Skip to content

ocx start auto-injects openai_base_url and overwrites provider config, breaking Codex Desktop on networks that cannot reach chatgpt.com #1090

Description

@majia3592

Client or integration

Codex CLI + Codex App (Desktop)

Area

CLI

Summary

ocx start auto-injects openai_base_url and overwrites provider config, breaking Codex Desktop on networks that cannot reach chatgpt.com.

When model_provider is already set to a custom provider (e.g. "deepseek"), ocx start should not inject openai_base_url. The injection forces Codex to treat the openai provider as the primary route, which conflicts with the user's explicit provider choice.

Reproduction

Attempt 1: ocx sync (recommended approach)

  1. Set model_provider = "deepseek" in config.toml
  2. Run ocx sync
  3. Observe: model_provider changed from "deepseek" to "openai", and openai_base_url = "http://127.0.0.1:10100/v1" injected
  4. Restart Codex Desktop → ChatGPT OAuth login required → corporate network blocks chatgpt.com → locked out

Attempt 2: Manual provider config (Design B)

  1. Manually add [model_providers.opencodex] to config.toml (without ocx sync)
  2. CLI works: codex -p opencodex routes through proxy
  3. Desktop works: model_provider = "deepseek" uses API Key auth

Attempt 3: Make Desktop also use opencodex

  1. Set model_provider = "opencodex" in config.toml
  2. Run ocx start
  3. Observe: ocx start auto-injects openai_base_url, causing Codex Desktop to show ChatGPT login page again
  4. During injection, model and model_provider lines removed from config.toml → config destroyed

Version

@bitkyc08/opencodex v2.10.0

Operating system

Windows 11 x64, Node.js v24.16.0, Codex CLI v0.146.0

Provider and model

deepseek / deepseek-v4-flash

Logs or error output

# When using sandbox = "elevated" on Windows:
SetTokenInformation(TokenDefaultDacl) failed: 1344

# Workaround: change to sandbox = "unelevated"

Screenshots and supporting files

N/A

Redacted configuration

{
  "model": "deepseek-v4-flash",
  "model_provider": "deepseek",
  "model_providers": {
    "opencodex": {
      "name": "opencodex",
      "base_url": "http://127.0.0.1:10100/v1",
      "wire_api": "responses",
      "env_key": "CODEX_DEEPSEEK_API_KEY"
    }
  },
  "windows": {
    "sandbox": "unelevated"
  }
}

Checks

  • I searched existing issues and documentation.
  • I removed secrets, tokens, account details, request credentials, and personal data.

Note: This issue was generated with AI assistance. The author is not a developer but a power user exploring opencodex integration on corporate networks.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    account-poolOAuth, credentials, Codex pool, quota, failover, plansbugSomething isn't workingcliCLI, config inject, packaging flags

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions