Codex Computer Use EnumWindows 0x80070003? Test the Desktop Boundary

Codex Computer Use EnumWindows 0x80070003? Test the Desktop Boundary

Aident AI

A cyan scan crosses a guarded desktop boundary through one controlled aperture toward a single window pane.

Codex Computer Use EnumWindows 0x80070003? Test the Desktop Boundary

If Codex Computer Use on Windows fails at sky.list_apps() or sky.list_windows() with EnumWindows failed: The system cannot find the path specified. (0x80070003), stop reinstalling components. Current reports show the helper can exist, start, and answer diagnostics while window discovery still fails. A successful compatibility test on one affected machine points to the desktop isolation boundary as a cause for at least one configuration.

The narrow compatibility test is to keep the elevated Windows sandbox, temporarily set windows.sandbox_private_desktop = false, fully restart Codex, and retry one read-only window listing. OpenAI documents this setting as the older Winsta0\\Default compatibility path and warns that the private desktop provides stronger UI isolation. Treat the test as a diagnosis with a rollback, not as a permanent security recommendation.

Confirm This Exact Failure

This guide applies when all of these are true:

  • Computer Use is installed and enabled in Codex on Windows.

  • The failure happens before Codex can select or approve a target application.

  • Both sky.list_apps() and sky.list_windows() return 0x80070003, or the closely related 0x80070002 file-not-found variant.

  • The bundled @oai/sky package imports and the Computer Use helper starts.

Use a read-only prompt for the reproduction:

Use Computer Use only to list the titles of visible top-level windows.
Do not click, type, launch, close, activate, or modify anything

Preserve the exact error, Codex app version, Computer Use plugin version, Windows version, architecture, and UTC time. Redact user names, account identifiers, local paths, window titles, screenshots, and feedback IDs before sharing logs publicly.

Five independent OpenAI issue reports opened from August 5 through August 7, 2026 describe the same EnumWindows boundary on Windows 10 and 11, x64 and ARM64. The longest report records successful helper startup, a healthy direct Win32 enumeration test outside the sandbox, and failure only when the Computer Use helper enumerates windows. That evidence points away from a missing executable or a dead Windows desktop.

Do Not Repeat Failed Repairs

The reports already cover these attempts without restoring enumeration:

  • repairing, resetting, uninstalling, and reinstalling Codex;

  • reinstalling the Computer Use plugin;

  • rebuilding the cua_node runtime;

  • restarting Codex and Windows;

  • reinstalling Workspace Dependencies;

  • toggling app access and checking that the desktop is active and unlocked;

  • creating missing profile folders or changing window-station access controls.

Do not weaken ACLs, disable UAC, grant broad desktop permissions, replace the signed helper, or install a custom broker from an issue comment. Those changes expand the security problem without establishing the cause.

This failure is also different from Error: node_repl exec context not found. If enumeration succeeds and a later JavaScript call loses its context, use the Codex Computer Use node_repl containment guide. If the helper never starts and the error says spawn EPERM, use the separate Windows Computer Use spawn diagnostic.

Run One Reversible Compatibility Test

Open your reviewed Codex configuration file. If it already contains a [windows] table, edit that table instead of creating a duplicate. Preserve any existing values and add only the compatibility setting:

[windows]
sandbox_private_desktop = false

Do not change the sandbox implementation as part of this test. If the table already has sandbox = "elevated", leave it in place. Do not switch to full access, disable approvals, or turn off the Windows sandbox. OpenAI's Windows sandbox documentation says both native sandbox modes use a private desktop by default for stronger UI isolation and recommends sandbox_private_desktop = false only when the older Winsta0\\Default behavior is needed for compatibility.

Fully exit Codex and any related ChatGPT desktop process through the normal app controls, then launch a fresh task. Repeat only the read-only listing prompt.

Expected result:

  • sky.list_windows() or sky.list_apps() returns visible application metadata;

  • no window is clicked, focused, captured, or changed;

  • the original 0x80070003 error no longer appears.

If the error is unchanged, restore the original configuration immediately. The private-desktop boundary was not a sufficient explanation for that installation, so record the result and wait for an upstream fix instead of applying broader permissions.

Understand the Security Tradeoff

The private desktop is a security boundary, not a performance option. It isolates UI-capable sandbox processes from the user's interactive desktop. Setting it to false lets the compatibility path use Winsta0\\Default, which can make real windows visible to Computer Use.

That explains why one issue participant restored enumeration with the setting, but it does not prove the complete Computer Use workflow is repaired. The same report still observed a later node_repl context failure and a screen-capture service error. Window listing, screen capture, and interaction are separate gates.

For a safe test:

  1. Use a disposable, non-sensitive application with no account, message, terminal, password, or private document visible.

  2. Keep normal approvals enabled.

  3. Test only window enumeration first.

  4. Do not test credential dialogs, security settings, terminals, Codex itself, or other privileged surfaces.

  5. Remove the explicit sandbox_private_desktop = false line after the test, or restore it to its prior value, then fully restart Codex again.

Success means you identified the boundary and restored the stronger default afterward. Leaving the compatibility setting enabled is a separate risk decision that should follow your organization's security policy and OpenAI's current guidance.

Verify the Rollback

After removing the temporary override, fully restart Codex and repeat the read-only listing prompt.

Expected result: the original behavior returns if the issue is still present upstream. That may feel like a failed repair, but it proves the rollback restored the stronger isolation boundary and that the compatibility test was causal.

If a future Codex or Computer Use update fixes the issue, test again with the private desktop enabled. Do not preserve a weaker compatibility setting after the supported path works.

For a case where Computer Use is missing only from project tasks but available elsewhere, follow the project capability visibility guide instead.

Keep External Work Moving Without UI Control

While the upstream Windows boundary is unresolved, use typed provider Actions for tasks that do not require screen control. Aident Loadout can search a connected service, inspect the current schema, estimate cost, and run one bounded read-only Action without exposing a provider key to the prompt.

Give Codex the canonical setup instruction:

Follow https://aident.ai/SETUP.md

Then use this prompt:

Check my Aident Loadout account and Vault status. Search the staging capability catalog for a connected read-only Hacker News search Action, inspect its current schema, and preflight it. If the estimate is free, search for "Codex Computer Use Windows" and return only matching titles and URLs. Do not publish, comment, edit, install, change files, or ask me for a provider key.

Success is measurable: account status, Vault status, discovery, schema inspection, preflight, and one read-only search complete without Computer Use; no provider credential appears; and no external write occurs. Set up Aident Loadout and run the read-only alternative.

Sources

Refresh this guide when issues 37043, 37255, or 37383 change state, OpenAI changes the sandbox_private_desktop guidance, a Computer Use release restores private-desktop enumeration, or the compatibility setting no longer affects the failure.

Home

Home

Home

Integrations

Integrations

Integrations

Vault

Vault

Vault

Audit

Audit

Audit

Arana Grande

Arana Grande

Arana Grande

Free

Free

Free

30-day audit summary

30-day audit summary

30-day audit summary

Daily action-call volume and the latest receipts from the Loadout audit trail.

Daily action-call volume and the latest receipts from the Loadout audit trail.

Daily action-call volume and the latest receipts from the Loadout audit trail.

View Audit

View Audit

View Audit

Loadout usage

Loadout usage

Loadout usage

617 action calls in the last 30 days

617 action calls in the last 30 days

617 action calls in the last 30 days

May 19 - Jun 17

May 19 - Jun 17

May 19 - Jun 17

10 active days

10 active days

10 active days

Less

Less

Less

More

More

More

Recent activity

Recent activity

Recent activity

Latest action-call receipts from connected agents

Latest action-call receipts from connected agents

Latest action-call receipts from connected agents

Apr 23, 09:23 AM

Apr 23, 09:23 AM

Apr 23, 09:23 AM

Shopify

Shopify

Shopify

Creates Or Updates An Asset For A Theme

Creates Or Updates An Asset For A Theme

Creates Or Updates An Asset For A Theme

Success

Success

Success

Apr 23, 09:21 AM

Apr 23, 09:21 AM

Apr 23, 09:21 AM

Shopify

Shopify

Shopify

Update Products Param Product Id

Update Products Param Product Id

Update Products Param Product Id

Success

Success

Success

Apr 23, 08:53 AM

Apr 23, 08:53 AM

Apr 23, 08:53 AM

Shopify

Shopify

Shopify

Update Products Param Product Id

Update Products Param Product Id

Update Products Param Product Id

Failed

Failed

Failed

Apr 22, 22:13 PM

Apr 22, 22:13 PM

Apr 22, 22:13 PM

Shopify

Shopify

Shopify

Create Product Image

Create Product Image

Create Product Image

Success

Success

Success

Apr 22, 22:12 PM

Apr 22, 22:12 PM

Apr 22, 22:12 PM

Shopify

Shopify

Shopify

Create Product Image

Create Product Image

Create Product Image

Success

Success

Success

Connected integration coverage

Connected integration coverage

Connected integration coverage

162

162

162

of 753 accessible connected

of 753 accessible connected

of 753 accessible connected

Callable actions

Callable actions

Callable actions

1,126

1,126

1,126

Vault credentials

Vault credentials

Vault credentials

8

8

8

Explore what's possible

Explore what's possible

Explore what's possible

See all Integrations

See all Integrations

See all Integrations

Google Ads

Google Ads

Google Ads

All available Goolge Ads tools via...

All available Goolge Ads tools via...

All available Goolge Ads tools via...

X (twitter)

X (twitter)

X (twitter)

All available X tools via...

All available X tools via...

All available X tools via...

Github

Github

Github

All available Github tools via...

All available Github tools via...

All available Github tools via...

Notion

Notion

Notion

All available Notion tools via...

All available Notion tools via...

All available Notion tools via...

Slack

Slack

Slack

All available Slack tools via...

All available Slack tools via...

All available Slack tools via...

Firecrawl

Firecrawl

Firecrawl

All available Firecrawl tools via...

All available Firecrawl tools via...

All available Firecrawl tools via...

753 integrations are available for loadouts.

753 integrations are available for loadouts.

753 integrations are available for loadouts.

The one tool

for every tool

your agent needs.

Give any AI agent real capabilities in seconds. Connect 1,000+ tools once, skip the setup headache, and let your agents execute.

Try Aident Loadout

Give your Agent real capabilities in minutes. Connect 1,000+ tools, and let your agents execute.

Try Aident Loadout

Give your Agent real capabilities in minutes. Connect 1,000+ tools, and let your agents execute.

Try Aident Loadout

Give your Agent real capabilities in minutes. Connect 1,000+ tools, and let your agents execute.