Mike HolpStart hereAll videos

Build guide · By · Published

Use Codex to make a change you can verify.

This Codex tutorial takes one small task from a brief to a checked diff: add a malformed-JSON check to this site’s local API example. You will finish with a script that verifies a failure case as well as the existing successful request.

Bring Git, Node.js 22 or later, and a configured coding assistant. The exercise makes only local requests and needs no provider key. Your coding assistant may have its own usage charges. No Skool membership is needed to read or run it.

1. Start from a working example

git clone https://github.com/mikeholp87/ai-income-lab.git
cd ai-income-lab
git switch -c practice/api-json-check
node public/examples/first-api-request.mjs

No npm install is needed for this example. It uses Node’s built-in modules, starts a server on loopback, checks three requests, and closes it. Read the API request guide if keys, models, and status codes are new to you.

The baseline prints HTTP 401 for the wrong key, HTTP 404 for an unknown model, HTTP 200 for a valid request, and a PASS line. Save this output before changing anything. If it fails already, resolve that failure first.

2. Give Codex a concrete brief

Open the cloned folder in your coding client. Ask it to inspect public/examples/first-api-request.mjs, then use this brief:

Add one executable check for malformed JSON to this local example.
Send an incomplete JSON body with the valid demo key.
Assert HTTP 400 and the existing "Invalid JSON" error.
Keep the three existing checks, timeout, redirect handling, and cleanup.
Use only built-in Node modules. Do not connect a real provider.
Run the example and show the diff and output. Do not commit or push.

This is an author-written practice task using the public repository, separate from the recorded Codex internal-link audit. Both use the same useful sequence: inspect, change, check, and review. The exact client buttons and model names are not part of the exercise.

3. Check the proposed change

The server already catches invalid JSON and replies with status 400. The missing piece is a request that exercises that branch. A minimal addition inside the existing try block, after the request loop and before the PASS message, can look like this:

const malformed = await fetch(endpoint, {
  method: 'POST',
  redirect: 'error',
  signal: AbortSignal.timeout(5000),
  headers: {
    'Content-Type': 'application/json',
    Authorization: 'Bearer demo-only',
  },
  body: '{',
});
assert.equal(malformed.status, 400);
assert.deepEqual(await malformed.json(), { error: 'Invalid JSON' });
console.log('Malformed JSON: HTTP 400');

Use the valid demo key so the request reaches JSON parsing. A wrong key would test authentication again. Keep the request inside the try block so the existing finally still closes the server on failure.

4. Run it and inspect the diff

node public/examples/first-api-request.mjs
git diff --check
git diff -- public/examples/first-api-request.mjs
git status --short

Expect the original three status lines, then Malformed JSON: HTTP 400, then PASS. Check that only your intended file changed. A passing script is evidence for these four checks; it does not establish a real provider connection or a comprehensive security review.

When the result is wrong

Continue with a real project

Read the source example, then try the React YouTube-feed build. The OpenCode desktop build shows why launching an app and checking saved data matter even after compilation passes.