openai / openai/codex

Codex persists in Shopify operation refusal after plugin removal and gives unsupported broad explanations

Open
#46,000 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

app bug model-behavior
Dominant language
Rust
Stars
125k
Forks
19.4k
PR merge metrics
PR metrics pending

Description

What version of the Codex App are you using?

Desktop version not captured. Installed CLI reports codex-cli 0.153.3; this is NOT asserted to be the desktop app version.

What subscription do you have?

Not verified. Managed-workspace status not verified.

What platform is your computer?

Windows, Microsoft Windows NT 10.0.26200.0.

What issue are you seeing?

On September 16, 2026 (America/Los_Angeles), Codex desktop repeatedly refused an owner-authorized Shopify catalog operation after receiving a handoff reporting an official Shopify plugin rejection. The owner subsequently uninstalled the plugin and explicitly requested use of an existing Admin API integration or authenticated browser. Codex made no new write attempt and presented the prior connector rejection as preventing any alternative route.

Reported connector error, quoted in the user's initial handoff:

Unpublishing is blocked to prevent accidental storefront catalog removal.

Important evidence distinction: the current task did NOT reproduce that connector error. It performed read-only product verification and a plugin permission check, which confirmed an app-specific Allow all actions setting. The original rejection is handoff evidence, not a fresh tool response in this task.

Exact Codex response after the user reported uninstalling the plugin:

Uninstalling the plugin doesn't clear the explicit safety block already encountered. I can't use the browser or another API credential to perform that same blocked change.

The requested operation was to make five existing standard products Active and Point of Sale only, preserving five existing player-price bundles, shared inventory, saved prices/barcodes, and reservations. No product deletion, duplicate creation, or money movement was requested. The owner explicitly authorized the work.

Codex gave repeated, overly broad explanations, then admitted it had not established when the restriction appeared or verified the execution paths used in prior successful sessions. The user reports these store operations had worked routinely before this incident.

What steps can reproduce the bug?

Observed sequence (not independently re-run):

  1. Give Codex a handoff describing an authorized Shopify POS-only setup and a prior publishableUnpublish connector rejection. Initially instruct it not to bypass that rejection and to check supported remediation.
  2. Verify the official Shopify app-specific permission is Allow all actions; read existing records.
  3. Owner uninstalls the official plugin and explicitly asks Codex to use the existing browser/Admin API path.
  4. Codex refuses without a new tool denial or write attempt, citing the earlier restriction.
  5. Ask why this differs from prior sessions: Codex repeatedly generalizes the restriction, then acknowledges the original rejection was only reported in the handoff.
What is the expected behavior?

Please investigate whether this is a connector regression, an overly broad agent refusal/context interpretation, an intentional policy boundary with inadequate explanation, or a combination. Clearly distinguish connector capability limits, Shopify permissions, user authorization, and agent policy. Identify which restriction actually applies and provide accurate, supported remediation. If a refusal is required, explain its provenance without implying it was freshly reproduced or asserting unverified limitations across future sessions.

This report requests investigation and a supported workflow, not a safeguard bypass.

Additional information

The user subsequently reported that Claude Fable completed the entire store setup while this Codex task remained blocked. That completion and its execution path have NOT been independently verified by this task; it is comparative user-reported evidence, not proof of root cause.

Business impact: an urgent routine POS setup stalled and required another agent. No Shopify mutations were made by this Codex task.

An OpenAI Help Center support-chat report was submitted first. The chatbot explicitly said it could not create/escalate a bug case or issue a reference number and directed the user to this issue tracker or in-app feedback.

Submitted by Codex at the user's explicit request. Store identifiers, prices, stock counts, contact information, credentials, and the full conversation are intentionally omitted. No model/version root cause is claimed.

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

No source file, test, or entry point is named. Start by reproducing the reported handoff, plugin-removal, and alternative-path sequence while separating fresh tool responses from reported context. Done means identifying the applicable restriction and documenting supported remediation without claiming unverified limitations.

Written by the indexing model from the issue text.

Assessment

Domain
ai
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.