Codex Desktop Bug: Missing Secret-Manager Capabilities Cause Auth Loops

jyongchul · ghdev · 2026-08-09

A bug report for OpenAI's Codex Desktop on Windows reveals missing runtime capabilities for credential consumption. Even when a task is explicitly authorized to use host-local secret managers (like Google Password Manager) for external web logins, the active session fails to expose the scoped credential tools or declared ownerassistance tools.

Because this limitation is only discovered after work begins, Codex repeatedly falls back to short owner-login windows. These windows expire, causing the external task to stall in an infinite loop. The reporter urges for a safe, auditable credential-consumption API and earlier surfacing of security boundaries or missing capabilities.

Original post →

More from coding & agent

coding & agent channel →