Skip to content

Codex Auth incorrectly treats different Team users as duplicate main login #51

Description

@mincia1110

When adding a ChatGPT Team account to Codex Auth, opencodex rejects it as:

Account is already used by the main Codex login.

In my case the main Codex login and the account being added have different emails and different user ids, but their JWTs share the same https://api.openai.com/auth.chatgpt_account_id.

Observed locally:

  • main Codex auth email: test_account1@gmail.com
  • added OAuth email: test_account2@gmail.com
  • both tokens report the same chatgpt_account_id
  • user ids / sub differ

This looks like chatgpt_account_id can identify the Team/workspace account, not the individual user. checkAccountIdCollision() currently treats a matching main chatgpt_account_id as a duplicate unconditionally.

I tested a local fix:

  • extract email from https://api.openai.com/profile.email
  • only treat the main Codex login as duplicate when both account id and email match, or when email is unavailable
  • keep the existing pool collision behavior scoped by plan bucket

Validation:

  • bun test tests/chatgpt-oauth.test.ts tests/codex-auth-collision.test.ts
  • bun run typecheck

If that approach sounds reasonable, I’m happy to open a small PR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions