Skip to content

[Codex OAuth/Windows] Account switch can omit account_id or select revoked token, causing workspace routing 401 loop #2671

Description

@beautyarbutin

Summary

On Windows, switching a ChatGPT/Codex OAuth account in Cockpit Tools 1.3.63 can leave the official Codex desktop app in a retry loop with:

workspace routing discovery failed

The underlying API response is:

GET https://chatgpt.com/backend-api/wham/usage
401 Unauthorized
code: token_revoked

In a separate switch, Cockpit wrote a fresh OAuth token but omitted tokens.account_id from D:\\code\\.codex\\auth.json. The official Codex app then repeatedly reports workspace routing unavailable and the usage panel stays blank.

Environment

  • Windows 11
  • Cockpit Tools 1.3.63
  • Codex desktop from Microsoft Store: 26.928.1915.0
  • Codex data directory: D:\\code\\.codex
  • ChatGPT OAuth authentication
  • Codex executable selected by Cockpit: C:\\Program Files\\WindowsApps\\OpenAI.Codex_26.928.1915.0_x64__2p2nqsd0c76g0\\app\\ChatGPT.exe

Reproduction

  1. Keep the official Codex desktop app running.
  2. In Cockpit Tools, switch to a stored Codex OAuth account.
  3. Use the normal switch action, or switch and launch.
  4. The Codex app is closed/restarted and shortly afterwards the usage request fails. The UI shows workspace routing discovery failed and keeps retrying.
  5. Inspect D:\\code\\.codex\\auth.json.

Observed variants:

  • The selected account token is already revoked by the upstream service; Cockpit still writes/selects it and keeps polling usage instead of marking the account invalid and stopping retries.
  • After a switch, auth.json contains valid access_token, id_token, and refresh_token, but tokens.account_id is missing. The account ID is present in the JWT claim https://api.openai.com/auth.chatgpt_account_id.
  • Cockpit's selected account and the account currently logged into the official Codex app can become different.

Evidence

For the affected account, the stored token was issued on 2026-09-27 and the first failure after switching occurred on 2026-09-30:

2026-09-30T18:13:33+08:00
GET /backend-api/wham/usage
401 Unauthorized
detail_code=token_revoked

For another switch, the official Codex app log repeatedly showed:

Workspace routing is unavailable
ChatGPT account ID not available, please re-run codex login

Adding the JWT-derived tokens.account_id and restarting the official app restores account/read and account/rateLimits/read.

Expected behavior

  • Write a complete official Codex auth.json, including auth_mode: "chatgpt", tokens.account_id, and all required token fields.
  • Validate the selected token before closing the running Codex app.
  • If upstream returns token_revoked, mark that stored account invalid and stop polling; do not overwrite the currently working official credential.
  • After a successful switch, verify that the official Codex app is using the same account that Cockpit selected.
  • The plain “Switch” action should either leave Codex running on the previous account or clearly state that it only changes stored credentials. “Switch and launch” should be the explicit close/restart flow.

Workaround

Disable Codex auto refresh and token keeper, use “Switch and launch” only, and manually re-login revoked accounts through the official Codex/ChatGPT OAuth flow.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions