under the MIT License. It was prepared for OpenAI Build Week 2026; it is not an official OpenAI product and is not endorsed by OpenAI.