openai / openai/codex

Desktop connector plugins lose ChatGPT authentication with command-auth custom model provider

Open
#40,610 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app app-server auth bug custom-model
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What version of the Codex App are you using (From “About Codex” dialog)?

26.818.61809 (build 7019)

What subscription do you have?

Plus

What platform is your computer?

Darwin 25.3.0 arm64 arm

What issue are you seeing?

Connector-backed plugins fail to load when a command-authenticated custom model provider is active, even though Codex is separately signed in with ChatGPT.

The visible error is:

Failed to load plugin connection

Connector requests fail with:

401 Unauthorized: Access token is missing

A credential-redacted app-server control test showed:

  • Custom command-auth provider active:
    authMethod = null
    requiresOpenaiAuth = false
    no ChatGPT credential returned

  • Built-in OpenAI provider selected using a transient override, with the same unchanged login:
    authMethod = "chatgpt"
    requiresOpenaiAuth = true
    ChatGPT credential present

codex login status reports Logged in using ChatGPT in both cases.

The desktop appears to derive the ChatGPT backend credential from the active model provider’s authentication mode. It also caches the missing-credential result, while the 401 retry path does not refresh when no credential was originally attached.

What steps can reproduce the bug?
  1. Sign in to Codex using ChatGPT.
  2. Configure a custom Responses API provider using command-backed bearer authentication.
  3. Select the custom provider globally.
  4. Restart the desktop app.
  5. Attempt to install any connector-backed curated plugin.
  6. The app displays “Failed to load plugin connection” before the connection flow starts.
  7. Temporarily selecting the built-in OpenAI provider restores the ChatGPT credential in a redacted app-server probe.

Generic configuration shape:

model_provider = "custom"

[model_providers.custom]
name = "Custom"
base_url = "https://example.invalid/v1"
wire_api = "responses"

[model_providers.custom.auth]
command = "credential-helper"
args = []

The endpoint and command above are non-functional placeholders.

What is the expected behavior?

ChatGPT account authentication and custom model-provider authentication should remain independent.

Connector and ChatGPT backend requests should use the existing ChatGPT session, while inference requests use the custom provider’s command-backed credential.

Additional information

Troubleshooting already performed:

  • Restarted the app.
  • Logged out and signed back in.
  • Completely removed and reinstalled the current OpenAI-distributed app.
  • Reset the desktop application profile.

The behavior remained unchanged.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Reproduce the failure with a command-authenticated custom provider selected, then compare the app-server control test results with the built-in OpenAI provider override. Trace how the active provider determines the ChatGPT credential and how the 401 retry handles a missing cached credential; done means connector requests use the existing ChatGPT session while inference continues using the custom provider credential.

Written by the indexing model from the issue text.

Assessment

Tech stack
macos
Domain
authentication, desktop
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Active
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.