401 Unauthorized Missing scopes: api.responses.write(Codex App and Codex CLI fail after signing in with ChatGPT)

Open 💬 0 comments Opened Jun 27, 2026 by chenlonggit333

What version of Codex CLI is running?

codex-cli 0.142.3

What subscription do you have?

ChatGPT Plus

Which model were you using?

gpt-5.5

What platform is your computer?

Darwin 25.5.0 arm64 arm

What terminal emulator and version are you using (if applicable)?

iTerm2

Codex doctor report

cliff@cliffdeMacBook-Pro ~ % codex doctor --json
{
  "schemaVersion": 1,
  "generatedAt": "1782552762s since unix epoch",
  "overallStatus": "ok",
  "codexVersion": "0.142.3",
  "checks": {
    "app_server.status": {
      "id": "app_server.status",
      "category": "app-server",
      "status": "ok",
      "summary": "background server is not running",
      "details": {
        "control socket": "/Users/cliff/.codex/app-server-control/app-server-control.sock",
        "daemon state dir": "/Users/cliff/.codex/app-server-daemon",
        "mode": "ephemeral",
        "pid file": "/Users/cliff/.codex/app-server-daemon/app-server.pid (missing)",
        "settings": "/Users/cliff/.codex/app-server-daemon/settings.json (missing)",
        "status": "not running",
        "update-loop pid file": "/Users/cliff/.codex/app-server-daemon/app-server-updater.pid (missing)"
      },
      "remediation": null,
      "durationMs": 0
    },
    "auth.credentials": {
      "id": "auth.credentials",
      "category": "auth",
      "status": "ok",
      "summary": "auth is configured",
      "details": {
        "auth file": "/Users/cliff/.codex/auth.json",
        "auth storage mode": "File",
        "stored API key": "false",
        "stored ChatGPT tokens": "true",
        "stored agent identity": "false",
        "stored auth mode": "chatgpt"
      },
      "remediation": null,
      "durationMs": 0
    },
    "config.load": {
      "id": "config.load",
      "category": "config",
      "status": "ok",
      "summary": "config loaded",
      "details": {
        "CODEX_HOME": "/Users/cliff/.codex",
        "config.toml": "/Users/cliff/.codex/config.toml",
        "config.toml parse": "ok",
        "cwd": "/Users/cliff",
        "enabled feature flags": "shell_tool, unified_exec, shell_snapshot, terminal_resize_reflow, sqlite, hooks, enable_request_compression, multi_agent, apps, tool_search_always_defer_mcp_tools, tool_suggest, plugins, in_app_browser, browser_use, browser_use_full_cdp_access, browser_use_external, computer_use, plugin_sharing, image_generation, resize_all_images, skill_mcp_dependency_install, mentions_v2, steer, guardian_approval, goals, collaboration_modes, tool_call_mcp_elicitation, personality, fast_mode, tui_app_server, auto_compaction, remote_compaction_v2, workspace_dependencies",
        "feature flag overrides": "none",
        "feature flags enabled": "33",
        "log dir": "/Users/cliff/.codex/log",
        "mcp servers": "1",
        "model": "<default>",
        "model provider": "ccswitch",
        "sqlite home": "/Users/cliff/.codex"
      },
      "remediation": null,
      "durationMs": 0
    },
    "git.environment": {
      "id": "git.environment",
      "category": "git",
      "status": "ok",
      "summary": "git version 2.50.1 (Apple Git-155)",
      "details": {
        "PATH git #1": "/usr/bin/git",
        "PATH git entries": "1",
        "git build options": "git version 2.50.1 (Apple Git-155); cpu: arm64; no commit associated with this build; sizeof-long: 8; sizeof-size_t: 8; shell-path: /bin/sh; feature: fsmonitor--daemon; libcurl: 8.7.1; zlib: 1.2.12; SHA-1: SHA1_DC; SHA-256: SHA256_BLK",
        "git exec path": "/Library/Developer/CommandLineTools/usr/libexec/git-core",
        "git version": "git version 2.50.1 (Apple Git-155)",
        "repo detected": "false",
        "selected git": "/usr/bin/git"
      },
      "remediation": null,
      "durationMs": 20
    },
    "installation": {
      "id": "installation",
      "category": "install",
      "status": "ok",
      "summary": "installation looks consistent",
      "details": {
        "PATH codex #1": "/opt/homebrew/bin/codex",
        "current executable": "/opt/homebrew/bin/codex",
        "install context": "brew",
        "managed by bun": "false",
        "managed by npm": "false",
        "managed package root": "not set"
      },
      "remediation": null,
      "durationMs": 5
    },
    "mcp.config": {
      "id": "mcp.config",
      "category": "mcp",
      "status": "ok",
      "summary": "MCP configuration is locally consistent",
      "details": {
        "configured servers": "1",
        "disabled servers": "0",
        "stdio servers": "1"
      },
      "remediation": null,
      "durationMs": 0
    },
    "network.env": {
      "id": "network.env",
      "category": "network",
      "status": "ok",
      "summary": "network-related environment looks readable",
      "details": {
        "proxy env vars": "none"
      },
      "remediation": null,
      "durationMs": 0
    },
    "network.provider_reachability": {
      "id": "network.provider_reachability",
      "category": "reachability",
      "status": "ok",
      "summary": "active provider endpoints are reachable over HTTP",
      "details": {
        "ChatGPT base URL": "https://chatgpt.com/backend-api/ reachable (HTTP 404)",
        "reachability mode": "ChatGPT auth"
      },
      "remediation": null,
      "durationMs": 660
    },
    "network.websocket_reachability": {
      "id": "network.websocket_reachability",
      "category": "websocket",
      "status": "ok",
      "summary": "Responses WebSocket is not enabled for the active provider",
      "details": {
        "model provider": "ccswitch",
        "provider name": "ccswitch",
        "proxy env vars": "none",
        "supports websockets": "false",
        "wire API": "responses"
      },
      "remediation": null,
      "durationMs": 0
    },
    "runtime.provenance": {
      "id": "runtime.provenance",
      "category": "runtime",
      "status": "ok",
      "summary": "running brew on macos-aarch64",
      "details": {
        "commit": "unknown",
        "current executable": "/opt/homebrew/bin/codex",
        "install method": "brew",
        "platform": "macos-aarch64",
        "version": "0.142.3"
      },
      "remediation": null,
      "durationMs": 0
    },
    "runtime.search": {
      "id": "runtime.search",
      "category": "search",
      "status": "ok",
      "summary": "search is OK (system)",
      "details": {
        "search command": "rg",
        "search command readiness": "ripgrep 15.1.0",
        "search provider": "system"
      },
      "remediation": null,
      "durationMs": 2
    },
    "sandbox.helpers": {
      "id": "sandbox.helpers",
      "category": "sandbox",
      "status": "ok",
      "summary": "sandbox configuration is readable",
      "details": {
        "approval policy": "OnRequest",
        "codex-linux-sandbox helper": "none",
        "execve wrapper helper": "/Users/cliff/.codex/tmp/arg0/codex-arg07uSDG8/codex-execve-wrapper",
        "filesystem sandbox": "restricted",
        "network sandbox": "restricted"
      },
      "remediation": null,
      "durationMs": 0
    },
    "state.paths": {
      "id": "state.paths",
      "category": "state",
      "status": "ok",
      "summary": "state paths and databases are inspectable",
      "details": {
        "CODEX_HOME": "/Users/cliff/.codex (dir)",
        "active rollout files": "36 files, 111893928 total bytes, 3108164 average bytes",
        "archived rollout files": "14 files, 29177295 total bytes, 2084092 average bytes",
        "goals DB": "/Users/cliff/.codex/goals_1.sqlite (file)",
        "goals DB integrity": "ok",
        "log DB": "/Users/cliff/.codex/logs_2.sqlite (file)",
        "log DB integrity": "ok",
        "log dir": "/Users/cliff/.codex/log (dir)",
        "memories DB": "/Users/cliff/.codex/memories_1.sqlite (file)",
        "memories DB integrity": "ok",
        "sqlite home": "/Users/cliff/.codex (dir)",
        "state DB": "/Users/cliff/.codex/state_5.sqlite (file)",
        "state DB integrity": "ok"
      },
      "remediation": null,
      "durationMs": 175
    },
    "state.rollout_db_parity": {
      "id": "state.rollout_db_parity",
      "category": "threads",
      "status": "ok",
      "summary": "rollout files and state DB thread inventory agree",
      "details": {
        "default model provider": "ccswitch",
        "rollout DB active files": "36",
        "rollout DB active rows": "36",
        "rollout DB archive mismatches": "0",
        "rollout DB archived files": "14",
        "rollout DB archived rows": "14",
        "rollout DB duplicate DB paths": "0",
        "rollout DB duplicate rollout thread ids": "0",
        "rollout DB malformed file names": "0",
        "rollout DB missing active rows": "0",
        "rollout DB missing archived rows": "0",
        "rollout DB model providers": "ccswitch=50",
        "rollout DB rows": "50",
        "rollout DB scan cap reached": "false",
        "rollout DB scan errors": "0",
        "rollout DB sources": "vscode=47, cli=2, exec=1",
        "rollout DB stale rows": "0"
      },
      "remediation": null,
      "durationMs": 314
    },
    "system.environment": {
      "id": "system.environment",
      "category": "system",
      "status": "ok",
      "summary": "OS language zh-Hans-CN",
      "details": {
        "EDITOR": "not set",
        "LANG": "zh_CN.UTF-8",
        "VISUAL": "not set",
        "os": "Mac OS 26.5.1 [64-bit]",
        "os language": "zh-Hans-CN",
        "os type": "Mac OS",
        "os version": "26.5.1"
      },
      "remediation": null,
      "durationMs": 2
    },
    "terminal.env": {
      "id": "terminal.env",
      "category": "terminal",
      "status": "ok",
      "summary": "terminal metadata was detected",
      "details": {
        "COLORFGBG": "0;15",
        "COLORTERM": "truecolor",
        "TERMINFO_DIRS entry": [
          "/Applications/iTerm.app/Contents/Resources/terminfo (dir)",
          "/usr/share/terminfo (dir)"
        ],
        "TERM_PROGRAM": "iTerm.app",
        "color output": "enabled",
        "effective locale": "zh_CN.UTF-8",
        "stderr is terminal": "true",
        "stdin is terminal": "true",
        "stdout is terminal": "true",
        "terminal": "iTerm2",
        "terminal size": "80x25",
        "terminal version": "3.6.11"
      },
      "remediation": null,
      "durationMs": 0
    },
    "terminal.title": {
      "id": "terminal.title",
      "category": "title",
      "status": "ok",
      "summary": "terminal title default",
      "details": {
        "terminal title activity": "true",
        "terminal title items": "activity, project-name",
        "terminal title project source": "cwd",
        "terminal title project value": "cliff",
        "terminal title source": "default"
      },
      "remediation": null,
      "durationMs": 0
    },
    "updates.status": {
      "id": "updates.status",
      "category": "updates",
      "status": "ok",
      "summary": "update configuration is locally consistent",
      "details": {
        "cached latest version": "0.142.3",
        "check for update on startup": "true",
        "last checked at": "2026-06-27T09:23:45.922809Z",
        "latest version": "0.142.3",
        "latest version status": "current version is not older",
        "update action": "brew upgrade --cask codex",
        "version cache": "/Users/cliff/.codex/version.json"
      },
      "remediation": null,
      "durationMs": 708
    }
  }
}

What issue are you seeing?

I can use Codex Web successfully at https://chatgpt.com/codex with the same ChatGPT Plus account.

However, both Codex App and Codex CLI fail after signing in with ChatGPT.

Error:
401 Unauthorized
Missing scopes: api.responses.write

Endpoint:
https://api.openai.com/v1/responses

Auth mode:
ChatGPT sign-in, not API key

What works:

  • Codex Web works on the same account

What fails:

  • Codex App fails with 401 Missing scopes: api.responses.write
  • Codex CLI also fails after codex logout / codex login with ChatGPT sign-in

What I already tried:

  • Reinstalled Codex App
  • Removed ~/.codex/auth.json and signed in again
  • Cleared OPENAI_API_KEY / OPENAI_ORG_ID / OPENAI_PROJECT_ID environment variables
  • Confirmed env | grep -i OPENAI returns empty
  • Used Codex CLI login with ChatGPT
  • Same error still occurs

Please check whether the ChatGPT OAuth token issued to Codex App/CLI for my account or workspace is missing the api.responses.write scope, even though Codex Web works.

What steps can reproduce the bug?

Uploaded thread: 019f0865-d28d-7d72-b612-ae68e60af125

What is the expected behavior?

_No response_

Additional information

Steps to reproduce:

  1. Open Codex App on macOS.
  2. Click "Sign in with ChatGPT".
  3. Sign in with my ChatGPT Plus account.
  4. Open a local project in Codex App.
  5. Send a simple prompt such as "hello" or ask Codex to inspect the project.
  6. Codex App calls https://api.openai.com/v1/responses and returns a 401 Unauthorized error.

I also reproduced the same issue in Codex CLI:

  1. Run:

codex logout
codex login

  1. Sign in with the same ChatGPT Plus account.
  1. Run:

codex

  1. Send a simple prompt:

hello

  1. The CLI returns the same 401 Unauthorized error.

Error message:

unexpected status 401 Unauthorized: You have insufficient permissions for this operation. Missing scopes: api.responses.write. Check that you have the correct role in your organization and project, and if you're using a restricted API key, that it has the necessary scopes.

Expected behavior:

Codex App and Codex CLI should work with ChatGPT sign-in because the same account can use Codex Web successfully at https://chatgpt.com/codex.

Actual behavior:

Codex Web works, but Codex App and Codex CLI fail with 401 Unauthorized / Missing scopes: api.responses.write.

Thread ID:

N/A

Request IDs:

req_f64a6758fba447b89898cbf16439d3c3

View original on GitHub ↗