Providers & Search

OAuth Accounts

Quick answer
Prism can sign in to OpenAI with your ChatGPT account and route Codex requests without an API key. It runs the OAuth flow itself, stores the tokens locally, refreshes them automatically, and shows session and weekly usage for every account you add.

Last updated Reviewed against Prism v0.3.26

Add a Codex account

1

Open the OAuth tab

Go to http://127.0.0.1:8765/admin and select the OAuth tab.
2

Click Add Codex Account

Prism generates a PKCE verifier and challenge and opens your browser at OpenAI's authorisation page. Sign in with the account you want to use.
3

Approve and return

After you approve, the browser lands on Prism's local callback and the account appears in the list. Prism reads the ChatGPT account id out of the returned token, so you never paste it.
4

Activate the account

If you have more than one account, set the active one. Prism routes Codex requests to the active account and keeps the others available for switching.
Device flow fallback
When a browser round-trip is not possible, Prism can use OpenAI's device-code flow instead: it shows a short code and a URL to enter it at, then polls until you approve.

What Prism does with the tokens

BehaviourDetail
StorageTokens live in config.json in Prism's per-user config directory. They never leave the machine except as the upstream request's own Authorization header.
RefreshPrism refreshes the access token before it expires, so a long-running session does not fail mid-request.
Account idThe chatgpt-account-id is extracted from the token's claims automatically.
UsagePrism shows session percentage, weekly percentage and reset times, refreshed from the account's usage endpoint.
RemovalRemoving an account deletes its tokens from the config and stops routing to it.

Why Codex routes to chatgpt.com

Codex accounts are authenticated against https://chatgpt.com/backend-api/codex/responses, not api.openai.com. That is deliberate: the ChatGPT backend accepts the OAuth bearer token, while api.openai.com expects an API key and will reject it. Routing to the backend also sidesteps the Cloudflare rules that block bearer tokens on the public API host.

Use a Codex model

Add the model in the Models tab, give it the Codex account as its provider, and set api to responses if Prism does not infer it. Then reference it like any other model:

{
  "known_models": [
    {
      "id": "gpt-5-codex",
      "provider": "codex_ab12cd",
      "api": "responses",
      "context_length": 200000,
      "capabilities": { "tool_calling": true, "vision": true }
    }
  ]
}
Two limits worth knowing
Prism's local web search interception does not run on Codex OAuth accounts, and Codex accounts are subject to your ChatGPT plan's session and weekly limits — which is exactly what the usage panel is reporting.

Switching between an API key and OAuth

You can keep both. Add an OpenAI API key as a custom provider and a Codex account through OAuth, then assign different models to each. Nothing about the agent configuration changes; only the model's provider field decides which credential is used.