Client or integration
Codex CLI + Codex App (Desktop)
Area
CLI
Summary
ocx start auto-injects openai_base_url and overwrites provider config, breaking Codex Desktop on networks that cannot reach chatgpt.com.
When model_provider is already set to a custom provider (e.g. "deepseek"), ocx start should not inject openai_base_url. The injection forces Codex to treat the openai provider as the primary route, which conflicts with the user's explicit provider choice.
Reproduction
Attempt 1: ocx sync (recommended approach)
- Set
model_provider = "deepseek" in config.toml
- Run
ocx sync
- Observe:
model_provider changed from "deepseek" to "openai", and openai_base_url = "http://127.0.0.1:10100/v1" injected
- Restart Codex Desktop → ChatGPT OAuth login required → corporate network blocks
chatgpt.com → locked out
Attempt 2: Manual provider config (Design B)
- Manually add
[model_providers.opencodex] to config.toml (without ocx sync)
- CLI works:
codex -p opencodex routes through proxy
- Desktop works:
model_provider = "deepseek" uses API Key auth
Attempt 3: Make Desktop also use opencodex
- Set
model_provider = "opencodex" in config.toml
- Run
ocx start
- Observe:
ocx start auto-injects openai_base_url, causing Codex Desktop to show ChatGPT login page again
- During injection,
model and model_provider lines removed from config.toml → config destroyed
Version
@bitkyc08/opencodex v2.10.0
Operating system
Windows 11 x64, Node.js v24.16.0, Codex CLI v0.146.0
Provider and model
deepseek / deepseek-v4-flash
Logs or error output
# When using sandbox = "elevated" on Windows:
SetTokenInformation(TokenDefaultDacl) failed: 1344
# Workaround: change to sandbox = "unelevated"
Screenshots and supporting files
N/A
Redacted configuration
{
"model": "deepseek-v4-flash",
"model_provider": "deepseek",
"model_providers": {
"opencodex": {
"name": "opencodex",
"base_url": "http://127.0.0.1:10100/v1",
"wire_api": "responses",
"env_key": "CODEX_DEEPSEEK_API_KEY"
}
},
"windows": {
"sandbox": "unelevated"
}
}
Checks
Note: This issue was generated with AI assistance. The author is not a developer but a power user exploring opencodex integration on corporate networks.
Client or integration
Codex CLI + Codex App (Desktop)
Area
CLI
Summary
ocx startauto-injectsopenai_base_urland overwrites provider config, breaking Codex Desktop on networks that cannot reachchatgpt.com.When
model_provideris already set to a custom provider (e.g."deepseek"),ocx startshould not injectopenai_base_url. The injection forces Codex to treat theopenaiprovider as the primary route, which conflicts with the user's explicit provider choice.Reproduction
Attempt 1:
ocx sync(recommended approach)model_provider = "deepseek"in config.tomlocx syncmodel_providerchanged from"deepseek"to"openai", andopenai_base_url = "http://127.0.0.1:10100/v1"injectedchatgpt.com→ locked outAttempt 2: Manual provider config (Design B)
[model_providers.opencodex]to config.toml (withoutocx sync)codex -p opencodexroutes through proxymodel_provider = "deepseek"uses API Key authAttempt 3: Make Desktop also use opencodex
model_provider = "opencodex"in config.tomlocx startocx startauto-injectsopenai_base_url, causing Codex Desktop to show ChatGPT login page againmodelandmodel_providerlines removed from config.toml → config destroyedVersion
@bitkyc08/opencodexv2.10.0Operating system
Windows 11 x64, Node.js v24.16.0, Codex CLI v0.146.0
Provider and model
deepseek / deepseek-v4-flash
Logs or error output
Screenshots and supporting files
N/A
Redacted configuration
{ "model": "deepseek-v4-flash", "model_provider": "deepseek", "model_providers": { "opencodex": { "name": "opencodex", "base_url": "http://127.0.0.1:10100/v1", "wire_api": "responses", "env_key": "CODEX_DEEPSEEK_API_KEY" } }, "windows": { "sandbox": "unelevated" } }Checks