Skip to content

Add ChatGPT subscription provider via OAuth 2.0 PKCE (#53166) (cherry-pick to preview) - #56807

Merged
zed-zippy[bot] merged 1 commit into
v1.3.xfrom
cherry-pick-v1.3.x-37f6d7a1
May 14, 2026
Merged

zed-zippy[bot] merged 1 commit into
v1.3.xfrom
cherry-pick-v1.3.x-37f6d7a1

Conversation

@zed-zippy

@zed-zippy zed-zippy Bot commented May 14, 2026

Copy link
Copy Markdown
Contributor

Cherry-pick of #53166 to preview


Adds a new language model provider that lets users authenticate with
their ChatGPT Plus/Pro subscription and use OpenAI models
(codex-mini-latest, o4-mini, o3) directly in the Zed agent — without
needing a separate API key.

How it works

  1. OAuth 2.0 + PKCE sign-in: Uses OpenAI's official Codex CLI client
    ID to run an authorization code flow. A local HTTP server on
    127.0.0.1:1455 captures the callback, exchanges the code for tokens,
    and stores them in the system keychain.

  2. Token refresh: Access tokens are automatically refreshed when
    they're within 5 minutes of expiry, using the stored refresh token.

  3. Responses API: Requests go to
    https://chatgpt.com/backend-api/codex/responses using the existing
    open_ai::responses client (Responses API format, not Chat Completions
    which was deprecated for this endpoint in Feb 2026).

  4. Required headers: originator: zed, OpenAI-Beta: responses=experimental, ChatGPT-Account-Id (extracted from JWT),
    store: false in the body.

Files changed

  • crates/open_ai/src/responses.rs: Add store: Option<bool> field to
    Request; add extra_headers param to stream_response for
    per-provider header injection
  • crates/language_models/src/provider/openai_subscribed.rs: New
    provider (sign-in UI, OAuth flow, token storage/refresh, model list)
  • crates/language_models/src/provider/open_ai.rs,
    open_ai_compatible.rs, opencode.rs: Pass vec![] for new
    extra_headers param
  • crates/language_models/src/language_models.rs: Register the new
    provider
  • crates/language_models/Cargo.toml: Add rand and sha2 deps for
    PKCE

Open questions / known gaps

  • Terms of service: Usage appears to be within OpenAI's ToS
    (interactive use via their official CLI client ID), but needs legal
    sign-off before shipping
  • Redirect URI: Currently http://localhost:1455/auth/callback
    — may need to match exactly what OpenAI's Codex CLI uses
  • UI polish: The sign-in card is functional but minimal; needs
    design review
  • Error messages: OAuth error responses from the callback URL
    aren't surfaced to the user yet
  • o3 availability: o3 may require a higher subscription tier;
    consider gating it

Testing

Sign-in flow was designed to match the Copilot Chat provider pattern.
Manual testing against the live OAuth endpoint is needed.

Release Notes:

  • Added ChatGPT subscription provider, allowing users to use their
    ChatGPT Plus/Pro subscription with the Zed agent

Co-authored-by: Zed Zippy <234243425+zed-zippy[bot]@users.noreply.github.com>
Co-authored-by: Richard Feldman richard@zed.dev
Co-authored-by: Richard Feldman oss@rtfeldman.com
Co-authored-by: Agus Zubiaga agus@zed.dev

Adds a new language model provider that lets users authenticate with
their ChatGPT Plus/Pro subscription and use OpenAI models
(codex-mini-latest, o4-mini, o3) directly in the Zed agent — without
needing a separate API key.

## How it works

1. **OAuth 2.0 + PKCE sign-in**: Uses OpenAI's official Codex CLI client
ID to run an authorization code flow. A local HTTP server on
`127.0.0.1:1455` captures the callback, exchanges the code for tokens,
and stores them in the system keychain.

2. **Token refresh**: Access tokens are automatically refreshed when
they're within 5 minutes of expiry, using the stored refresh token.

3. **Responses API**: Requests go to
`https://chatgpt.com/backend-api/codex/responses` using the existing
`open_ai::responses` client (Responses API format, not Chat Completions
which was deprecated for this endpoint in Feb 2026).

4. **Required headers**: `originator: zed`, `OpenAI-Beta:
responses=experimental`, `ChatGPT-Account-Id` (extracted from JWT),
`store: false` in the body.

## Files changed

- `crates/open_ai/src/responses.rs`: Add `store: Option<bool>` field to
`Request`; add `extra_headers` param to `stream_response` for
per-provider header injection
- `crates/language_models/src/provider/openai_subscribed.rs`: New
provider (sign-in UI, OAuth flow, token storage/refresh, model list)
- `crates/language_models/src/provider/open_ai.rs`,
`open_ai_compatible.rs`, `opencode.rs`: Pass `vec![]` for new
`extra_headers` param
- `crates/language_models/src/language_models.rs`: Register the new
provider
- `crates/language_models/Cargo.toml`: Add `rand` and `sha2` deps for
PKCE

## Open questions / known gaps

- [ ] **Terms of service**: Usage appears to be within OpenAI's ToS
(interactive use via their official CLI client ID), but needs legal
sign-off before shipping
- [ ] **Redirect URI**: Currently `http://localhost:1455/auth/callback`
— may need to match exactly what OpenAI's Codex CLI uses
- [ ] **UI polish**: The sign-in card is functional but minimal; needs
design review
- [ ] **Error messages**: OAuth error responses from the callback URL
aren't surfaced to the user yet
- [ ] **`o3` availability**: o3 may require a higher subscription tier;
consider gating it

## Testing

Sign-in flow was designed to match the Copilot Chat provider pattern.
Manual testing against the live OAuth endpoint is needed.

Release Notes:

- Added ChatGPT subscription provider, allowing users to use their
ChatGPT Plus/Pro subscription with the Zed agent

---------

Co-authored-by: Zed Zippy <234243425+zed-zippy[bot]@users.noreply.github.com>
Co-authored-by: Richard Feldman <richard@zed.dev>
Co-authored-by: Richard Feldman <oss@rtfeldman.com>
Co-authored-by: Agus Zubiaga <agus@zed.dev>
@cla-bot cla-bot Bot added the cla-signed The user has signed the Contributor License Agreement label May 14, 2026
@zed-community-bot zed-community-bot Bot added the bot Pull requests authored by a bot label May 14, 2026
@zed-zippy
zed-zippy Bot merged commit 28529b4 into v1.3.x May 14, 2026
41 checks passed
@zed-zippy
zed-zippy Bot deleted the cherry-pick-v1.3.x-37f6d7a1 branch May 14, 2026 22:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bot Pull requests authored by a bot cla-signed The user has signed the Contributor License Agreement

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant