YubiKey / hardware security key login loop in Codex Desktop for Windows
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
What version of the Codex App are you using (From “About Codex” dialog)?
26.820.60940
What subscription do you have?
Plus
What platform is your computer?
Microsoft Windows NT 10.0.26100.0 x64
What issue are you seeing?
After enabling Advanced Account Security, I can successfully authenticate with my YubiKey when Codex starts. But as soon as I open a project or chat, Codex asks me to authenticate again. After successful YubiKey login it returns to the project, and opening the chat immediately triggers the login flow again - endless loop.
The hardware-key authentication itself succeeds; the Windows Codex Desktop session just doesn’t stay authenticated.
This currently makes Codex Desktop practically unusable for users who are required to use physical security keys.
What steps can reproduce the bug?
-
Use Codex Desktop on Windows with an OpenAI account that has Advanced Account Security enabled and requires authentication with a physical FIDO2 hardware security key (YubiKey).
-
Launch Codex Desktop.
-
Complete the login flow using the YubiKey. Authentication succeeds and Codex opens normally.
-
Select an existing project.
-
Open any existing chat/thread inside that project.
-
Codex immediately starts the login flow again.
-
Authenticate again successfully with the same YubiKey.
-
Codex returns to the project view.
-
Open the chat/thread again.
-
The login flow starts again.
This repeats indefinitely.
What is the expected behavior?
Expected behavior:
After successfully authenticating with the YubiKey, Codex Desktop should preserve the authenticated session and allow projects and chats to open normally.
Actual behavior:
YubiKey authentication succeeds, but opening a project/chat causes Codex Desktop to request authentication again, resulting in an endless authentication loop.
Additional information
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the login flow in Codex Desktop on Windows with Advanced Account Security and a YubiKey, then trace what happens when opening an existing project and chat. The work is done when successful hardware-key authentication persists and projects and chats open without restarting the login flow.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- rust
- Domain
- authentication, desktop
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100