Codex requires verification of an inaccessible legacy phone number and provides no phone number replacement or recovery path
What issue are you seeing?
Problem Description
I can successfully sign in to my OpenAI account using Google OAuth and access ChatGPT without any issues.
My account is already authenticated through Google and protected by MFA. I can use ChatGPT normally, which demonstrates that I have valid access to the account.
However, when attempting to use Codex on macOS, the application requires verification of a phone number that was associated with my account years ago. That phone number is no longer under my control.
The system provides no practical way to update, replace, or recover from an obsolete phone number, even though I have already proven ownership of the account through stronger authentication mechanisms.
This creates a situation where:
- Google OAuth authentication succeeds.
- MFA authentication succeeds.
- Existing account access is available.
- Trusted device authentication succeeds.
- ChatGPT access works normally.
Yet access to Codex is completely blocked because of an outdated phone number.
Why this is problematic
Phone numbers are not permanent identifiers.
Users may:
- Change carriers.
- Move to another country.
- Lose access to old numbers.
- Have used temporary numbers years ago.
- Have numbers that were recycled by mobile providers.
If a historical phone number becomes a mandatory requirement for accessing a product, there should also be a secure recovery or replacement process.
At the moment, the old phone number effectively becomes the ultimate gatekeeper of the account despite the existence of stronger authentication methods.
Suggested Improvement
Provide a recovery path that allows users who have already proven account ownership through Google OAuth, MFA, trusted devices, or existing authenticated sessions to update an obsolete phone number after appropriate security checks.
Without such a mechanism, users can become permanently locked out of Codex despite maintaining full control of their OpenAI account.
What steps can reproduce the bug?
- Sign in to an OpenAI account using Google OAuth.
- Successfully access ChatGPT and use normal ChatGPT features.
- Launch the Codex macOS application.
- Complete local biometric authentication (Touch ID).
- Codex redirects to phone verification.
- The verification page requires a phone number that was associated with the account years ago.
- The user no longer has access to that phone number.
- No option is provided to replace the phone number or recover access through existing account authentication.
- Access to Codex is blocked.
Expected Behavior:
Users who can already prove ownership of the account through Google OAuth, MFA, trusted devices, and active authenticated sessions should have a secure method to replace an obsolete phone number.
Actual Behavior:
Codex requires verification of an inaccessible legacy phone number and provides no replacement or recovery mechanism, resulting in permanent loss of access to the product.
What is the expected behavior?
Users who have already proven ownership of their OpenAI account through Google OAuth, MFA, trusted devices, and active authenticated sessions should be provided with a secure recovery path to update or replace an obsolete phone number.
Access to Codex should not be permanently blocked solely because a historical phone number is no longer accessible.
At a minimum, users should have one of the following options:
- Replace the old phone number after additional security verification.
- Use existing MFA methods to recover access.
- Use an authenticated OpenAI session to confirm ownership.
- Contact support through a documented recovery process.
The current behavior leaves legitimate account owners with no practical recovery path.
Additional information
Additional context:
- I can successfully sign in to my OpenAI account using Google OAuth.
- I can access and use ChatGPT normally.
- My account is protected by MFA.
- The issue only occurs when attempting to access Codex.
- Codex requests verification of a phone number that was associated with the account years ago.
- That phone number is no longer under my control.
- There is no visible option to replace the phone number.
- The verification screen offers SMS and WhatsApp delivery only.
- As a result, I am permanently blocked from accessing Codex despite maintaining full control of my OpenAI account.
Screenshot attached.
70 Comments
Potential duplicates detected. Please review them and close your issue if it is a duplicate.
Powered by Codex Action
same problems,Is there an official handling this matter
It's hard to understand the phone number verification but the settings don't allow you to change the phone number? if at some point I can no longer use that number, I can no longer use the Codex? Lost your account?
same problem. I am a paid user. But now I can not log in to my codex thanks to the phone varification to a legacy phone number.
+1, exact same situation.
--device-auth) redirects to phone verification for a number I no longer controlThe core problem is exactly as described in this issue: Codex requires verification of an inaccessible legacy phone number and provides no replacement or recovery path, even though the account is fully authenticated through other methods.
Same problem. I am a paid user and I can not use my codex, how to compensate?
The same issue! Paid for codex now can't get access to it.
it allows but it still asks code from an old number! Very strange!
Same Problem here!
I am experiencing the same issue with Codex on macOS.
I can successfully sign in to ChatGPT through Google OAuth, complete authentication with my authenticator app, and access Codex Cloud in the browser under my Plus account.
However, Codex for macOS then requires an additional WhatsApp verification code sent to an old inaccessible phone number. In my ChatGPT Security settings, Authenticator app is enabled and Text message / SMS / WhatsApp is disabled.
I also reproduced the same problem through Codex CLI using
codex login --device-auth: after successful authenticator verification, it still redirects me to WhatsApp verification on the old inaccessible number.This blocks access to my existing local Codex projects and threads in the desktop app. Please investigate.
Additional detail: the issue started immediately after I updated the Codex macOS app today.
Codex macOS app version:
26.527.60818 (3437).Before this update, I had been using the same ChatGPT Plus account in Codex on this Mac for about a month without any WhatsApp phone verification prompt, including after signing out and signing back in several times.
After updating the app, Codex began requiring verification through an inaccessible legacy WhatsApp number. I then installed Codex CLI v0.136.0 and reproduced the same issue with
codex login --device-auth: authenticator verification succeeds, but the authentication flow still redirects to WhatsApp verification on the inaccessible legacy number.ChatGPT and Codex Cloud in the browser remain accessible under the same account.
I second that—I’ve tried various methods. I wrote to support. Plus account
Same problem happens
same problem.
Same problem, support told me (real person, not ai) that they are very sorry but they don't have a solution. But, and I quote "Our team is actively reviewing the behavior and working to better understand the impact."
And "We understand how frustrating this is, especially when it prevents access to Codex functionality. While we do not have a timeline to share for a resolution, please be assured that the issue is being investigated."
So I guess we can only wait
I have Pro subscription. And BTW codex cloud works.
Same here. PRO subscriber. Just got forced to log in again after the Codex update, and all of a sudden it asks to verify a phone number that has been dead for years. Can log into the web version, ChatGPT, everything but Codex. Have MFA set up, passkey set up... And they don't even give any other option to verify / authenticate my identity and other than my old dead SIM card.
Crazy stupid!
same issue, cannot send verification code using PLUS account
same issue, after MFA it asking to send a code to phone number that is old and I can't change it phone number to send to the right phone (with no alternative to different login auth) for codex
in the same boat
Same situation here — adding a Windows + Codex CLI data point, since the existing reports are macOS. This is cross-platform.
Setup
Problem
When Codex needs to (re)authenticate, it redirects to the phone-OTP step-up (
phone-otp/select-channel) and demands an SMS/WhatsApp code to an old phone number I no longer have access to. That line is dead — no code can ever arrive. Despite having proven ownership of the account (active ChatGPT session, authenticator app, two security keys), none of those factors are accepted for this step. It insists on SMS to a number I cannot reach.The only number-removal path OpenAI documents is deleting the entire account and waiting 30 days before the number is released. For a paying customer who can already authenticate by stronger means, that is not an acceptable recovery path.
This is the same core defect as #25737 (the CLI forces an SMS step-up even on a security-key-only Advanced Account Security account, while browser sign-in honors the policy). The pattern is identical: a dead legacy phone number becomes an absolute gatekeeper that overrides every stronger factor already on the account, with no self-serve recovery.
Ask (echoing the OP): for accounts that can prove ownership via OAuth / active session / authenticator / passkeys / trusted device, provide a secure way to replace or clear an obsolete phone number — or accept an enrolled factor for the Codex step-up — without requiring account deletion. As it stands, paying users are locked out of a product they pay for by a phone number that no longer exists.
wtf is this? pro sub. i was logged out from my account and now can enter it coz of idiotic phone number verification. mfa for account is configured, phone sms not configured.
This just happened to me. And I'm unable to change it. Simply insane...
I tried asking their email but they didn't provide a solution, even though I don't use a VPN or only use a cellular phone
!image
I have exactly the same issue. just wrote to the support center. This is so annoying.
I also encountered the same problem. Now I can only use the chatgpt on the web version.
It works! I logged into my Codex 10 minutes ago. It didn't require phone verification.
Tibo help
họ đã làm gì đâu mà thành công bro, tài khoản của tôi gửi mã otp đến số điện thoại không còn sử dụng giờ không biết làm cách nào
What did they do to succeed bro, my account sent an OTP code to a phone number that is no longer in use now I don't know how to do it
It has been restored now. I just tried to log in again. I didn't perform any actions. I logged in on the "codex desktop". Now, there is no need for any verification anymore.
same to me
yep. works for me too.
works
🎉 it works!
________________________________
From: Alexey Kuznetsov @.*>
Sent: Wednesday, June 3, 2026 6:11:22 PM
To: openai/codex @.*>
Cc: ClarifiedfishLee @.>; Comment @.>
Subject: Re: [openai/codex] Codex requires verification of an inaccessible legacy phone number and provides no phone number replacement or recovery path (Issue #25749)
[https://avatars.githubusercontent.com/u/10403392?s=20&v=4]legtar left a comment (openai/codex#25749)<https://github.com/openai/codex/issues/25749#issuecomment-4611242547>
works
—
Reply to this email directly, view it on GitHub<https://github.com/openai/codex/issues/25749?email_source=notifications&email_token=ASSFDJEWC6JXQ2RZ7JTR5BD4572UVA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTINRRGEZDIMRVGQ32M4TFMFZW63VHMNXW23LFNZ2KKZLWMVXHJLDGN5XXIZLSL5RWY2LDNM#issuecomment-4611242547>, or unsubscribe<https://github.com/notifications/unsubscribe-auth/ASSFDJDK7W3ANZWUJ3JGVFT4572UVAVCNFSM6AAAAACZWNKNAOVHI2DSMVQWIX3LMV43OSLTON2WKQ3PNVWWK3TUHM2DMMJRGI2DENJUG4>.
Triage notifications, keep track of coding agent tasks and review pull requests on the go with GitHub Mobile for iOS<https://github.com/notifications/mobile/ios/ASSFDJFGPKZLGAPMGTX2ML34572UVA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTINRRGEZDIMRVGQ32M4TFMFZW63VHMNXW23LFNZ2KKZLWMVXHJKTGN5XXIZLSL5UW64Y> and Android<https://github.com/notifications/mobile/android/ASSFDJARRNP7NAG6VFCDZXT4572UVA5CNFSNUABFM5UWIORPF5TWS5BNNB2WEL2JONZXKZKDN5WW2ZLOOQXTINRRGEZDIMRVGQ32M4TFMFZW63VHMNXW23LFNZ2KKZLWMVXHJLTGN5XXIZLSL5QW4ZDSN5UWI>. Download it today!
You are receiving this because you commented.Message ID: @.***>
same issue to me, and it works!
same here
same issue, cannot send verification code using PLUS account
do NOT work for me
im still stuck on this issue
tôi mới đăng ký tài khoản mới từ khi họ bắt nhận mã từ tài khoản cũ, giờ lại tiếp tục bắt gửi mã nhưng họ chỉ spam thông báo "Chúng tôi sẽ gửi mã dùng một lần đến * qua WhatsApp."
I just signed up for a new account since they started receiving codes from my old account, and now they keep sending codes but they just spam the message 'We'll send a one-time code to * via WhatsApp.'
Chúng tôi không thể gửi tin nhắn SMS đến số điện thoại này nên đã chuyển sang WhatsApp. Tiếp tục để gửi mã xác minh qua WhatsApp.
Không thể gửi mã xác minh đến số điện thoại này. Vui lòng thử lại sau, dùng số khác hoặc thử một kênh khác.
Bạn đã yêu cầu xác minh số điện thoại quá nhiều lần. Vui lòng thử lại sau.
We couldn't send SMS messages to this phone number, so we switched to WhatsApp. Proceed to send the verification code via WhatsApp.
Verification codes can't be sent to this phone number. Please try again later, use a different number, or try a different channel.
You've asked for phone number verification too many times. Please try again later.
It worked one week and now it doesn't work again!!!
I have exactly the same issue.
Additional findings:
The problem only occurs when using the standard OpenAI account login flow in Codex Desktop.
Instead of asking me to verify my own number, Codex requests verification of an unknown Romanian phone number (+40...).
This appears to be specific to the Codex Desktop authentication flow rather than account access itself.
fix it
Updated the app. Can't login because of wrong phone number. It happened after updating to version 26.609.71450.
This problem has appeared again, it requires confirmation on a phone that is no longer available
I got AI responses from support@openai.com that ended with them just repeatedly sending me the same message telling me that phone numbers cannot be changed.
The support article is titled "How to change the phone number associated with your account".
But the article just tells you that they can't, in fact, be changed.
After two days I requested deletion of my ChatGPT account and then created a new one. A pain, but it was going nowhere. I did receive a pro-rata refund of my monthly fee, which I suppose is a small consolation.
This is the email they kept sending me:
Hello,
Thank you for contacting OpenAI Support.
I understand your concern about being unable to access Codex because the verification process is requesting a phone number that you no longer have access to.
For more information, please review the following Help Center articles:
How to change the phone number associated with your account
Can I phone verify over email/call instead of SMS?
These articles provide additional information regarding phone verification and account phone number management that may help answer your questions.
We hope this information helps. Please let us know if you have any additional questions.
Best
Marvic
OpenAI Support
Same problem, exact same scenario: my account is from 2023, tied to a number in another country that I cancelled after relocating, and now I'm locked out by it.
What stings is that support confirmed this was a bug and fixed it last week, and now it's regressed, with no alternative offered this time. After 35 emails, support says nothing can be done. +1 on the recovery path, this is hitting exactly the long-term paying users the verification is meant to protect.
Did anyone else change any account settings that might have triggered this? For me, I changed my payment details and then immediately started getting the error. (I had two billing cards listed and I switched from one to the other). Payment was imminent so could be the payment change OR the end of one billing period OR a combination.
Just wondering if there is a pattern to this madness.
I had to create a new account ... I did not enter my phone number!!!
Well, I thought it was fixed, but this issue is back now for me. Subscribing to this thread again.
The same problem occurred again a few days ago.
Same exact issue. This is also, as far as I can tell, unlawful under Art. 16 GDPR in the EU, as right to rectification of inaccurate personal data is enshrined in law.
Support agents stonewall at every turn when this is brought up, so I've submitted a complaint to my national data authority and OpenAI's data authority in Ireland.
Issue still persist
same to me, isssue happened again after codex update today, please help solve this bug in highest priority.
I am a codex paid user now failed to use codex, how to compensate this...?
Please fix the issue
Same issue here
Any info?
Same issue here. I regularly use Codex, and I have now been locked out for approximately 5–6 days.
At first, I did not think it was a major issue, but after researching possible solutions and trying several reasonable troubleshooting steps, the problem still has not been resolved.
So far, I have tried:
This has become increasingly frustrating because I rely on Codex regularly, and I have been unable to access my account for nearly a week despite having other valid verification methods available.
I also have this problem. I have been unable to use codex for almost 2 weeks, and I am also a plus subscriber. The customer service asked me for some screenshots and after recording the screen, they did not give me any solution or compensation plan.
I would think they probably updated it intentionally, but the re-enabled SMS verification is blocking legacy phone-number users from logging into Codex. I just hope this can be resolved soon without hurting the UX, since the account is actively subscribed to Pro and the usage window is being wasted while access is blocked.
Same issue, Codex desktop. Flow: "Sign in with ChatGPT" → OAuth succeeds → passkey / Google Authenticator succeeds → then forced into a phone OTP against a number I haven't controlled in years, with only SMS/WhatsApp offered and no field to enter a different number. ChatGPT web and platform login work normally on the same account; the block is Codex-specific.
Account is several years old and paid, with a current phone number, an authenticator app, and a passkey all configured — none accepted past the OAuth step. Email support is looping canned "can't change phone numbers / create a new account" replies with no route to a human.
Support Case: 10338341. Happy to share account email, timestamps, and screenshots privately with anyone on the Codex/auth team.
I am experiencing the exact same issue.
I can log in to ChatGPT Web without any problems. Codex Cloud works normally. The problem only affects Codex CLI and Codex App.
After successfully completing the OpenAI login flow, I am redirected to a "Confirm phone number" page that requires verification of an old phone number that I no longer have access to. No alternative verification method is offered.
Support initially suggested creating a new account and then just started to ignore me.
Could someone from OpenAI confirm whether this issue is being actively investigated and whether there is any recovery path available for affected paid users?
Support case: 10080635
It's useless. I communicated with them for almost 2 weeks. During these 2 weeks, I couldn't use codex. They still asked me to register new users. I'm not going to continue the communication, it will just be a waste of my time. I'm going to apply for a refund
same problem. it requires phone verification from platform.openai.com portal, even though I have another phone linked on chatgpt with 2fa and so on
from openai support:
im locked out too. Oh well, claude desktop app is great too!
im locked out too. Oh well, claude desktop app is great too!
@tibo-openai GDPR? This is not only a serious UX problem but literally illegal. 20x user here. Can ya'll pls fix this? privacy@openai.com and dsar@openai.com are unwilling to change it either, they just told me to f off.
Please be kind and address this. My wife can't use the Codex app because of this issue, and she really wants to upgrade to 20x.
unsubscribed
Hi. I have been a devoted OpenAI user since the GPT-3 era, and I am also an especially devoted, long-time fan of both @tibo-openai and @etraut-openai . I am very sorry to tag you directly, but this issue is extremely important to me and is currently blocking my work.
I am experiencing the same Codex desktop sign-in issue on macOS.
Support Case: 11465182
Previous Case: 10227974
My password verification succeeds, followed by successful device-bound passkey verification using the passkey registered on my computer. Codex then requires a separate SMS or WhatsApp verification code sent to my permanently deactivated Japanese +81 number ending in 5682.
My current U.S. +1 number ending in 9744 is active in my ChatGPT MFA settings, and my main ChatGPT account remains fully accessible.
I am not requesting a general account phone-number change. I only need Codex to stop depending on the inaccessible legacy +81 number so I can continue using this long-standing account.
I would be deeply grateful if someone could help route this case to the appropriate Codex authentication or account-security team. Thank you very much for your time and consideration.
@tibo-openai @etraut-openai @bolinfest
I am experiencing the same issue.
I am a paid ChatGPT Pro/Codex user, but I am completely blocked from using Codex because it requires verification of an old phone number that I no longer have access to.
My situation:
Codex redirects me to verify this phone number:
+40 xxx xxx 430
I do not have access to this number anymore. In fact, calling this number returns that the number does not exist.
The biggest issue is that there is no recovery path:
A phone number should not become a permanent lock preventing a legitimate account owner from accessing a paid product.
Please consider adding an account recovery flow that allows verified users to replace inaccessible legacy phone numbers after additional security checks.
This issue is especially serious for paid users because we can lose access to a product we already subscribed to.
Thank you.