OAuth Accounts
Last updated Reviewed against Prism v0.3.26
Add a Codex account
Open the OAuth tab
http://127.0.0.1:8765/admin and select the OAuth tab.Click Add Codex Account
Approve and return
Activate the account
What Prism does with the tokens
| Behaviour | Detail |
|---|---|
| Storage | Tokens live in config.json in Prism's per-user config directory. They never leave the machine except as the upstream request's own Authorization header. |
| Refresh | Prism refreshes the access token before it expires, so a long-running session does not fail mid-request. |
| Account id | The chatgpt-account-id is extracted from the token's claims automatically. |
| Usage | Prism shows session percentage, weekly percentage and reset times, refreshed from the account's usage endpoint. |
| Removal | Removing an account deletes its tokens from the config and stops routing to it. |
Why Codex routes to chatgpt.com
Codex accounts are authenticated against https://chatgpt.com/backend-api/codex/responses, not api.openai.com. That is deliberate: the ChatGPT backend accepts the OAuth bearer token, while api.openai.com expects an API key and will reject it. Routing to the backend also sidesteps the Cloudflare rules that block bearer tokens on the public API host.
Use a Codex model
Add the model in the Models tab, give it the Codex account as its provider, and set api to responses if Prism does not infer it. Then reference it like any other model:
{
"known_models": [
{
"id": "gpt-5-codex",
"provider": "codex_ab12cd",
"api": "responses",
"context_length": 200000,
"capabilities": { "tool_calling": true, "vision": true }
}
]
}Switching between an API key and OAuth
You can keep both. Add an OpenAI API key as a custom provider and a Codex account through OAuth, then assign different models to each. Nothing about the agent configuration changes; only the model's provider field decides which credential is used.