How to Connect Codex to cPanel / GoDaddy via SSH: Complete Setup & Troubleshooting Guide
Introduction
Connecting Codex directly to a cPanel-hosted website is one of those jobs that looks like it should take five minutes. Enable SSH, point Codex at the server and get on with the work. In reality, there are a few separate layers to get right: GoDaddy has to allow shell access, cPanel has to trust your SSH key, Windows needs the correct private key, and Codex needs a remote shell where the codex command is available.
This guide follows the route that worked for us on GoDaddy Web Hosting with cPanel, using a dedicated SSH key and the site's normal cPanel user. We also hit most of the useful failure modes along the way, including invalid format, Shell access is not enabled on your account!, and a port 22 timeout after repeated reconnect attempts.
The end result is a practical setup where Codex can work against the website through SSH without root access or a server-wide admin account.
The Finished Setup at a Glance
The working route is straightforward once you separate the pieces:
- enable SSH access in the GoDaddy hosting dashboard
- create a dedicated SSH key for Codex in cPanel
- authorise the public key in cPanel
- download and save the private key on your Windows machine
- prove the SSH login works manually before touching Codex
- add a clean SSH host alias in
~/.ssh/config - make sure Codex CLI is installed and on PATH in the remote login shell
- add or enable the SSH host in Codex and select the website directory
Keeping those stages separate makes troubleshooting much easier because you always know whether you are dealing with GoDaddy, cPanel, Windows SSH or Codex itself.
What You'll Need Before You Start
Before you begin, make sure you have:
- a GoDaddy Web Hosting (cPanel) account with SSH available on the plan
- access to the GoDaddy hosting dashboard and cPanel
- your cPanel / FTP username
- a Windows machine with PowerShell and OpenSSH available
- the ChatGPT / Codex desktop app installed and signed in
- permission to work on the website you are connecting to
- Node.js and npm available in the remote shell, or a supported way to expose them to your cPanel user
GoDaddy's own SSH documentation uses your domain or server IP as the host, the cPanel/FTP username as the SSH username and port 22. Password login is supported, but for Codex we will use a dedicated SSH key instead.
Why Use a Dedicated SSH Key for Codex?
You could reuse an existing SSH key, but a dedicated key is much easier to manage. If you later want to remove Codex access, you can deauthorise one key without affecting your normal terminal access or anything else using SSH.
The key pair has two parts:
- public key: stored and authorised on the server
- private key: kept on your own computer and used by Windows/Codex to prove identity
Never share the private key or paste it into a ticket, chat or public repository. The .pub file is the public half and is safe to add to cPanel.
Step 1: Enable SSH in the GoDaddy Hosting Dashboard
Before creating keys, make sure GoDaddy is actually allowing shell access to the hosting account. Go to your GoDaddy product page, find the relevant Web Hosting (cPanel) plan and select Manage. In the hosting dashboard, open Settings, find SSH access, select Manage and switch SSH on.
This is separate from cPanel's SSH key manager. You can have a perfectly valid key in cPanel and still receive:
Shell access is not enabled on your account!
if the GoDaddy-level switch is disabled.
Once enabled, GoDaddy displays the SSH credentials for the account. Keep note of the cPanel/FTP username and the host you intend to use.
Step 2: Generate a Dedicated SSH Key in cPanel
Open cPanel and go to:
Security β SSH Access β Manage SSH Keys β Generate a New Key
Give the key a recognisable name such as:
codex
Set a strong passphrase if you want the private key protected at rest. cPanel will create the pair inside your hosting account, normally under a path similar to:
/home/YOUR_CPANEL_USER/.ssh/codex
/home/YOUR_CPANEL_USER/.ssh/codex.pub
The first file is the private key and the .pub file is the public key. Because we used a custom key name, we will explicitly tell Windows and Codex which identity file to use later.
If you prefer, you can generate the pair locally with ssh-keygen and import only the public key into cPanel. That is arguably the cleaner security model because the private key never exists on the web server. The cPanel-generated route is used here because it is simple and works well when handled carefully.
Step 3: Authorise the Public Key and Download the Private Key
Generating the key is not enough. cPanel requires the public key to be authorised before SSH logins can use the matching private key.
In Manage SSH Keys, find codex under Public Keys, choose Manage and click Authorize. The status should change to authorised.
Then find codex under Private Keys and choose View / Download. Save the private key to your Windows computer. Do not confuse it with codex.pub.
This distinction caused one of our first errors. A public key normally begins with something like:
ssh-rsa AAAAB3N...
whereas the private key should begin with a header such as:
-----BEGIN OPENSSH PRIVATE KEY-----
or:
-----BEGIN RSA PRIVATE KEY-----
If Windows says Load key ...: invalid format and the file starts with ssh-rsa, you have saved the public key where the private key should be.
Step 4: Save the Private Key on Windows
Save the downloaded private key somewhere only your Windows account can access. We used:
C:\Users\Tony\.ssh\codex
The file should be called codex, not codex.pub and preferably not codex.txt.
A quick check in PowerShell is:
Get-Content "$env:USERPROFILE\.ssh\codex" -TotalCount 1
You want to see a BEGIN ... PRIVATE KEY header. Do not paste the rest of that file anywhere.
If you copied the key manually rather than downloading it, also make sure the file has not been saved with unexpected formatting or encoding. A malformed private key will fail locally before Windows even attempts to connect to the server.
Step 5: Test the SSH Login Manually First
Before opening Codex, prove the exact host, username and private key work from PowerShell:
ssh -i "$env:USERPROFILE\.ssh\codex" YOUR_CPANEL_USER@your-domain.co.uk
GoDaddy documents port 22 for Web Hosting (cPanel), so you can also be explicit:
ssh -p 22 -i "$env:USERPROFILE\.ssh\codex" YOUR_CPANEL_USER@your-domain.co.uk
On the first connection, OpenSSH may ask you to trust the server's host key. If the private key has a passphrase, you will then be prompted for that passphrase.
A successful login should leave you at a shell prompt for your cPanel user. Run a couple of harmless checks:
pwd
whoami
Do not move on to Codex until this works. If manual SSH fails, Codex will fail too.
Step 6: Add a Clean SSH Alias on Windows
OpenAI's current remote-connection guidance recommends adding the remote machine to your normal SSH config so Codex can discover and resolve it through OpenSSH. On Windows, edit or create:
C:\Users\Tony\.ssh\config
Add a concrete host entry:
Host godaddy-codex
HostName your-domain.co.uk
User YOUR_CPANEL_USER
Port 22
IdentityFile C:/Users/Tony/.ssh/codex
IdentitiesOnly yes
Then test the alias:
ssh godaddy-codex
If that works, you now have one clean connection name that both you and Codex can use.
If your version of Codex offers a manual connection form instead of discovering the SSH alias, use the same values there. In builds where there is no separate username field, a host value such as YOUR_CPANEL_USER@your-domain.co.uk works naturally with OpenSSH.
Step 7: Check Node.js and Install Codex CLI on the Remote Account
Codex's SSH connection does more than open a normal terminal. The desktop app starts the remote Codex app server through SSH, so the remote login shell needs the codex command available on its PATH.
First check whether Node.js and npm are available:
node --version
npm --version
Current GoDaddy Web Hosting plans advertise Node.js support, but the exact shell environment can vary. If both commands work, install Codex into your own account rather than trying to use sudo on shared hosting:
mkdir -p ~/.npm-global
npm config set prefix ~/.npm-global
echo 'export PATH="$HOME/.npm-global/bin:$PATH"' >> ~/.bash_profile
source ~/.bash_profile
npm install -g @openai/codex@latest
Then verify it:
which codex
codex --version
If node or npm is missing from the SSH shell, do not start trying to install system packages with sudo. On shared cPanel hosting you normally do not have root access. Use the Node.js facilities provided by the hosting plan or contact GoDaddy support to confirm how Node is exposed to the shell. Codex remote SSH will not become healthy until codex is available to that user's login shell.
Step 8: Authenticate Codex on the Remote Host
Once the CLI is installed, authenticate it from the remote shell if the desktop app has not already guided you through that step:
codex login
Complete the browser or device authentication flow, then confirm the CLI can see its login state. The important point is that the remote account, not just your local Windows machine, needs a working Codex CLI environment because the remote app server runs there.
If you administer a managed workspace, use the authentication method required by that workspace rather than placing long-lived secrets into shell history.
Step 9: Add the cPanel SSH Host in Codex
Open Codex and go to Settings β Connections β SSH. Depending on the version, your godaddy-codex alias may appear automatically, or you may be able to add the connection manually.
For a manual connection, the settings are effectively:
- Host:
YOUR_CPANEL_USER@your-domain.co.ukif the UI has no separate username field - Port:
22 - Authentication:
Identity - Identity file path:
C:\Users\Tony\.ssh\codex
The identity file is the private key. Do not select codex.pub.
Once connected, select the remote project folder you want Codex to work in. On many cPanel accounts this will be somewhere under your home directory, commonly public_html for the primary site, but use the actual document root shown in your cPanel setup rather than assuming a path.
Step 10: Verify the Remote Connection
Once the connection shows as healthy, open the remote project and start with a read-only sanity check. For example, ask Codex to identify the current directory, list the top-level files and explain the project structure without making changes.
You can also verify from your own SSH session:
which codex
codex --version
pwd
At this point Codex is operating through the permissions of your cPanel user. It does not magically gain root access, and it can only read or change files that account is already allowed to access. That is exactly what we want on shared hosting.
Troubleshooting: 'Load key ... invalid format'
This normally means Windows cannot parse the file you selected as the private identity.
The first thing to check is the first line:
Get-Content "$env:USERPROFILE\.ssh\codex" -TotalCount 1
If it starts with:
ssh-rsa AAAA...
you have the public key, not the private key. Go back to cPanel, open the Private Keys section and download codex rather than codex.pub.
If it does contain a private-key header, check that the file was saved as plain text without extra HTML, copy/paste damage or a .txt extension.
Troubleshooting: 'Shell access is not enabled on your account!'
This error is actually helpful because it proves the server is reachable and has got far enough to identify your account. The fix is at the GoDaddy hosting level, not in the SSH key itself.
Go back to:
GoDaddy β Web Hosting β Manage β Settings β SSH access β Manage
and make sure SSH is enabled.
Troubleshooting: Connection Timed Out on Port 22
A timeout is different from an authentication failure. If you see:
ssh: connect to host your-domain.co.uk port 22: Connection timed out
Windows has not reached the SSH service at all, so changing passwords or keys will not help yet.
Test the port directly:
Test-NetConnection your-domain.co.uk -Port 22
A useful result looks like:
TcpTestSucceeded : True
If it is False but ping succeeds, the host is reachable while TCP port 22 is not. Check that SSH is still enabled, stop any aggressive auto-reconnect loop, verify you are using the correct SSH hostname, and try another network such as a phone hotspot. If another network works, your current public IP may have been temporarily blocked or rate-limited by the hosting provider.
We hit this after repeated failed connection attempts. The important lesson is to disable Codex's reconnect loop while troubleshooting and prove SSH manually before turning the connection back on.
Troubleshooting: Domain Name vs Shared Hosting IP
GoDaddy allows SSH clients to use either the domain name or the relevant server IP, but on shared hosting the IP shown in one part of the dashboard is not always the most useful endpoint to troubleshoot with.
If the domain worked earlier, do not switch to a different shared IP just because it appears in cPanel. Test the exact endpoint you intend to use:
ssh -v -i "$env:USERPROFILE\.ssh\codex" YOUR_CPANEL_USER@your-domain.co.uk
The verbose output shows which IP the hostname resolves to and how far the connection gets. That is far more useful than guessing.
Quick Reference Table
The table above covers the handful of settings and commands worth checking first when the connection does not behave as expected.
| task | command or setting | why it matters |
|---|---|---|
| Enable SSH in GoDaddy | Web Hosting β Manage β Settings β SSH access β Manage β On | cPanel keys cannot work if GoDaddy-level shell access is disabled |
| Create a dedicated key | cPanel β Security β SSH Access β Manage SSH Keys β Generate a New Key | Keeps Codex access separate and easy to revoke |
| Authorise the public key | Public Keys β codex β Manage β Authorize | cPanel-generated keys do not work until the public key is authorised |
| Save the private key on Windows | C:\Users\You\.ssh\codex | This is the identity file used by OpenSSH and Codex |
| Test SSH manually | ssh -i "$env:USERPROFILE\.ssh\codex" USER@your-domain.co.uk | Separates SSH problems from Codex problems |
| Test port 22 | Test-NetConnection your-domain.co.uk -Port 22 | Shows whether the SSH service is reachable before authentication |
| Install Codex CLI | npm install -g @openai/codex@latest | The remote login shell needs the codex command on PATH |
| Codex identity file | C:\Users\You\.ssh\codex | Use the private key, never codex.pub |
Security Notes and Good Practice
A remote coding agent can edit the same files your cPanel user can edit, so treat the connection like any other privileged development tool:
- use a dedicated SSH key for Codex
- protect the private key with an appropriate passphrase
- keep the private key off shared drives and out of source control
- use the normal cPanel user, not a root or server-wide administrator
- do not add
sudojust to make Codex easier to install - test against a staging site first where possible
- start with read-only inspection before asking Codex to make broad changes
- keep backups and source control for anything important
- deauthorise the public key in cPanel if you no longer need the connection
If you generated the private key inside cPanel and have safely copied it to your local machine, consider whether you still need the server-side private copy. The public key is what the server needs for incoming authentication.
Official Documentation
The setup above was tested as a practical workflow, but the underlying behaviour is also covered by the relevant vendor documentation:
- GoDaddy: Enable SSH for Web Hosting (cPanel)
- GoDaddy: Connect to Web Hosting (cPanel) with SSH
- cPanel: SSH Access and Manage SSH Keys
- OpenAI: Remote connections and SSH hosts
Interfaces change over time, so if a button has moved, use the same underlying settings rather than relying on the exact position shown in the reference images.
Conclusion
Connecting Codex to GoDaddy cPanel hosting over SSH is very workable once the layers are tackled in the right order. The route that worked for us was:
- enable SSH in the GoDaddy hosting dashboard
- create and authorise a dedicated key in cPanel
- keep the private key on Windows and give Codex that exact file
- prove normal SSH works before debugging Codex
- use a clean entry in
~/.ssh/config - make sure the remote login shell has Codex CLI on PATH
- connect Codex using the same host, user and identity you already tested
Most of the frustrating errors become obvious once you know which layer they belong to. invalid format is a local key problem, Shell access is not enabled is a GoDaddy setting, Permission denied is usually authentication, and a timeout on port 22 means you have not reached SSH at all.
If you already use Codex against a Plesk server, this cPanel route gives you the same sort of remote workflow on shared GoDaddy hosting and sits nicely alongside the Plesk setup without needing root access.