The Codex Changelog
All Episodes
Codex CLI 0.154.0 Fixes OAuth Refresh Chaos

Codex CLI 0.154.0 Fixes OAuth Refresh Chaos

0:00|0:00

This episode breaks down Codex CLI 0.154.0’s auth overhaul, including coordinated OAuth refreshes that prevent refresh-token family revocation and challenge preservation that pauses a turn for interactive re-login instead of dropping work.

It also covers stdio MCP state sync, headless codex exec failure behavior, and terminal upgrades like formatted copying and a smarter slash copy command.


Chapter 1

Coordinated OAuth Refreshes and Challenge Preservation in 0.154.0

Maya

Um, remember last time when we were staring at Codex CLI and all our external tools just disappeared into thin air after an hour?

Ethan Park

Oh, I remember. We traced it down to that bug where HTTP 400 invalid grant errors were basically getting ignored, and the client just dropped the tools silently. No error, no warning, just gone.

Maya

Right! You go to run a database query or fetch a ticket, and suddenly Codex is like, what tools? I don't know her.

Ethan Park

Well, OpenAI fixed it. Codex CLI 0.154.0 is out, and they updated the core rmcp library to version 3.2.0, adding a dedicated RMCP OAuth credential store adapter. And, uh, it fundamentally changes how token expiration is handled.

Maya

Okay, so what actually happens now when that one hour access token expires?

Ethan Park

A couple of things, but the big one is coordinated OAuth refresh. In the old build, if you had, say, three parallel subagents or tool calls firing at the exact same millisecond when the token expired, all three would independently try to hit the refresh endpoint.

Maya

Oh no! That triggers token family revocation on identity providers like Okta or Auth0! Because the server sees three simultaneous refresh requests using the exact same refresh token, assumes a replay attack, and revokes the whole refresh token family!

Ethan Park

Exactly. One token expires, three tasks try to refresh it at once, and boom, you are completely logged out. Pulling ticket 42413 in this release introduces a mutex lock around the refresh process. The first call initiates the refresh, while the other pending calls wait and share the new credentials once it succeeds.

Maya

That is huge for multi agent workflows! But wait, what if the refresh token itself is expired or revoked? What happens to the running turn?

Ethan Park

That brings us to challenge preservation, under pull request 42552. Previously, if authentication failed, Codex might either auto replay the request with dead credentials or just crash out. Now, it preserves the tool execution handle and surfaces an interactive login prompt right in the terminal UI or app server.

Maya

Wait, so it pauses execution instead of just dropping the task or replaying broken requests in a loop?

Ethan Park

Yeah. It holds the handle, presents the auth challenge, lets you log in, and then resumes the exact turn with the fresh token. And for stdio servers, pull request 43428 adds dynamic state synchronization over app slash installed notifications.

Maya

Wait, say that again. Stdio servers?

Ethan Park

Right. If an opted in stdio MCP server is running, it receives a real time notification that credentials changed without you having to restart your whole session or kill the CLI process.

Chapter 2

Workflow Steps, Headless Caveats, and Terminal Upgrades

Maya

Okay, so for anyone who was constantly doing that annoying workaround where you had to manually delete dot codex slash mcp oauth dot json or run codex mcp logout... how do we upgrade?

Ethan Park

It is straightforward. If you are on npm, run npm install g at openai slash codex at 0.154.0. If you are using Python, run pip install upgrade openai codex equal equal 0.154.0. According to the release notes on GitHub, the Python package automatically includes the matching 0.154.0 CLI binary runtime.

Maya

Okay, but what about headless environments? Like, if I am running codex exec inside a CI CD pipeline or an automated background worker, there is no human sitting there to answer an interactive login prompt.

Ethan Park

Ah, good catch. In non interactive mode under codex exec, when an unresolvable login challenge occurs, the process does not hang forever or spin in an infinite retry loop. It pauses or fails gracefully with a explicit exit code and diagnostic output, so your CI pipeline catches it immediately.

Maya

Thank goodness. Infinite loops in GitHub Actions burn through build minutes so fast.

Ethan Park

Absolutely. Now, outside of the auth overhaul, there are some really slick terminal quality of life updates in 0.154.0 too.

Maya

Oh yeah? Like what?

Ethan Park

First, formatted copying under pull request 42847. When you copy assistant responses out of the terminal, rich text Markdown formatting is preserved when pasting into apps like Slack, Notion, or Google Docs.

Maya

Oh, finally! No more losing code blocks and bold headers when pasting into documentation!

Ethan Park

Right! And pull request 43055 expanded the slash copy command. You can now target specific session state fields directly. Like slash copy status to grab your system status, or slash copy model to copy the current model configuration.

Maya

And I saw Vim mode got some love too in pull 42194?

Ethan Park

Yes! The TUI composer now supports Vim replace mode with capital R, full undo with u, and dot repeat with dot. So if you edit text using modal bindings in the prompt box, your Vim muscle memory actually works now.

Maya

Man, from fixing silent tool drops to proper token refresh locks and Vim replace mode... 0.154.0 feels like a really mature stability release.

Ethan Park

It really is. Grab the update, stop deleting your credential files, and enjoy reliable MCP tools.

Maya

Alright, good chatting! Go upgrade your CLI, everyone.