Public Incident Report: OpenAI Codex credits exhausted without corresponding attributable usage
Nobody has claimed this yet.
- Dominant language
- Rust
- Stars
- 125k
- Forks
- 19.4k
- PR merge metrics
- PR metrics pending
Description
What version of the IDE extension are you using?
26.908.31748
What subscription do you have?
Business
Which IDE are you using?
Visual Studio Code
What platform is your computer?
Windows 11 Pro
What issue are you seeing?
Public Incident Report — GM Web Tech Lab
On September 10, 2026, OpenAI notified our workspace that it was “out of credits.”
I formally dispute this accounting result.
Based on the usage information available to me, there is no corresponding activity capable of explaining the reported credit depletion. The workspace had available credits before the event, and the usage performed afterwards does not reconcile with the balance subsequently reported by OpenAI.
I initially reported the issue privately to OpenAI Support on September 11 and requested an investigation and recalculation.
During the investigation I also identified a possible reproduction scenario.
Two users belonging to the same Team used Codex from the same computer. One user, whose usage allowance was close to exhaustion, logged out of Codex. Another Team user, whose 5-hour allowance was still at 100%, subsequently logged in on the same machine.
My current hypothesis is that some part of the Codex session, metering or account-attribution state may have remained associated with the previous user and that subsequent usage may consequently have been attributed incorrectly.
This is a hypothesis regarding the root cause, not a statement that the root cause has already been proven.
The observable issue is simpler: OpenAI's system reports credits as exhausted, while I cannot identify corresponding attributable usage that explains their depletion.
I therefore publicly dispute those credit deductions and request that OpenAI provide an auditable reconciliation of the account.
Specifically, I am requesting sufficient information to associate the disputed consumption with actual activity: timestamps, user/workspace attribution, Codex task or thread attribution where available, model or workload involved, credits charged, and the balance before and after the disputed operations.
If legitimate activity can account for the missing credits, such a ledger should make the discrepancy straightforward to resolve.
If no corresponding activity exists, the credits should be restored and the underlying accounting or session-attribution defect investigated.
This request is particularly reasonable because OpenAI has previously acknowledged incidents affecting Codex usage limits. On September 9, OpenAI reported that some Codex users were experiencing unexpected usage-limit resets. In June, OpenAI also investigated Codex usage limits depleting faster than expected.
I am not claiming that either previous incident is the same defect affecting this case. They simply demonstrate why discrepancies involving usage accounting deserve technical investigation rather than being dismissed on the assumption that the displayed balance must necessarily be correct.
I contacted OpenAI privately before publishing this report and provided time for the matter to be investigated. I am publishing it now because I have not yet received a substantive explanation or a reconciliation of the disputed consumption.
My allegation is therefore precise:
OpenAI's Codex accounting system appears to have exhausted credits belonging to GM Web Tech Lab without corresponding attributable usage being visible or explained to us.
I am asking OpenAI either to provide the usage records that justify those deductions or to restore the incorrectly deducted credits.
I will update this incident publicly when OpenAI responds, including correcting the report if the accounting records demonstrate that the disputed consumption was legitimate.
- Status: OPEN
Impact: Codex usage unavailable despite disputed remaining credits
First observed: September 10, 2026
Reported privately: September 11, 2026
Public escalation: September 11, 2026
What steps can reproduce the bug?
I cannot currently confirm that this reproduces the issue deterministically.
However, the following sequence immediately preceded the disputed credit depletion and may be relevant to the root cause:
Possible reproduction scenario
-
Two different users belong to the same ChatGPT Business/Team workspace.
-
User A was using Codex on a Windows computer and was close to exhausting their current Codex usage allowance.
-
User A logged out of Codex on that computer.
-
User B, belonging to the same workspace, then logged into Codex on the same computer.
-
At the time User B logged in, User B's 5-hour usage allowance was showing 100% available.
-
Codex activity was subsequently performed while authenticated as User B.
-
Later, the workspace/account was reported as "out of credits", despite the available usage information not showing corresponding activity sufficient to explain the credit depletion.
Suspected behavior
My current hypothesis is that some session, metering, usage-accounting, or account-attribution state may have persisted after the logout/login transition and caused subsequent consumption to be attributed incorrectly.
This is only a root-cause hypothesis. I have not been able to verify OpenAI's server-side metering state.
Actual result
Credits were reported as exhausted, but I cannot reconcile the deducted credits with the attributable Codex usage visible to us.
Expected result
Usage generated after User B authenticated should be:
- attributed only to User B / the correct workspace context;
- charged exactly once;
- reflected consistently in the available usage indicators and credit balance;
- completely independent from User A's previous authenticated session.
Logging out User A and authenticating User B on the same machine should not preserve any billing, quota, or metering attribution associated with User A.
Additional notes
This issue cannot be reproduced using a code snippet because it appears to concern server-side Codex usage metering/account attribution rather than application code.
I am willing to provide OpenAI with the relevant timestamps, workspace/account information, and additional details privately if needed for tracing the corresponding server-side usage records.
What is the expected behavior?
not beign out of credits.
Additional information
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
No repository file, test, or entry point is mentioned; first determine whether this repository owns the server-side metering or account-attribution behavior. Done would require a reproducible failure or traceable usage evidence showing that credits are attributed correctly after one user logs out and another logs in.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- vscode
- Domain
- backend
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Active
- Clarity
- Mostly clear
- Newbie friendliness
- 25/100