Know where Codex runs and which account supplies access
Codex
This page covers tools outside your selection. You can still read it. Find matching guides
Distinguish the checkout, execution environment, hosting interface, and authentication method before relying on a result.
A Codex session has several identities: the interface hosting it, the place where commands run, the files it can access, and the account supplying access. Check them separately when a result appears in the wrong checkout or usage seems to belong to the wrong subscription.
Choose the workspace that fits the task
Codex's documented environments include Local, Worktree, and Cloud. Local works in the current project directory. Worktree keeps changes in a separate Git worktree on your computer. Cloud runs in a configured remote environment.
An IDE integration is a host for the session. The folder visible in its editor does not prove where every tool command runs. Have the agent identify its working directory and inspect its version-control state before a substantial change.
For a clean task record, collect:
Task: Correct retry delay
Execution: Local worktree
Working directory: The actual absolute path reported by the tool
Base revision: The commit inspected before editing
Checks: The commands available in this environment
Result: Diff and test output from this same worktree
A worktree separates edits. It does not by itself isolate credentials, network access, or executable repository code.
Check authentication without exposing credentials
OpenAI distinguishes ChatGPT sign-in for subscription access from API-key access billed by usage. Local Codex clients support these methods; Codex cloud requires ChatGPT sign-in.
Use the client's account or authentication status display. Record the method and relevant workspace, while keeping tokens and key values private. If an IDE offers several providers or account routes, inspect the active Codex configuration instead of inferring the answer from the IDE logo.
Do not ask the model to prove a charge from a transcript. A status record can establish the configured access method; account usage and billing records are the place to verify charges. Model availability and quotas can differ by account and surface.
Move work with its evidence
A cloud result needs the revision, diff, and checks from that environment. Before applying it locally, inspect the current base and resolve any differences. Do not copy a session identifier and assume another product can resume it.
For a pipeline, keep account configuration per adapter. A saved local login does not imply the same identity is available to a Linux CI runner. Use the programmatic guide for that transition.
What goes wrong
The editor shows one branch while the agent changed another worktree. A cloud environment lacks a required service. The user is signed into ChatGPT in a browser while a CLI invocation uses a separately configured API key. Tests pass in an environment with different dependencies.
Name each boundary in the task record. Fix the configuration that the actual command used rather than changing unrelated account settings.
How to check
Find the changed file at the reported path and confirm the diff's base revision. Read the check output from that same environment. Reproduce one relevant check locally when integrating a remote result.
Inspect the active authentication method without copying secrets into chat. If actual charges matter, compare the run's time and usage with the appropriate account records. State what could and could not be verified.
Sources
- OpenAI: Codex environments Tier 1 2026-09-08
- OpenAI: authentication Tier 1 2026-09-08
Something wrong with this page?
Say what you expected and what you got. That is usually the shortest route to a correction, and it goes on the public issue tracker so the fix is visible.