1- // OAuth constants for the Codex (ChatGPT Plus/Pro subscription) login flow.
2- // These values mirror the public Codex CLI client: the client id is a public
3- // identifier (not a secret), and the endpoints belong to OpenAI's consumer
4- // authorization server at auth.openai.com — distinct from the platform API key
5- // system at platform.openai.com.
6- //
7- // A successful login yields a token billed against the user's ChatGPT
8- // subscription. The inference base URL is chatgpt.com/backend-api, which is
9- // OpenAI-compatible but a different surface from api.openai.com.
1+ import { CODEX_REDIRECT_URI } from "@corbits/codex-provider" ;
102
11- // Public client identifier for the Codex CLI authorization flow. Not a secret.
12- export const CODEX_CLIENT_ID = "app_EMoamEEZ73f0CkXaXp7hrann" ;
3+ export {
4+ CODEX_BASE_URL ,
5+ CODEX_REDIRECT_URI ,
6+ CODEX_REFRESH_SKEW_MS ,
7+ CODEX_RESPONSES_PATH ,
8+ } from "@corbits/codex-provider" ;
139
14- export const CODEX_AUTHORIZE_URL = "https://auth.openai.com/oauth/authorize" ;
15- export const CODEX_TOKEN_URL = "https://auth.openai.com/oauth/token" ;
10+ const codexRedirect = new URL ( CODEX_REDIRECT_URI ) ;
11+ export const CODEX_CALLBACK_PORT = Number ( codexRedirect . port ) ;
12+ export const CODEX_CALLBACK_PATH = codexRedirect . pathname ;
1613
17- // Token refresh runs on the send path before inference, outside the harness
18- // timers, so the request must abort rather than hang the agent if the endpoint
19- // stalls.
20- export const CODEX_TOKEN_TIMEOUT_MS = 15_000 ;
21-
22- // The Codex CLI registers a fixed loopback redirect on port 1455; the
23- // authorization server only accepts this exact redirect_uri for this client, so
24- // (unlike the MCP flow) the callback port is not free to vary.
25- export const CODEX_CALLBACK_PORT = 1455 ;
26- export const CODEX_CALLBACK_PATH = "/auth/callback" ;
27- export const CODEX_REDIRECT_URI = `http://localhost:${ String ( CODEX_CALLBACK_PORT ) } ${ CODEX_CALLBACK_PATH } ` ;
28-
29- export const CODEX_SCOPES = [
30- "openid" ,
31- "profile" ,
32- "email" ,
33- "offline_access" ,
34- ] as const ;
35-
36- // Inference surface reached with the subscription token. NOTE: the Codex
37- // backend serves the OpenAI *Responses* API at `${CODEX_BASE_URL}/codex/
38- // responses`, not Chat Completions, and requires a `chatgpt-account-id` header
39- // (see CodexTokens.accountId) plus `OpenAI-Beta: responses=experimental`. The
40- // Responses adapter is tracked as follow-up work; this base + the stored
41- // accountId are the inputs it needs.
42- export const CODEX_BASE_URL = "https://chatgpt.com/backend-api" ;
43- export const CODEX_RESPONSES_PATH = "/codex/responses" ;
4414// Live usage/quota for the prepaid plan (window %, reset, credits) and the
4515// account's available model catalog. The models endpoint requires a
4616// client_version query param.
4717export const CODEX_USAGE_PATH = "/codex/usage" ;
4818export const CODEX_MODELS_PATH = "/codex/models" ;
4919export const CODEX_CLIENT_VERSION = "0.50.0" ;
5020
51- // Extra authorize-request params the Codex flow requires.
52- export const CODEX_AUTHORIZE_EXTRA_PARAMS : Record < string , string > = {
53- codex_cli_simplified_flow : "true" ,
54- id_token_add_organizations : "true" ,
55- originator : "codex_cli_rs" ,
56- } ;
21+ // Client identity the Codex backend expects on usage/model requests, matching
22+ // the public Codex CLI originator.
23+ export const CODEX_ORIGINATOR = "codex_cli_rs" ;
5724
5825// Fallback model list, used only when the live catalog (GET /codex/models) is
5926// unavailable — e.g. while rate-limited it returns an empty list. The Codex
@@ -70,10 +37,6 @@ export const CODEX_DEFAULT_MODELS = [
7037 "gpt-5.4-mini" ,
7138] as const ;
7239
73- // Refresh a token this many milliseconds before its stated expiry so a request
74- // is never sent with a token about to lapse mid-flight.
75- export const CODEX_REFRESH_SKEW_MS = 60_000 ;
76-
7740// How often a headless run re-checks its Codex token and reseeds the source.
7841// Half the skew so the refresh window is never missed between ticks.
7942export const CODEX_HEADLESS_REFRESH_INTERVAL_MS = 30_000 ;
0 commit comments