Codex login expired? Fix repeated login prompts
When Codex keeps reopening the login flow, it's almost always one account's saved auth, not a broken install. Do not delete your whole setup. Refresh that one account, Open it again, and start the next session clean.
Why this happens
- The saved token for that Codex account expired or was revoked.
- The account changed state, for example after a password change or security review.
- You're on SSH or a headless box, where the normal browser flow doesn't fit.
Fast fix
CLI-only steps
- Run
codexonce and confirm it is really a login prompt, not a 429 or network problem. - If you manage accounts with the CodexUse CLI, refresh the affected account instead of deleting everything.
- On remote or headless sessions, prefer
--login=deviceso you can complete auth from another device.
CodexUse path
- In the Accounts tab, find the account that shows Needs sign-in.
- Refresh that account with browser or device auth.
- Click Open on it, then start the next Codex task in its window.
codexuse profile list
codexuse profile refresh Work --login=device
codexuse profile switch Work
codexuse profile current
Use --login=browser on a normal desktop session. Use --login=device on SSH or headless Linux.
If refresh still fails
- Remove and re-add only the broken account, not every saved account.
- Check whether the same OpenAI account is saved under more than one name, which muddies local hygiene.
- Rule out a network or status issue before you assume the credentials are bad.
Prevent it next time
- Keep personal, work, and client accounts clearly named so you know exactly which one expired.
- Refresh before you remove. It keeps the account's settings and the fix stays narrow.
- Default to device auth on headless or SSH-heavy workflows.
Troubleshooting table
| Symptom | Likely cause | Action |
|---|---|---|
| Codex opens login every time it starts | That account's auth is expired or revoked | Refresh that specific account, then Open it again |
| Refresh works but the next run still feels wrong | The existing shell or session started before the refresh | Open a fresh terminal tab or start the next Codex turn after refreshing |
| Browser login is awkward over SSH | The environment is effectively headless | Use codexuse profile refresh <name> --login=device |
What to copy and paste
What to avoid
- Reinstalling the CLI before you confirm it is only an expired login.
- Removing every saved account when only one is stale.
- Assuming an old shell picks up the refreshed account mid-session.
Related
Why does Codex keep asking me to log in?
The saved auth for that account expired or was revoked. Usually the fix is to re-authenticate the affected account, not reinstall the whole toolchain.
Should I remove the account when login expires?
Not first. Try refreshing the account first. Remove and re-add only if the refresh path still leaves the account at Needs sign-in.
What if I am on SSH or a headless machine?
Use device auth instead of a browser flow. The CodexUse CLI supports refreshing an account with --login=device, which fits remote and Linux server sessions better.