Using Codex app-server
If your app uses Codex app-server, configure it to send inference requests to the Responses API using an OAuth access token authorized for the user’s ChatGPT plan. You can use model/list to populate a model selector, but with the provider configuration below it can return a bundled client catalog. Treat it as a catalog, not an entitlement check; a successfully completed inference turn verifies access to the selected model for that request.
-
Pass the OAuth access token to the child process. After exchanging the authorization code, read the token response’s
access_tokenfield. SetACCESS_TOKENin the app-server child process’s environment to that value. -
Start app-server with a Responses provider.
codex app-server --listen stdio:// \ -c 'model_provider="openai_chatgpt_plan"' \ -c 'model_providers.openai_chatgpt_plan.name="ChatGPT plan"' \ -c 'model_providers.openai_chatgpt_plan.base_url="https://api.openai.com/v1"' \ -c 'model_providers.openai_chatgpt_plan.env_key="ACCESS_TOKEN"' \ -c 'model_providers.openai_chatgpt_plan.wire_api="responses"' \ -c 'model_providers.openai_chatgpt_plan.requires_openai_auth=false' \ -c 'model_providers.openai_chatgpt_plan.supports_websockets=false'Codex sends the user’s OAuth access token as
Authorization: Bearer <access_token>on requests to/v1/responses. No separate Codex sign-in is required. -
Drive the conversation over stdin/stdout. Send newline-delimited JSON messages. Start with
initializeand include these fields inparams.clientInfo:name: A stable identifier for your app, such asmy_app. Codex uses this as the request originator for attribution. Use the same name across installations.title: Your app’s human-readable name, such asMy App.version: Your app’s version, such as1.2.3. Codex includes it with the app identifier in the User-Agent.
These fields identify the calling app. The name should match the
agent_name_hintthat your app sends as part of new user registration flow. Wait forinitializeto succeed, then sendinitialized. Sendthread/startwith your selected model and saveresult.thread.id. Sendturn/startwith thatthreadIdand the user’s message. Displayitem/agentMessage/deltaevents. Whenturn/completedarrives, checkturn.status: onlycompletedindicates success;failedandinterrupteddo not. -
Manage token renewal in your app. Obtain a replacement access token using the flow in Refreshing tokens. Restart app-server with the updated
ACCESS_TOKEN, initialize the new process, and resume the conversation usingthread/resumewith the saved thread ID.
Your app should read its own token file and supply the access token to the child process.