garrytan / garrytan/gstack

Document Codex refresh_token_reused recovery when Hermes auth still works

Open
#1,542 1 comment 0 reactions 0 assignees View on GitHub
Dominant language
TypeScript
Stars
133k
Forks
19.9k
Avg merge
18h 46m
Merged PRs (30d)
26

Description

## Problem
When Codex CLI reports `refresh_token_reused`, the current recovery guidance can send users straight to `codex login` even if Hermes' `openai-codex` provider still has fresh working tokens. That creates a split-brain auth situation: Hermes works, standalone `codex exec` fails.

## Expected behavior
The Codex skill should distinguish a Hermes provider outage from a stale standalone Codex CLI credential store, and suggest repairing the standalone auth file only after a Hermes smoke test proves the provider route still works.

## Current downstream workaround
A local downstream skill patch adds guidance to verify Hermes `openai-codex`, repair the standalone CLI credential store from Hermes tokens via a helper script, chmod the auth file, then re-test `codex exec`.

## Notes
This is documentation/runbook guidance only; it does not change Codex or Hermes auth behavior.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.