Codex CLI Sign-In: ChatGPT Account vs API Key
The Codex CLI signs in one of two ways: with your ChatGPT account, which draws on your plan’s included usage, or with an OpenAI API key, billed per token to your OpenAI Platform account. How each works, what each can reach, how they bill, and how to switch between them.
7 min read
There is no separate Codex API key. The Codex CLI signs in either with your ChatGPT account or with an ordinary OpenAI API key from the OpenAI Platform dashboard. Sign in with ChatGPT and Codex draws on the usage included in your ChatGPT plan, shared with Codex in the desktop app, cloud tasks and ChatGPT Work; it is the only route to Codex Cloud, GitHub code review and the Slack and Linear integrations. Sign in with an API key and every request is billed per token, at standard API rates, to your OpenAI Platform account, with no plan window to run out of; it covers local work in the CLI, the IDE extension and the desktop app, and it is what OpenAI recommends for CI. codex login starts the first route, codex login --with-api-key the second, and codex logout clears whichever is active.
The two routes at a glance
OpenAI’s authentication page (opens in a new tab) calls them “Sign in with ChatGPT for subscription access” and “Sign in with an API key for usage-based access.” The desktop app, the CLI and the IDE extension accept both for local work; Codex Cloud requires ChatGPT. Beyond billing, the choice decides which rules govern your data: a ChatGPT sign-in follows your ChatGPT workspace’s permissions, role-based access control and retention settings, while an API key follows your API organization’s retention and data-sharing settings.
- Sign in with ChatGPT: included plan usage, five-hour windows with weekly limits that may also apply, cloud tasks and integrations, workspace controls. Needs a browser once, or a device code.
- API key: pay per token, the models your key can access, local surfaces and scripting only, API organization controls. Needs nothing but the key.
Signing in with ChatGPT
Run codex in a project, or codex login, and choose Sign in with ChatGPT. A browser window opens, you sign in, and the browser hands the credentials back to the CLI. This is the default path whenever there is no valid session. Codex refreshes the tokens during use, so an active session rarely asks you to sign in again.
On a remote or headless machine, where the browser cannot reach the CLI’s local callback, use device code sign-in, which OpenAI marks as beta: codex login --device-auth, then open the link on any device and enter the one-time code. You may first need to allow device code login in your ChatGPT security settings, or ask a workspace admin to. OpenAI documents two fallbacks: forward the callback port (1455 by default) over SSH, or sign in on a machine with a browser and copy ~/.codex/auth.json across.
Signing in with an OpenAI API key
Get a key from the OpenAI Platform dashboard, then pipe it to the CLI through standard input so it never lands in your shell history:
printenv OPENAI_API_KEY | codex login --with-api-key codex login status # prints the active sign-in method codex logout # clears the stored credentials
In the desktop app, choose Sign in another way on the signed-out screen and enter the key; in the IDE extension, choose Use API Key. The CLI and the extension share one cached sign-in, so switching in one switches the other. The CLI reference (opens in a new tab) notes that codex login status exits with 0 when credentials are present, which makes it a cheap check at the top of a script.
Which bills how
With ChatGPT, Codex is part of what your plan already includes. You do not pay per task; you spend an allowance that is estimated per five-hour window, with weekly limits that may also apply, and that the CLI shares with the desktop app, cloud tasks and ChatGPT Work. How far it goes depends on the model, the size of each task and whether it runs locally or in the cloud. When it runs out, Plus and Pro users can buy credits, and workspaces on flexible pricing can buy workspace credits. The detail is in Codex usage limits.
With an API key, OpenAI “bills API key usage through your OpenAI Platform account at standard API rates.” There is no window and no plan ceiling: every token of every session is metered, and the bill is whatever you used. Codex itself puts no cap on it. Which models you can pick follows the API models available to your key, rather than the models in your ChatGPT plan. Image generation, where available, is also charged at API prices.
The two can be combined. OpenAI’s pricing FAQ says anyone who reaches their plan’s limit “may also run extra local chats using an API key,” charged at API rates. Keep the ChatGPT sign-in for daily work and switch to a key for a burst that would otherwise wait for the window to reset.
What an API key cannot do
OpenAI says API-key sign-in “supports local Codex workflows, but some features that rely on ChatGPT workspace access or cloud services are limited or unavailable.” In practice:
- No Codex Cloud: no cloud tasks, cloud environments or
codex cloudsubmissions. - No GitHub code review or
@codexdelegation on pull requests, and no Slack or Linear integration. - Plugins: OpenAI-curated plugins work in the CLI and the desktop app, but some are missing because their sign-in flows need OAuth features API keys do not support.
- No ChatGPT Voice in the desktop app, and no local computer access for Work Cloud.
Which to choose
- You have a ChatGPT plan and work interactively: sign in with ChatGPT. It costs nothing extra and unlocks the cloud.
- You run Codex in CI or a scheduled job with
codex exec: use an API key. OpenAI recommends it for automation and warns not to expose Codex execution in untrusted or public environments. - Your company has no ChatGPT workspace but does have an API organization: an API key, under that organization’s data settings.
- You are on ChatGPT Enterprise and your automation needs workspace entitlements: ask an admin about Codex access tokens, which permitted members can create and pipe in with
codex login --with-access-token.
Switching, and keeping credentials safe
To switch, run codex logout, which removes saved credentials for both methods, then sign in the other way. If Codex refuses to switch, an admin may have pinned the method: the configuration reference (opens in a new tab) lists forced_login_method, set to chatgpt or api, and if your credentials do not match it Codex logs you out and exits.
Codex caches credentials either in ~/.codex/auth.json in plain text, or in your operating system’s credential store. Set cli_auth_credentials_store in config.toml to keyring to require the OS store, auto to prefer it, file for the JSON file, or ephemeral to keep them in memory for one process. OpenAI’s warning is blunt: treat auth.json like a password, and never commit it, paste it into a ticket or share it in chat. The same goes for the API key itself.
The board needs its own credential
Codex’s sign-in decides who pays for the model. It does not decide what Codex may do on your other tools; each MCP server signs in separately. fenbs, a task board your team and your AI assistants share, connects in config.toml at https://fenbs.ai/api/mcp with a browser OAuth sign-in, and the assistant then acts as you, narrowed to the scopes you ticked: read, write, comment. For a CI job running codex exec, where no browser is available, issue a token in fenbs under Settings, “Connect an AI assistant”, with a name, only the scopes the job needs and an expiry, and pass it through the stdio bridge, npx -y fenbs-mcp, with FENBS_TOKEN in its environment. Revoking the token stops that job at once, and everything it did stays in History under its name.
Related
Set-up page: Codex CLI on fenbs. What ChatGPT Codex is and where its tasks run: ChatGPT Codex. Every command and config key: Codex CLI commands. Habits for a good session: Codex CLI best practices.