When adding a ChatGPT Team account to Codex Auth, opencodex rejects it as:
Account is already used by the main Codex login.
In my case the main Codex login and the account being added have different emails and different user ids, but their JWTs share the same https://api.openai.com/auth.chatgpt_account_id.
Observed locally:
- main Codex auth email:
test_account1@gmail.com
- added OAuth email:
test_account2@gmail.com
- both tokens report the same
chatgpt_account_id
- user ids /
sub differ
This looks like chatgpt_account_id can identify the Team/workspace account, not the individual user. checkAccountIdCollision() currently treats a matching main chatgpt_account_id as a duplicate unconditionally.
I tested a local fix:
- extract email from
https://api.openai.com/profile.email
- only treat the main Codex login as duplicate when both account id and email match, or when email is unavailable
- keep the existing pool collision behavior scoped by plan bucket
Validation:
bun test tests/chatgpt-oauth.test.ts tests/codex-auth-collision.test.ts
bun run typecheck
If that approach sounds reasonable, I’m happy to open a small PR.
When adding a ChatGPT Team account to Codex Auth, opencodex rejects it as:
In my case the main Codex login and the account being added have different emails and different user ids, but their JWTs share the same
https://api.openai.com/auth.chatgpt_account_id.Observed locally:
test_account1@gmail.comtest_account2@gmail.comchatgpt_account_idsubdifferThis looks like
chatgpt_account_idcan identify the Team/workspace account, not the individual user.checkAccountIdCollision()currently treats a matching mainchatgpt_account_idas a duplicate unconditionally.I tested a local fix:
https://api.openai.com/profile.emailValidation:
bun test tests/chatgpt-oauth.test.ts tests/codex-auth-collision.test.tsbun run typecheckIf that approach sounds reasonable, I’m happy to open a small PR.