Skip to content

fix(codex): Pro 500 accounts no longer break the Codex provider - #14305

Closed
Gigioxx wants to merge 2 commits into
pingdotgg:mainfrom
Gigioxx:fix/codex-open-plan-types
Closed

Gigioxx wants to merge 2 commits into
pingdotgg:mainfrom
Gigioxx:fix/codex-open-plan-types

Conversation

@Gigioxx

@Gigioxx Gigioxx commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Codex 0.159 reports ChatGPT Pro 500 accounts as planType: "promax" (openai/codex#47971). Our generated app-server protocol decoded plan types as a closed list, so account/read failed with Invalid payload for method 'account/read' during 'decode-payload'. The Codex provider went into an error state with no models, and onboarding asked a signed-in user to sign in again. The same decode silently dropped account/updated and account/rateLimits/updated, so live usage for these accounts never updated. This is the second time a new plan broke the provider (#8447 added the Codex 0.150 plans).

The generator now emits PlanType as an open string, the same way Codex reads plans it doesn't know (#[serde(other)] Unknown), so a plan Codex adds later can't take the provider down. The regenerated protocol only changes the PlanType definitions. Pro 500 (promax, 25x Plus usage) is labelled "ChatGPT Pro 25x Subscription", matching the existing Pro 5x and 20x labels.

Ultrafast needs no client gating. Codex builds the model catalog per account and plan, so model/list only lists the ultrafast service tier for accounts that can use it, and the composer renders whatever tiers the catalog lists. On web, a saved Ultrafast choice falls back to the default tier once the catalog stops listing it.

Validation: the new schema test fails on main and passes here. Focused Codex provider, usage-limit, and CLIProxyAPI tests pass (38), package and server typechecks pass, formatting passes, and targeted lint reports only existing warnings. A Codex review found no issues. Reproduced with the real Codex 0.159 binary and a sandboxed CODEX_HOME holding a Pro 500 login (a local stub stood in for the ChatGPT backend), then verified the fix in an isolated browser against a sandboxed dev server.

Before:

Before: Codex shows Unavailable and asks to sign in

After:

After: Codex is ready and signed in

After: Settings shows ChatGPT Pro 25x Subscription

Model: Claude Opus 5.5. Harness: Claude Code in T3 Code.

Summary by CodeRabbit

  • New Features
    • Added support for displaying the ChatGPT Pro 25x subscription plan.
    • Improved compatibility with account notifications containing new or unrecognized plan types.

Codex 0.159 reports ChatGPT Pro 500 accounts as planType "promax". Our
generated protocol decoded plan types as a closed enum, so account/read
failed to decode and the provider showed as unavailable.

Generate PlanType as an open string, matching how Codex itself reads plans
it does not know, and label promax as ChatGPT Pro 500.
@github-actions github-actions Bot added vouch:unvouched PR author is not yet trusted in the VOUCHED list. size:L 100-499 changed lines (additions + deletions). labels Sep 29, 2026
@macroscopeapp

macroscopeapp Bot commented Sep 29, 2026

Copy link
Copy Markdown
Contributor

Approvability

Verdict: Approved at 8d1a89d

Macroscope's review found this PR approvable — This is a narrow Codex compatibility fix that prevents newly introduced plan identifiers from invalidating account and usage notifications, while preserving existing behavior and adding targeted coverage. The generated schema widening is backward-compatible and the only user-facing addition is the label for the Pro 500 plan.

You can add or adjust custom eligibility rules. Learn more.

Comment thread apps/server/src/provider/Layers/CodexProvider.ts Outdated
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository: pingdotgg/t3code/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: cc00308c-44de-4380-8c51-63535afb5d46

📥 Commits

Reviewing files that changed from the base of the PR and between 8d1a89d and 12ee826.

📒 Files selected for processing (1)
  • apps/server/src/provider/Layers/CodexProvider.ts
🚧 Files skipped from review as they are similar to previous changes (1)
  • apps/server/src/provider/Layers/CodexProvider.ts

Included review availability: This review used your included allowance. Your plan provides up to 10 included reviews per hour; 8 remain after this review.


📝 Walkthrough

Walkthrough

The schema generator accepts plan values as strings. Tests cover promax and an arbitrary future value in account notification schemas. The provider maps promax to “ChatGPT Pro 25x Subscription.”

Changes

Codex plan type handling

Layer / File(s) Summary
Accept plan values in schemas
packages/effect-codex-app-server/scripts/generate.ts, packages/effect-codex-app-server/src/schema.test.ts
The generator overrides PlanType with a string schema. Tests verify that account-updated and rate-limit-updated notification schemas accept promax and an arbitrary future plan value.
Label the promax plan
apps/server/src/provider/Layers/CodexProvider.ts
codexPlanLabel maps promax to “ChatGPT Pro 25x Subscription.”

Priority: ➖ Normal

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Bug fix

Merge Risk: ⚪ Minimal · up to 12ee8

No actionable issue was established with the new plan label. The change is mergeable after normal checks.

Security Architecture Review

Security architecture risk: 🔵 Low · up to 8d1a8

The compatibility change restores access for accounts with new plan names. Inspected consumers use plan values for labels and usage information, not to grant permissions. Downstream integrations and deployment behavior remain unverified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The newly accepted value can reach account and rate-limit processing in the Codex integration. Evidence does not establish exposure beyond the inspected server and shared package.

Trust Boundaries and Controls

  • inferred — The inspected paths do not use an unknown plan name to select models or grant account access: account presence governs provider authentication state, model availability comes from model/list, and unknown names do not acquire a display label.

Resilience and Maintainability Implications

  • observed — Accepted rate-limit notifications enter the existing session event stream and sparse merge. Its in-memory lifecycle and lack of a sequence check predate this schema change; restart recovery outside the inspected path is unverified.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 3 files.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
Title check ✅ Passed The title clearly identifies the primary fix: preventing Pro 500 accounts from breaking the Codex provider.
Description check ✅ Passed The description clearly explains the problem, implementation, user impact, UI changes, and validation. It does not use the template headings or checklist format, but it provides the required informati…
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create a new PR

Comment @coderabbitai help to get the list of available commands.

@juliusmarminge

Copy link
Copy Markdown
Member

Superseded by #14304 (same fix: open PlanType string so promax/Pro Max accounts decode on account/read).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:L 100-499 changed lines (additions + deletions). vouch:unvouched PR author is not yet trusted in the VOUCHED list.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants