The codex cli giving: 401 unauthorized
Resolved 💬 100 comments Opened Feb 25, 2026 by isha-paliwal3 Closed Apr 17, 2026
💡 Likely answer: A maintainer (etraut-openai, contributor)
responded on this thread — see the highlighted reply below.
Getting:
unexpected status 401 Unauthorized: {"detail":"Unauthorized"},
stream disconnected before completion: error sending request for url (https://chatgpt.com/backend-api/codex/responses)
codex-cli 0.104.0
cf-ray: 9d365d4acc6514b5-SIN,
request id: 3c42618e-4712-4634-8959-f73fa73737ca
100 Comments
Where are you located? Are you accessing from a supported country?
I am accessing from India, it was working fine until yesterday, even now its logged in successfully but its unabble to get response from https://chatgpt.com/backend-api/codex/responses
it has happened to me earlier as well but somehow it worked on its own but the issue reappeared now
@etraut-openai I have chatgpt Plus subscription
Which model were you using?
gpt-5.2 medium
What platform is your computer?
Windows
Try logging out and logging back in to see if that resolves it.
If not, please repro the problem and then use the
/feedbackslash command to upload your logs and session details, then post the thread ID here so I can reference the uploaded details.@etraut-openai here is the thread ID 019c968f-a41c-7ef3-a193-c32530d246a2
I have exactly the same issue - my thread ID is 019c9740-2f19-7af0-993e-706e58f9d6b6
Based in the UK however
@isha-paliwal3, I'm looking at your logs, and it appears that you've configured Codex to use
https://ai-linton8487ai296041917917.openai.azure.com/openai/v1/responsesas the endpoint. Are you using an Azure-hosted model?@kj809, I'm seeing the same thing in your logs.
If you're using an Azure-hosted endpoint and you're seeing "401 Unauthroized" errors, you should contact the folks in Azure and work with them on a fix.
I have same issue.
request id: b6c97496-0371-4140-ba4a-43852c628904
Based in Perth, Australia
Was working fine two days ago.
OK, it works on my mbp, which has codex 5.3 available. However, on the machine that fails, I can only see 5.2 instead. Reinstalling extension makes no change.
@super148666, I wasn't able to look at your logs. If you used
/feedbackto upload, it apparently failed. Are you also using Azure-hosted models? If so, please report this issue to the Azure folks.I just uploaded the feedback. Thread ID: 019c9844-047b-7622-b1c0-56d9ffc81e67
Same problem here. Feedback send ID: 019c9901-1445-77b3-af5d-be8bdaa4c039
same. started yesterday. thread ID 019c98fe-953f-7162-a418-ddf21f19aa0e
same here. thread ID 019c9949-5f53-7323-a6e6-bf962f0ce993
Same here. thread ID 019c9966-f793-7052-a8a2-d8523c1dc89b . Tried logout and auth, no result
same here. based in US, Codex CLI on Mac. cf-ray: 9d408af82e53f52e-EWR,
request id: 96e14778-9648-4552-9f0b-b649c5f4ecd5 version 0.105.0
any update? same issue. Codex on windows, through VS code IDE. Plus account. request id: 3c796f49-1973-4642-96ff-3f3862d8f64d
same here id: 019c9bc2-85bc-7e91-a1dc-f8c5d055516f
same :(
request id: ed264702-e4ec-405c-aa30-f742c4960dd5
I had OPENAI_BASE_URL="https://api.openai.com/v1" set. Unset that makes it works again.
This does not fix my issue. Mine is already unset.
after restart machine, it works for about 10mins then this unauthorized issue came up again. This issue is persisted after many restart.
Thread id: 019c9ce0-2754-77d2-a73d-35320eb59d93
issue still exists for me. any update here please? not been able to use for 3 days now.
I can’t use it on my corporate PC. After a fresh restart it works for about 5 minutes, then stops. If I connect through a VPN, I get a 2–3 minute window where it works, and then it stops again. It was working perfectly three days ago and still works flawlessly on my private PC. I’m not sure if the issue is on my side, but it’s indicative that it only started appearing now, around the same time others began reporting it.
My issue is also corporate laptop. but I confirmed, thay are not blocking anything.
Same problem in this thread ID 019ca055-de23-7e60-bc66-df692350662b
no improvements. When a switch wifi/vpn, it works for a bit and then again the same issue. Can someone give any update here please?
i got the same issue
same issue thread id: 019cade7-991c-7c30-8eeb-ed7b1523c4b2
All users in our corporate environment are also getting this issue. UK Based. Running Codex via CLI and App on Macbook:
Still same issue with latest update in extension 0.4.79
Can anyone look into this? Apparently this is a common issue that prevents the use of codex completely.
yes, still same issue. It worked for a day then we are back with same problem again.
This issue has been open for a week and is currently completely unusable. At the moment, no action or assignee has been assigned, and there has been no update on progress.
Could someone from the maintainers please take a look and confirm whether this issue is being investigated? An update on the status or an estimated timeline for addressing it would be greatly appreciated.
So, no one is looking into this?
codex works with the API key. It just doesn't work via subscription.
I don't know what else we can provide here.
Same issue here. No help from OpenAI support portal. I am also noticing subscription fetch issues and problems loading normal ChatGPT chats as well as codex not working.
Codex App doesn't work. Codex Extension in VS Code, Codex WebApp also does not work. Intermitant issues with Chat GPT as well. I would think this is all related somehow but I am unable to determine where the breakpoint is...
Plus subscription. Worked fine before last week...
Logged out of all devices, uninstalled and reiunstalled extension/ app, no sign of any changes. contantly just "Reconnecting...1/5"
request id: b173a9ff-850c-4674-a0b0-56da382beb5c
Sorry, we haven't had time to root cause this issue yet. The Codex team has been chasing down other higher-priority issues. We've verified that the 401 error is not a widespread problem. It appears to be affecting just a handful of users. I realize that's little consolation if you're affected. We'll get to this. It's in our queue.
Here's something that could help us out. We'd like to get a few recent logs for the issue. Some of the earlier logs in this thread are pretty old at this point. If you're able to repro this 401 error, please use the
/feedbackslash command to upload your logs, and then post your thread ID here.@chrisslanphear, I see that posted a request id. Thanks for that info, but the full logs would be even more helpful.
@etraut-openai - see feedback 019cbfb9-8b53-7502-9987-1991e59c1aeb
@etraut-openai
NEW thread ID: 019cc0ab-04b5-7030-ac26-14de45232f23
Am I correct in assuming that everyone who is seeing this is on a Windows machine? If you are on a Mac or Linux system, let us know.
We're struggling to repro this, and we're not seeing evidence of this error in any of our backend logs. This error is likely coming from some other source.
Here's a theory. I wonder if this is caused by Windows Defender or some other anti-virus / anti-malware software or management (MDM) tools. If you're seeing this, do you have any AV software or enterprise management tools installed on your system — something that might be intercepting network calls?
Hi, in my case my laptop has Windows 11. And yes, I have a corporate laptop, with Cyberark and Crowdstrike installed.
hello, yes its SentinelOne maybe? Also to mention, it does work fine with API key.
thread ID 019cc285-c682-7ad3-8701-1eecd43eca23
No, we're on Macs... no changes in management software according to our IT
can you share the /feedback thread Id as well please? maybe it helps..
Yup - mine is a windows 11 corporate machine that has enterprise management tools. Based on my conversations with IT, there hasn't been any changes to these that could be impacting this. My support case to Open AI discusses these a bit.
<img width="792" height="121" alt="Image" src="https://github.com/user-attachments/assets/a12eddfc-1135-48e8-9673-1af1b129cb3a" />
Among the issues noted in this thread, I have also been experiencing the above in normal web Chat GPT and on Codex Web app. They apprear to potentially be related as they both started happening at the same time for me...
Anyone else getting this too?
@etraut-openai
I am using Mac with Windows defender. Your teory make sense for me. Maybe I can ask to open acces to some routes?
Today I have tried to disable Windows Defender and start a chat on codex. One chat has started running and still runs, but I have tried to create a new chat, and the new one doesn't run. Only one of 20 attemps works and still work...
<img width="236" height="414" alt="Image" src="https://github.com/user-attachments/assets/d8260e36-17de-43e0-9de4-5f581ef8a874" />
And now stoped working
<img width="1098" height="298" alt="Image" src="https://github.com/user-attachments/assets/a383afd3-930d-4ff2-8dda-6d3d07b2f16c" />
now it seems to work?
@yugaja - this is still not working for me
@etraut-openai - any updates that you can see? updated feedback id 019cd4c9-f625-7340-a676-6dc31ea85faa
For anyone having this issue, verify your ENV variables!
You might have set OPENAI_BASE_URL to wrong place which makes codex cli use incorrect baseurl. Remove env variable and try again
This issue has nothing to do with OPENAI_BASE_URL. Have to move to other platform since this is deal killer.
have the same issue here #
<img width="1107" height="944" alt="Image" src="https://github.com/user-attachments/assets/573b1c8f-d16d-4f02-a087-8072661e9931" />
Very strange behavior I noticed. I have two ISPs at home. With the first one, Codex works from my corporate PC; with the other one, it does not. At the same time, both ISPs work fine from my private PC. 🤦♂️
I have found a way to use Codex with the error.
It's a strange solution, but meanwhile we don't have solution I can use Codex.
Here's something to try: if you log out and log back in, does the problem go away?
No
I am losing my month free plus subscription trying to solve this error :(
@etraut-openai
Another feedback ID: 019cd9f4-0d75-7681-a7e1-c3302b6e1722
@etraut-openai
Another feedback ID: 019cdc29-2def-7e22-bf44-d39bfc61d66c
Codex was working perfectly until a few days ago. I have tried logging out / re-installing / re-authenticating multiple times.
hasn't worked for me for a long time now. I have never set env variables. I just just codex or opencode. Both not working. If I use my API key, it works.
I have had to switch to claude code now. I hope this gets resolved soon.
worked for me. thanks!
cf-ray: 9daa94119a96d1e1-ICN, request id: 21264631-e7de-4f32-b8d6-c38e327d8ed0
does not work me too.
I also have this issue. I ran this through ChatGPT (web interface) and shared my auth.json file with it, and this was ChatGPT's response:
response/
I do not think the main issue is:
Given this file, the most likely explanation is:
So this looks much more like a Codex ChatGPT-auth integration problem than a simple user-side login failure.
/response
It's baffling to me that this many people are having this issue and the only support we've gotten from OpenAI is, "Have you tried logging out and logging back in?" and "I think it's a problem with your network." Like, no. We didn't all randomly start having the same network problem two weeks ago.
@etraut-openai I'm paying for this service. I want to see some action from OpenAI. What is being done? Where are we at with finding a solution?
We've had capacity issues and outages that have affected many users over the past several days that have demanded the team's attention. This issue is in the queue for investigation, but we haven't had time to get to it yet.
So in summary:
had this issue, just cleared all my env vars that started with OPENAI, works now
I just faced the same issue while using it on my pi-coding-agent instance. It was working perfectly fine. A day before i added the nvidia-nim extension to add nvidia as a provider. It was working fine for a bit but after restarting, it just stopped working and kept throwing 401's. I removed the extension, restarted pi code and it's working now.
May try removing extensions and restarting. Helped in my case. Hopefully it helps others.
Same issue here.. Disconnecting and connecting the wifi works but you have to do it almost every 20 seconds. Is there an incoming fix for this?
I am not having any luck with disconnecting the wifi and trying. But also that is not a good solution for this as @jhonatansossa has mentioned I would need to do it once every 30 seconds or so. @etraut-openai any updates on this? I am still seeing the same errors I have been for the past 3 weeks.
Thanks for your patience on this issue. The Codex team has been busy over the past two weeks working on a few other high-priority issues. This one is now at the head of our priority queue.
Update: We've looked at our server-side telemetry and logs and have not been able to identify the root cause. We've added more extensive logging on the client side in this PR, and this logic will be included in the next release of the CLI. Once that's out (should be today), I'll ask a few of you who are experiencing this problem to send us
/feedback. That should give us the clues that we need to diagnose this problem.@etraut-openai - will this only impact CLI users? Or is there potential that this could impact those using the extension, web app, or desktop apps?
The other clients are built on the CLI, so once we find and fix the root cause, it should fix the problem everywhere.
As of today, it is still the same :(
thread id: 019cfad1-edd2-7380-8423-3a4bfcd6bdc2
feedback id
019cfd09-b076-7d71-b4b1-fc4dbf06ba0e
019c9508-f847-7c20-9a31-bc6df6f0a718
I dug through current
origin/mainplus the current issue thread, and this looks mixed rather than one single 401 bug.etraut-openaialready noted that some uploaded logs in this thread were pointed at Azure-hosted/openai/v1/responses, not the default ChatGPT backendorigin/mainstill routes an explicit built-in OpenAI provider override through ChatGPT auth too:config/mod.rsresolvesopenai_base_url/ deprecatedOPENAI_BASE_URL, passes that intobuilt_in_model_providers(...), andModelProviderInfo::to_api_provider(Some(AuthMode::Chatgpt))still honors an explicit providerbase_urlinstead of the defaulthttps://chatgpt.com/backend-api/codexOPENAI_BASE_URLare a real separate bucket, not just random anecdotesI put a tiny branch-backed proof test around the endpoint-selection part here:
ae856afCOPYFILE_DISABLE=1 cargo test -p codex-core model_provider_info -- --nocapture(passed locally)So the clearest next step for the thread is to keep the unresolved investigation focused on the default-backend subscription slice, not the
OPENAI_BASE_URL/ Azure slice.thread ID: 019d0113-e6e2-7a11-a08d-a12400002026
This is still an issue for me. Adding a refreshed thread id here since there has been an application update since I last attempted.
thread ID: 019d0608-64ac-75f1-9512-15e00a1f0144
Thanks for your patience, and thanks to everyone who has been submitting
/feedbackreports. Those reports are what let us trace these failures cleanly.We’re currently focusing on two core buckets from the
/feedbackuploads and request IDs we were able to trace. There are other less common failure modes in the thread too, but these are the two we can sort cleanly today.Bucket A: custom backend / provider configuration
These are not using the default Codex backend.
Examples, grouped by reporter:
isha-paliwal3:019c968f-a41c-7ef3-a193-c32530d246a2kj809:019c9740-2f19-7af0-993e-706e58f9d6b6annop-w:019c9949-5f53-7323-a6e6-bf962f0ce993toth3stars:019c9966-f793-7052-a8a2-d8523c1dc89bIf your thread ID is in Bucket A, the right things to check are:
OPENAI_*environment variablesBucket B: Sign in with ChatGPT, but the request reaches Codex backend with the client’s
Authorizationheader missingThese are reports where login appears to succeed, client telemetry says the client attached an
Authorizationheader, but the matching Codex request still reaches our backend without that header.Examples, grouped by reporter:
super148666:019c9844-047b-7622-b1c0-56d9ffc81e67,019c9ce0-2754-77d2-a73d-35320eb59d93tanushshukla:019c98fe-953f-7162-a418-ddf21f19aa0e,019d0113-e6e2-7a11-a08d-a12400002026jdivins:019ca055-de23-7e60-bc66-df692350662bferdinando-valsecchi-murgitroyd:019cade7-991c-7c30-8eeb-ed7b1523c4b2yugaja:019cfad1-edd2-7380-8423-3a4bfcd6bdc2chrisslanphear:019cfd09-b076-7d71-b4b1-fc4dbf06ba0essportal:019c9508-f847-7c20-9a31-bc6df6f0a718kj809:019d0608-64ac-75f1-9512-15e00a1f0144If your thread ID is in Bucket B, the most useful reply is:
/feedbackthread ID from the latest build if you have not posted one since updatingWe also have additional thread IDs posted in the issue that we have not yet bucketed publicly:
019c9901-1445-77b3-af5d-be8bdaa4c039019c9bc2-85bc-7e91-a1dc-f8c5d055516fPlease do not post
auth.json, tokens, or other credentials in this thread.Bucket B:
Also, like others, same account works on my personal laptop.
@ccy-oai
Bucket B
Both of my machines (one local and one virtual) behave similarly. Local exhibits behaviors regardless of network being used. Remote instance only uses the network my local machine is connected to but is ethernet and is only able to be accessed on company network. Behaviors still are the same across machines though.
API key mode works but I still run into the same reconnecting issue after a few minutes.
This does not do anything meaningful Like others have stated, I will reset wifi, restart machine, etc, and still run into issues. They might seem fixed momentarily and then fails again after a few minutes.
Will provide a fresh feedback thread ID likely next week.
Thanks for looking into this!
I have the same issue - when I try login to the CLI with OAuth I get 401. Thread ID: 019d1004-fa10-7663-af41-42d6c1384113 I also have the same issue trying to login to ChatGPT on Open Code
if it helps, we're working internally to see if this was the issue: https://community.cisco.com/t5/umbrella-discussions/chatgpt-codex-apps-on-mac-broken-after-tls-decryption-started/m-p/5372780
EDIT: I can confirm Cisco Umbrella was the issue for us
I can confirm it was Cisco Umbrella for us, too. It looks like Cisco is currently working with OpenAI on a resolution to this, but our IT team was able to add ChatGPT to the on-prem allow list which allows me to connect. Thanks for suggesting this, @ferdinando-valsecchi-murgitroyd .
UPDATE: API Key "works" in the fact that I do not get the 401 error. Instead I get a Quota Exceeded warning. This is different behavior than before. When I switched back to logging in with ChatGPT, it reverts back to the 401 error.
Thank you @ferdinando-valsecchi-murgitroyd and @ssportal for confirming the Cisco Umbrella case.
For folks in Bucket B, the leading hypothesis is that in at least some environments, something on the network between Codex and your machine is interfering with sign-in/auth. If you’re on a managed corporate network, it would be worth checking with your network admin whether Cisco Umbrella or a similar proxy/filtering system is handling ChatGPT traffic.
If your case is in Bucket A, please check for any
OPENAI_*environment variables or custom provider/base URL settings and unset them before retrying. Those cases are not using the default Codex setup, so they can fail for a different reason than the main Sign in with ChatGPT401issue.We do not think this explains all of Bucket B, so we’re still diagnosing the remaining cases.
@chrisslanphear when you hit the API-key
Quota Exceededpath again, please send a fresh/feedbackthread ID from that exact repro. That looks different from the Sign in with ChatGPT401, and I want to inspect those logs separately.Bucket B, and I have installed Firewall Cisco Umbrella.
So I am going to ask to IT team to unlock this.
@ssportal what action has your IT team done on the configuration?
Thank you.
EDIT AS OF 04022026 @ 2:59PM PST:
Feedback ID: 019d4f65-788c-7d10-aad3-cecf6d28a5b8 Stopped working again and provided the 401 error via vs code extension on windows. @etraut-openai @ccy-oai
As of 4/2/2026 - this issue seems to be resolved on my side. No changes were made on anything but it is working as expected once again.
Guessing the items mentioned earlier about cli updates have finally made their way through to the vs code extension.
@chrisslanphear, I checked your April 2 reports more closely.
Around
18:07 UTC, the same account/client setup was working from a135.x.x.xIP. Later, around21:56 UTC, the same setup was hitting repeated401s from a146.x.x.xIP, and those later requests reached our backend without your ChatGPT auth attached.So at this point I suspect the later network/IP more than the extension itself. If you can, please try the same machine on a different network and let us know what you see.
I have still the problem, can we have some kind of compensation, I have been working with codex enabling and disabling wifi since I discovered it and it's a really bad experience. @
During next week I hope I can check it with the IT team.
We have detrmined on our end that this is fully related to the Cisco Umbrella issue mentioned earlier in this thread. The specifics are as follows:
Reconnecting details
"unexpected status 302 Found: <html> <head><title>302 Moved Temporarily</title></head> <body> <center><h1>302 Moved Temporarily</h1></center> <hr><center>Umbrella Cloud Security Gateway</center> </body> </html>, url: wss://chatgpt.com/backend-api/codex/responses"
Then we get the 401 status.
"unexpected status 401 Unauthorized: We got your request, but your ChatGPT login did not make it to this service., url: https://chatgpt.com/backend-api/codex/responses, cf-ray: 9e8c1f990b76ad1b-EWR, request id: 9b12512f-1962-42e0-bf0a-db412429c230"
@ccy-oai - do you know if Open AI is working wiht Cisco on this at all?
See https://community.cisco.com/t5/umbrella-discussions/chatgpt-codex-apps-on-mac-broken-after-tls-decryption-started/m-p/5372780
@chrisslanphear Cisco is aware. Let me check what they have available for us on the 401 issue here.
@ccy-oai Any updates on this? Still getting the following
unexpected status 401 Unauthorized: We got your request, but your ChatGPT login did not make it to this service., url: https://chatgpt.com/backend-api/codex/responses, cf-ray: 9e839c890c11a0fb-EWR, request id: 694f535d-2e5a-4bd9-8158-375f66789b65
@chrisslanphear Cisco is aware of the issue, but I did not get a response with any specific Cisco-side guidance or public help page to point Codex users to.
That leaves us to this guidance for anyone hitting this specific server error:
> We got your request, but your ChatGPT login did not make it to this service.
That means the request reached OpenAI, but the expected ChatGPT auth did not arrive with it. In the cases we’ve investigated, for this issue, that points to something on the user’s network path, such as Cisco Umbrella / Secure Access / TLS inspection / proxy policy, interfering with Codex traffic.
I'm closing the issue with recommendation: take the error text and URL to your network admins. They should review the network security / proxy / TLS inspection configuration for ChatGPT and Codex traffic, and escalate to Cisco Support if needed. If I do get public guidance from Cisco I will append it here.
Please I would like some detailed information about what url port or network information to send to my it team, can you help me on that?
@jdivins Yes! @ccy-oai it would be helpful if you could provide specifics on what IT teams need to adjust to get this working because I have not received anything useful elsewhere (openAI or Cisco).
@jdivins @chrisslanphear
Think of it this way:
OpenAI server <- Internet <- [security/proxy system run by your network admin, possibly Cisco Umbrella] <- your computerThis is standard HTTPS over port
443to:https://chatgpt.com/backend-api/codex/responseshttps://chatgpt.com/backend-api/codex/modelsWhat appears to be happening in affected cases is that the system in the middle is intercepting or forwarding the HTTPS request, without letting the ChatGPT
Authorizationheader reach OpenAI intact.So the ask for IT is:
AuthorizationheaderThis confirms what I am seeing.
Codex CLI cannot connect to
chatgpt.com/backend-api/...endpoints when running behind Cisco Umbrella and every API call fails with401 Unauthorized:The logs also show:
... since Umbrella intercepts requests to
chatgpt.comand returns a 302 redirect through its inspection gateway:The issue is specific to ChatGPT auth mode.
api.openai.comis not inspected by Umbrella on the same network.Crucially,
chatgpt.comis _inspected_, but _allowed_.chatgpt.comworks normally in a browser on the same network / machine.Browsers handle this transparently (follow redirect, accept cookie, get proxied through). The Codex binary does not, resulting in the 302/401 errors above. I understand "talk to IT" is the most straightforward solution but I hope there is also a more scalable one which would allow Codex to behave like the browser client.
Workarounds tried:
chatgpt.com.Some standard info: