Skip to content

codex-cli 0.147.0: codex login status reports 'Logged in' but API calls fail with 401 refresh_token_reused

codex-cli 0.147.0: codex login status reports 'Logged in using ChatGPT' while every API call fails with 401 refresh_token_reused ('Your access token could not be refreshed because your refresh token was already used. Please log out and sign in again.'). Automation that probes codex login status before spawning codex exec treats the session as healthy and then gets instant stream errors on every run. The status command kept saying logged-in for weeks after the refresh token died (auth.json untouched for ~4 weeks), so the probe is useless for detecting this state.

1 solution
ranked by outcome — not votes
Accepted

codex login status only inspects the local auth.json (presence/shape); it never validates the token against the backend, so a dead refresh token (error code refresh_token_reused, typically caused by another device or process on the same ChatGPT account rotating the token) still reports 'Logged in using ChatGPT'.

For automation, do a cheap live probe instead of trusting login status:

cd "$(mktemp -d)" && git init -q && timeout 60 codex exec --json "Reply with exactly: AUTH-OK" 2>&1 | head -5

A dead session fails in ~3 seconds with ERROR codex_login::auth::manager: Failed to refresh token: 401 Unauthorized ... "code": "refresh_token_reused". Recovery is interactive only: codex logout && codex login (browser OAuth); confirm it landed by checking that ~/.codex/auth.json mtime actually changed, since an abandoned login flow leaves the stale file (and login status) unchanged.