@narumitw/pi-codex-accounts

Pi extension for switching self-managed ChatGPT Codex subscription accounts without touching /login.

Packages

Package details

extension

Install @narumitw/pi-codex-accounts from npm and Pi will load the resources declared by the package manifest.

$ pi install npm:@narumitw/pi-codex-accounts
Package
@narumitw/pi-codex-accounts
Version
0.24.0
Published
Jul 21, 2026
Downloads
2,190/mo · 1,003/wk
Author
narumitw
License
MIT
Types
extension
Size
57.2 KB
Dependencies
1 dependency · 2 peers
Pi manifest JSON
{
  "extensions": [
    "./src/codex-accounts.ts"
  ]
}

Security note

Pi packages can execute code and influence agent behavior. Review the source before installing third-party packages.

README

🔐 pi-codex-accounts — Codex Account Switcher for Pi

npm Pi extension License: MIT

[!WARNING] @narumitw/pi-codex-accounts is deprecated and will be replaced by @narumitw/pi-accounts. Do not load both extensions at the same time. To migrate one Pi installation, run:

pi uninstall npm:@narumitw/pi-codex-accounts
pi install npm:@narumitw/pi-accounts

@narumitw/pi-codex-accounts is a native Pi coding agent extension that lets you log in to, switch between, and remove multiple ChatGPT Plus/Pro Codex subscription accounts.

It keeps using Pi's built-in openai-codex provider and does not add provider aliases or register another OAuth provider. While a named account is active, it temporarily adds API-key resolution to that native provider so Pi can consume the account's runtime access token; returning to the default Pi login removes the overlay.

✨ Features

  • Adds /codex-login <name> for storing a named ChatGPT Codex subscription account.
  • Adds /codex-account [name] for switching the active self-managed Codex account.
  • Adds /codex-logout <name> for deleting one self-managed account.
  • Adds (default pi login) in the selector to clear the active self-managed account and return to Pi's normal openai-codex auth.
  • Stores credentials in ~/.pi/agent/pi-codex-accounts.json with private file permissions.
  • Sets a runtime API key on Pi's native openai-codex provider and verifies that Pi can resolve it before reporting activation success.
  • Temporarily installs the native-provider API-key bridge required by Pi's OAuth-only Codex provider, then removes it when self-managed auth becomes inactive.
  • Leaves your selected /model unchanged, matching Pi's built-in /login behavior, except it may select openai-codex/gpt-5.5 when the current model is unknown/unknown.
  • Shows codex:<name> in the statusline only while the current model provider is openai-codex.
  • Fails closed if an active self-managed account cannot refresh or produce a runtime key, so Pi does not silently fall back to a different Codex account.
  • Closes the current session's cached Codex WebSocket when auth changes, preventing a reused connection from staying on the previous account.

📦 Install

pi install npm:@narumitw/pi-codex-accounts

Try without installing permanently:

pi -e npm:@narumitw/pi-codex-accounts

Try this package locally from the repository root:

pi -e ./extensions/pi-codex-accounts

🚀 Usage

Login to named accounts (default is reserved for Pi's built-in login):

/codex-login work
/codex-login personal

Switch accounts:

/codex-account
/codex-account work

Return to Pi's built-in Codex login without deleting any self-managed account:

/codex-account default

Remove one self-managed account:

/codex-logout work

🔐 Auth behavior

The canonical credential file is ~/.pi/agent/pi-codex-accounts.json. A legacy-only codex-accounts.json is migrated under the existing credential-file lock, copied with 0600 permissions, and removed only after the canonical file is installed. If both files exist, the canonical file takes precedence and the legacy file is retained.

When an active self-managed account is set, the extension temporarily overlays Pi's native openai-codex provider with an API-key resolver, applies the account's access token as a runtime key, and verifies the resolved key before reporting success. This bridge is necessary because Pi 0.80.8's native Codex provider is OAuth-only: recording an api_key runtime credential without an API-key resolver leaves the provider unavailable. Login and refresh still use Pi's built-in Codex OAuth implementation through the loader entry point supported by the running Pi version. Runtime key application supports both Pi 0.80.3's auth-storage shape and Pi 0.80.8's model-runtime shape.

When no self-managed account is active, the extension removes its runtime override and native-provider overlay, and Pi uses its normal openai-codex auth resolution. That means existing /login openai-codex, auth.json, or environment behavior still works. Return to /codex-account default before using Pi's built-in /login or /logout flow.

If the active self-managed account cannot refresh or produce an API key, the extension keeps a non-empty failing runtime key in place. This prevents accidental fallback to a different Codex account.

Account switches and token refreshes also close any cached Codex WebSocket for the current Pi session. The next request reconnects with the newly selected credentials; repeated pre-turn checks, including turns started after compaction, keep the connection when auth is unchanged.

🚧 Limitations

  • This extension supports ChatGPT Plus/Pro Codex subscription auth only.
  • It does not rotate accounts automatically or try to bypass rate limits.
  • It does not switch Claude, Anthropic, or browser-cookie sessions.
  • Multiple Pi processes refreshing the same account at the same time are serialized through the extension's credential-file lock, but the newest refreshed token wins.

🗂️ Package layout

extensions/pi-codex-accounts/
├── src/
│   ├── codex-accounts.ts
│   ├── oauth.ts
│   ├── runtime-auth.ts
│   └── storage.ts
├── test/
│   ├── codex-accounts-storage.test.ts
│   └── codex-accounts.test.ts
├── README.md
├── LICENSE
├── tsconfig.json
└── package.json

The package exposes its Pi extension through package.json:

{
  "pi": {
    "extensions": ["./src/codex-accounts.ts"]
  }
}

🔎 Keywords

Pi extension, Pi coding agent, Codex, ChatGPT Plus, ChatGPT Pro, subscription account switching, OAuth.

📄 License

MIT. See LICENSE.