Skip to content
Closed
10 changes: 7 additions & 3 deletions docs-site/src/content/docs/fr/guides/codex-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,11 @@ Ces routes ne se rabattent jamais l'une sur l'autre. Les configurations v1 distr

## Injection de configuration

`ocx init`, `ocx start` et `ocx sync` appellent l'injecteur. Sur la liaison de bouclage par défaut, il conserve
Par défaut, seuls les points de terminaison loopback autonomes sans jeton d’admission ouvrent Codex sans connexion séparée. Les connexions clientes et les cibles authentifiées par jeton conservent `requires_openai_auth = true` et `OPENCODEX_API_AUTH_TOKEN`, même avec une URL loopback. Le réglage dans Dashboard → Overview utilise les comptes et fournisseurs enregistrés dans OpenCodex. Redémarrez Codex après modification.

Ce réglage supprime uniquement la connexion séparée à Codex Desktop : il ne crée ni ne sélectionne d’identifiants et n’accorde aucun accès supplémentaire. Pool sélectionne les comptes Codex configurés ; Direct exige toujours les identifiants du compte appelant/principal. Luna Reserve exige aussi le mode local `codexDesktopAuthless` effectif, des identifiants et une autorisation actuelle du fournisseur liée à ces identifiants. La présence dans le catalogue ne suffit pas à autoriser une requête. Luna Reserve est pris en charge uniquement via l’adaptateur canonique ChatGPT-forward avec une autorisation amont liée aux identifiants. L’authentification par clé API et les passerelles Responses arbitraires ne sont pas éligibles. Pour les requêtes ChatGPT, ni Pool ni Direct ne se rabat sur des identifiants par clé API ; le mécanisme de repli distinct pour la génération d’images concerne uniquement les requêtes d’images.

`ocx init`, `ocx start` et `ocx sync` appellent l’injecteur lorsque l’intégration Codex est activée. Sinon, l’injection est ignorée ; une synchronisation du catalogue seul ne modifie pas la configuration Codex. Avec `codexDesktopAuthless: false`, sur la liaison de bouclage, il conserve
l'identifiant du fournisseur `openai` intégré à Codex et fait pointer ce fournisseur vers opencodex :

```toml
Expand Down Expand Up @@ -121,7 +125,7 @@ model_catalog_json = "/absolute/path/to/opencodex-catalog.json"
# appended at the end of the file
# Auto-injected by opencodex
[model_providers.opencodex]
name = "OpenCodex Proxy"
name = "OpenCodex"
base_url = "http://your-host:10100/v1"
wire_api = "responses"
requires_openai_auth = true
Expand Down Expand Up @@ -185,7 +189,7 @@ le proxy renvoie `426` et Codex se rabat sur HTTP/SSE.

## Identité et historique du fil de discussion

La configuration de bouclage par défaut conserve l'étiquette du fournisseur natif `openai` de Codex sur les
La configuration de bouclage avec `codexDesktopAuthless: false` conserve l'étiquette du fournisseur natif `openai` de Codex sur les
nouveaux fils ; la reprise normale de l'historique ne nécessite donc aucun remappage. La synchronisation et la
restauration n'appliquent qu'un manifeste de sauvegarde correspondant et rétablissent exactement le fournisseur,
la source et l'indicateur d'événement d'origine. Une ligne `opencodex` sans manifeste reste inchangée ; utilisez
Expand Down
36 changes: 23 additions & 13 deletions docs-site/src/content/docs/guides/codex-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -22,8 +22,9 @@ configs migrate to marker 2 and preserve `config.json.pre-openai-tiers-v2.bak` f

## Config injection

`ocx init`, `ocx start`, and `ocx sync` call the injector. On the default loopback bind, it keeps
Codex's built-in `openai` provider id and points that provider at opencodex:
`ocx init`, `ocx start`, and `ocx sync` call the injector when the Codex integration is enabled. If the integration is disabled, injection is skipped; catalog-only synchronization leaves Codex configuration unchanged. For standalone loopback targets that require no admission token, it defaults to the
[authless dedicated provider](#authless-codex-desktop). If `codexDesktopAuthless` is explicitly
`false`, it keeps Codex's built-in `openai` provider id and points that provider at opencodex:

```toml
# root keys, before the first table
Expand Down Expand Up @@ -154,7 +155,7 @@ model_catalog_json = "/absolute/path/to/opencodex-catalog.json"
# appended at the end of the file
# Auto-injected by opencodex
[model_providers.opencodex]
name = "OpenCodex Proxy"
name = "OpenCodex"
base_url = "http://your-host:10100/v1"
wire_api = "responses"
requires_openai_auth = true
Expand Down Expand Up @@ -207,21 +208,30 @@ warn about this exact mismatch and print redacted target paths. If a background
from that Orca shell, uninstall it from the original shell first, then set `CODEX_HOME` to the app
home, unset `ORCA_CODEX_HOME`, rerun sync/restore, and install the service again.

In dedicated-provider mode, `requires_openai_auth = true` keeps Codex App/TUI account-gated surfaces
In non-loopback dedicated-provider mode, `requires_openai_auth = true` keeps Codex App/TUI account-gated surfaces
aligned with native Codex. opencodex also serves `/v1/responses` over WebSocket. The dedicated
provider advertises `supports_websockets = true` only when `"websockets": true`; on loopback Codex's
built-in provider may try WebSocket first, and a disabled proxy returns `426` so Codex falls back to
HTTP/SSE.

### Authless Codex Desktop (opt-in)
### Authless Codex Desktop

Codex Desktop shows its ChatGPT login screen whenever the active provider requires OpenAI auth. If
your OpenCodex setup never uses ChatGPT credentials (routed providers only, or a blocked
`chatgpt.com`), you can opt out of that gate:
Codex Desktop starts without a separate ChatGPT login by default for standalone loopback targets
that require no admission token. Client connections and other admission-authenticated targets
keep `requires_openai_auth = true` and `OPENCODEX_API_AUTH_TOKEN`, even when their URL is loopback.
OpenCodex still authenticates requests with the accounts and providers saved in OpenCodex;
ChatGPT accounts in Pool mode remain available. Direct mode still requires caller/main credentials.
The switch does not create or select credentials or grant account permissions. Luna Reserve still
requires effective local `codexDesktopAuthless` mode, the appropriate credentials and a current upstream permission. Catalog visibility alone never authorizes a request. Luna Reserve is supported only through the canonical ChatGPT-forward adapter with credential-bound upstream authorization. API-key authentication and arbitrary Responses gateways do not qualify. For ChatGPT requests, neither Pool nor Direct falls back to API-key credentials; the separate image-generation fallback applies only to image requests.

Toggle **Open Codex without signing in** in **Dashboard → Overview**. Saving synchronizes the
Codex configuration; restart Codex to apply the change. If synchronization is pending, the dashboard
shows a retry hint. Existing configurations with an explicit `false` keep the login requirement;
a missing key adopts the new enabled default on the next sync or start. The CLI remains available:

```bash
ocx system settings --desktop-authless on # or "codexDesktopAuthless": true in config.json
ocx sync # rewrites ~/.codex/config.toml; restart Desktop
ocx system settings --desktop-authless off # restore the native login requirement
ocx sync # then restart Codex Desktop
```

With the switch on, a loopback bind injects the dedicated provider form instead of the root
Expand All @@ -231,15 +241,15 @@ With the switch on, a loopback bind injects the dedicated provider form instead
model_provider = "opencodex"

[model_providers.opencodex]
name = "OpenCodex Proxy"
name = "OpenCodex"
base_url = "http://127.0.0.1:10100/v1"
wire_api = "responses"
requires_openai_auth = false
```

Desktop then starts without a login and routes every turn through the proxy. The setting survives
`ocx start`, restart, `ocx sync`, and `ocx ensure`; turning it off (`--desktop-authless off`) makes the
next sync restore the default loopback form, and `ocx restore` strips it like any other injected
next sync restore the native-provider loopback form, and `ocx restore` strips it like any other injected
routing. What to expect while it is on:

- ChatGPT-gated Desktop chrome (account, usage, Fast mode) stays dark: Codex derives those surfaces
Expand All @@ -257,7 +267,7 @@ without authentication.

## Thread identity and history

The default loopback form keeps new threads tagged with Codex's native `openai` provider, so normal
With `codexDesktopAuthless: false`, the loopback form keeps new threads tagged with Codex's native `openai` provider, so normal
resume history needs no remapping. Sync and restore apply only a matching backup manifest and
restore each thread's exact original provider, source, and event marker. A bare `opencodex` row with
no manifest is left unchanged; use `ocx recover-history --legacy-openai --yes` only when you explicitly
Expand Down
10 changes: 7 additions & 3 deletions docs-site/src/content/docs/ja/guides/codex-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,11 @@ opencodex は、Codex が読み取る 2 つの内容 (構成 (`$CODEX_HOME/confi

## 設定の注入

`ocx init`、`ocx start`、および `ocx sync` はインジェクターを呼び出します。デフォルトのループバック バインドでは、Codex の組み込み `openai` プロバイダー ID を保持し、そのプロバイダーを opencodex にポイントします。
アドミッショントークンを必要としない単独のループバック接続先では、既定で別途ログインせずに Codex を開きます。クライアント接続やトークン認証が必要な接続先では、URL がループバックでも `requires_openai_auth = true` と `OPENCODEX_API_AUTH_TOKEN` を維持します。Dashboard → Overview で切り替えられます。OpenCodex に保存されたアカウントとプロバイダーを使用し、変更後は Codex の再起動が必要です。

この設定は Codex Desktop の個別ログインのみを省略し、認証情報の作成・選択やアカウント権限の付与は行いません。Pool は設定済みの Codex アカウントを選択し、Direct は引き続き呼び出し元またはメインアカウントの認証情報を必要とします。Luna Reserve には有効なローカル `codexDesktopAuthless` モード、認証情報、およびその認証情報に紐づく現在のプロバイダーの許可が必要です。カタログに表示されるだけではリクエストは許可されません。 Luna Reserve は、認証情報に紐づく上流の許可を持つ正規の ChatGPT-forward アダプターでのみ利用できます。API キー認証や任意の Responses ゲートウェイは対象外です。 ChatGPT リクエストでは、Pool も Direct も API キー認証にフォールバックしません。別途用意された画像生成のフォールバックは、画像リクエストにのみ適用されます。

`ocx init`、`ocx start`、および `ocx sync` は Codex 統合が有効な場合にインジェクターを呼び出します。統合が無効な場合は注入をスキップし、カタログのみの同期では Codex 設定を変更しません。`codexDesktopAuthless: false` のループバック バインドでは、Codex の組み込み `openai` プロバイダー ID を保持し、そのプロバイダーを opencodex にポイントします。

```toml
# root keys, before the first table
Expand Down Expand Up @@ -84,7 +88,7 @@ model_catalog_json = "/absolute/path/to/opencodex-catalog.json"
# appended at the end of the file
# Auto-injected by opencodex
[model_providers.opencodex]
name = "OpenCodex Proxy"
name = "OpenCodex"
base_url = "http://your-host:10100/v1"
wire_api = "responses"
requires_openai_auth = true
Expand Down Expand Up @@ -117,7 +121,7 @@ Windows では、ChatGPT/Codex アプリが `%USERPROFILE%\\.codex` を読み取

## スレッドのアイデンティティと履歴

デフォルトのループバック形式では、Codex のネイティブ `openai` プロバイダーでタグ付けされた新しいスレッドが維持されるため、通常の再開履歴には再マッピングが必要ありません。同期と復元は、一致するバックアップマニフェストだけを適用し、各スレッドの元のプロバイダー、ソース、イベントマーカーを正確に復元します。マニフェストのない `opencodex` 行は変更されません。従来の再ラベル付けを明示的に強制する場合にだけ `ocx recover-history --legacy-openai --yes` を使用してください。このコマンドは意図的に広範囲です。ユーザーメッセージを持ち、現在 `opencodex` とタグ付けされているすべてのスレッドを `openai` に変更し、`exec` を `cli` に正規化してイベントマーカーを設定します。正当な専用プロバイダー履歴も対象です。状態をバックアップし、この全範囲を意図する場合にのみ使用してください。非ループバック専用プロバイダー モードでは、アクティブな間は `opencodex` プロバイダーの下で履歴がミラーリングされ、終了時にバックアップされたメタデータが復元されます。履歴を変更しないように `syncResumeHistory: false` を設定します。
`codexDesktopAuthless: false` のループバック形式では、Codex のネイティブ `openai` プロバイダーでタグ付けされた新しいスレッドが維持されるため、通常の再開履歴には再マッピングが必要ありません。同期と復元は、一致するバックアップマニフェストだけを適用し、各スレッドの元のプロバイダー、ソース、イベントマーカーを正確に復元します。マニフェストのない `opencodex` 行は変更されません。従来の再ラベル付けを明示的に強制する場合にだけ `ocx recover-history --legacy-openai --yes` を使用してください。このコマンドは意図的に広範囲です。ユーザーメッセージを持ち、現在 `opencodex` とタグ付けされているすべてのスレッドを `openai` に変更し、`exec` を `cli` に正規化してイベントマーカーを設定します。正当な専用プロバイダー履歴も対象です。状態をバックアップし、この全範囲を意図する場合にのみ使用してください。非ループバック専用プロバイダー モードでは、アクティブな間は `opencodex` プロバイダーの下で履歴がミラーリングされ、終了時にバックアップされたメタデータが復元されます。履歴を変更しないように `syncResumeHistory: false` を設定します。

## モデルカタログの同期

Expand Down
10 changes: 7 additions & 3 deletions docs-site/src/content/docs/ko/guides/codex-integration.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,11 @@ opencodex는 Codex가 읽는 두 가지, 즉 설정(`$CODEX_HOME/config.toml`,

## 설정 주입

`ocx init`, `ocx start`, `ocx sync`는 모두 인젝터를 호출합니다. 기본 loopback 바인드에서는 Codex의 빌트인 `openai` 프로바이더 id를 그대로 유지한 채, 그 프로바이더가 opencodex를 바라보게 합니다.
접근 토큰이 필요 없는 독립 실행형 루프백 대상에서만 기본적으로 별도 로그인 없이 Codex를 엽니다. 클라이언트 연결이나 토큰 인증이 필요한 대상은 루프백 URL이라도 `requires_openai_auth = true`와 `OPENCODEX_API_AUTH_TOKEN`을 유지합니다. Dashboard → Overview에서 전환할 수 있습니다. OpenCodex에 저장된 계정과 제공자를 사용하며 변경 후 Codex를 다시 시작해야 합니다.

이 설정은 Codex Desktop의 별도 로그인만 생략하며 인증 정보를 생성하거나 선택하지 않고 계정 권한도 부여하지 않습니다. Pool은 설정된 Codex 계정을 선택하고, Direct는 여전히 호출자 또는 메인 계정의 인증 정보가 필요합니다. Luna Reserve는 로컬 `codexDesktopAuthless` 모드가 실제로 활성화되어 있어야 하며, 해당 인증 정보에 연결된 제공자의 현재 허가가 필요합니다. 카탈로그에 표시되는 것만으로 요청이 허가되지는 않습니다. Luna Reserve는 인증 정보에 연결된 업스트림 허가가 있는 정식 ChatGPT-forward 어댑터에서만 지원됩니다. API 키 인증과 임의의 Responses 게이트웨이는 지원 대상이 아닙니다. ChatGPT 요청에서 Pool과 Direct는 모두 API 키 인증 정보로 대체하지 않습니다. 별도의 이미지 생성 대체 경로는 이미지 요청에만 적용됩니다.

`ocx init`, `ocx start`, `ocx sync`는 Codex 통합이 활성화된 경우 인젝터를 호출합니다. 통합이 꺼져 있으면 주입을 건너뛰며, 카탈로그 전용 동기화는 Codex 설정을 변경하지 않습니다. `codexDesktopAuthless: false`인 loopback 바인드에서는 Codex의 빌트인 `openai` 프로바이더 id를 그대로 유지한 채, 그 프로바이더가 opencodex를 바라보게 합니다.

```toml
# root keys, before the first table
Expand Down Expand Up @@ -88,7 +92,7 @@ model_catalog_json = "/absolute/path/to/opencodex-catalog.json"
# appended at the end of the file
# Auto-injected by opencodex
[model_providers.opencodex]
name = "OpenCodex Proxy"
name = "OpenCodex"
base_url = "http://your-host:10100/v1"
wire_api = "responses"
requires_openai_auth = true
Expand Down Expand Up @@ -121,7 +125,7 @@ Windows에서 Orca shell은 `CODEX_HOME`과 `ORCA_CODEX_HOME`을 Orca의 번들

## 스레드 식별자와 대화 기록

기본 loopback 형식은 새 thread에 네이티브 `openai` provider 태그를 유지하므로 일반적인 resume history는 다시 매핑할 필요가 없습니다. sync와 restore는 일치하는 백업 manifest만 적용하여 각 thread의 원래 provider, source, event marker를 정확히 복원합니다. manifest가 없는 `opencodex` row는 변경하지 않으며, legacy 재태깅을 명시적으로 강제하려는 경우에만 `ocx recover-history --legacy-openai --yes`를 사용합니다. 이 명령은 의도적으로 범위가 넓습니다. 사용자 메시지가 있고 현재 `opencodex`로 표시된 모든 thread를 `openai`로 바꾸고, `exec`를 `cli`로 정규화하며 event marker를 설정합니다. 정상적인 dedicated-provider history도 포함됩니다. 상태를 백업하고 이 전체 범위를 의도한 경우에만 사용하세요. non-loopback 전용 provider 모드는 활성 상태일 때만 history를 `opencodex` provider 아래로 미러링하고, 종료할 때는 백업된 메타데이터를 복원합니다. history를 건드리지 않으려면 `syncResumeHistory: false`로 설정하세요.
`codexDesktopAuthless: false`인 loopback 형식은 새 thread에 네이티브 `openai` provider 태그를 유지하므로 일반적인 resume history는 다시 매핑할 필요가 없습니다. sync와 restore는 일치하는 백업 manifest만 적용하여 각 thread의 원래 provider, source, event marker를 정확히 복원합니다. manifest가 없는 `opencodex` row는 변경하지 않으며, legacy 재태깅을 명시적으로 강제하려는 경우에만 `ocx recover-history --legacy-openai --yes`를 사용합니다. 이 명령은 의도적으로 범위가 넓습니다. 사용자 메시지가 있고 현재 `opencodex`로 표시된 모든 thread를 `openai`로 바꾸고, `exec`를 `cli`로 정규화하며 event marker를 설정합니다. 정상적인 dedicated-provider history도 포함됩니다. 상태를 백업하고 이 전체 범위를 의도한 경우에만 사용하세요. non-loopback 전용 provider 모드는 활성 상태일 때만 history를 `opencodex` provider 아래로 미러링하고, 종료할 때는 백업된 메타데이터를 복원합니다. history를 건드리지 않으려면 `syncResumeHistory: false`로 설정하세요.

## 모델 카탈로그 동기화

Expand Down
Loading
Loading