2026/10/9 22:10:10

Codex 服务器端使用指南:ChatGPT 登录缓存迁移到 TaoToken 的 auth.json 配置

Codex 服务器端使用指南:ChatGPT 登录缓存迁移到 TaoToken 的 auth.json 配置 1. 服务器端 Codex 登录缓存迁移到底在解决什么问题如果你在服务器上跑 Codex CLI大概率遇到过这个场景本地 Windows 用 ChatGPT 账号登录 Codex 一切正常但一上服务器就卡住——要么codex login --device-auth报 403要么用 API key 登录后直接甩你一句Quota exceeded。这不是 Codex 装错了也不是服务器网络彻底不通而是登录体系选错了。先把概念理清楚。ChatGPT 订阅和 OpenAI Platform API 是两套完全独立的计费体系。你用 API key 登录 Codex走的是 Platform API 的额度池账户里没有 API credits 或者项目限额不足就会报 Quota exceeded。而 ChatGPT Plus/Pro 的订阅额度不会自动映射到 API key 上。所以服务器端最稳的方案不是去买 API token而是把本地已经用 ChatGPT 登录好的凭据缓存auth.json迁移过去。auth.json是什么它是 Codex CLI 登录后落盘的凭据文件里面包含auth_mode、access token、refresh token 等字段。当auth_mode为chatgpt时Codex 走的是 ChatGPT 登录体系token 通常可以自动刷新。官方文档也说明缓存可能位于~/.codex/auth.json或系统凭据存储通过cli_auth_credentials_store file可以强制写到文件。这套方案适合谁适合在 Linux 服务器、跳板机、CI 环境里用 Codex 做代码助手但服务器没有浏览器、device-auth 又被拦住的开发者。核心动作就三步本地生成 auth.json、scp 复制到服务器、验证登录态。下面我把每一步拆到可复制。需要特别提醒auth.json等同于登录凭据不要发给任何人、不要截图、不要提交到 Git、不要放进项目目录只存放在可信机器的~/.codex/auth.json。2. TaoToken 前置准备Base URL、Key 与 Model ID 三件套在正式迁移之前先把 TaoToken 这一侧的前置准备好。TaoToken 提供统一的模型接入入口官网是 https://taotoken.net/?utm_sourcetaotoken_aicg_blog_endutm_mediumcsdnutm_campaignrewriteutm_content API 端点是 https://taotoken.net/api 。你需要拿到三样东西Base URL、API Key、Model ID。这三件套在后面的auth.json改写和config.toml配置里都会用到。先到控制台创建 API Key入口在 https://taotoken.net/console?utm_sourcetaotoken_aicg_blog_endutm_contentconsoleutm_campaignrewrite Key 管理页在 https://taotoken.net/api-keys?utm_sourcetaotoken_aicg_blog_endutm_contentapi-keysutm_campaignrewrite 。创建后立刻复制保存页面刷新后通常不再完整显示。Model ID 可以在模型对话页确认地址是 https://taotoken.net/models?utm_sourcetaotoken_aicg_blog_endutm_contentmodelsutm_campaignrewrite 选一个你常用的编码模型记下它的 ID。为什么要在迁移 auth.json 之前先准备这些因为服务器端 Codex 的稳定运行实际上依赖两个层面的配置一层是登录态auth.json 决定走 ChatGPT 还是 API另一层是请求出口Base URL 和 Key 决定请求发到哪里。如果你只迁移了 ChatGPT 登录缓存但服务器网络到官方端点不稳定Codex 依然会卡在请求阶段。把 TaoToken 作为统一出口可以让 Base URL、Key、Model ID 集中管理迁移和排障都更清晰。这里给一个对照表方便你确认三件套的取值位置配置项取值来源典型写法Base URLTaoToken API 端点https://taotoken.net/apiAPI Key控制台 api-keys 页sk- 开头的字符串Model ID模型对话页确认例如 claude-sonnet 系列 ID如果你后续要做长期编码或 Agent 任务可以了解 Coding Plan入口在 https://taotoken.net/coding-plan?utm_sourcetaotoken_aicg_blog_endutm_contentcoding-planutm_campaignrewrite 。接入文档在 https://taotoken.net/doc?utm_sourcetaotoken_aicg_blog_endutm_contentdocutm_campaignrewrite 遇到字段不确定时优先查文档。3. 可复制配置auth.json 字段模板与 config.toml 改写这一节是全文的核心给出可直接复制的配置片段。先看本地 Windows 侧你需要让 Codex 把凭据写到文件而不是系统凭据存储。打开%USERPROFILE%\.codex\config.toml写入# 本地 Windows: %USERPROFILE%\.codex\config.toml cli_auth_credentials_store file保存后执行codex.cmd login用 ChatGPT 账号完成浏览器登录。登录成功后%USERPROFILE%\.codex\auth.json会生成。它的结构大致如下字段值已脱敏仅作模板参考{ auth_mode: chatgpt, tokens: { access_token: your-access-token, refresh_token: your-refresh-token, account_id: your-account-id }, last_refresh: 2026-05-07T00:00:00Z }关键字段是auth_mode它必须是chatgpt。如果这里是apikey说明你之前用 API key 登录过需要先codex logout再重新用 ChatGPT 登录。接下来是服务器侧的~/.codex/config.toml。如果你希望服务器端 Codex 通过 TaoToken 统一出口请求模型可以这样写# 服务器: ~/.codex/config.toml cli_auth_credentials_store file [model_providers.taotoken] name TaoToken base_url https://taotoken.net/api env_key TAOTOKEN_API_KEY [profiles.default] model_provider taotoken model your-model-id注意env_key指向的是环境变量名真正的 Key 通过环境变量注入不要硬编码进配置文件。服务器上执行export TAOTOKEN_API_KEYsk-你的Key这样 Base URL、Key、Model ID 三件套就齐了Base URL 在base_urlKey 在环境变量Model ID 在model。如果你用的是 Codex 的auth.json走 ChatGPT 登录态那么auth_mode保持chatgpt如果你希望走 TaoToken 的 API 计费则把auth_mode相关逻辑交给 provider 配置处理两者不要混用同一个 Key。迁移前后对照可以这样理解迁移前服务器~/.codex/auth.json不存在或auth_mode为apikey请求走 Platform API容易 Quota exceeded迁移后auth.json来自本地 ChatGPT 登录auth_mode为chatgpt同时config.toml里配好 TaoToken provider请求出口稳定。复制文件时用 scp注意端口参数是大写-Pscp -P 1222 $env:USERPROFILE\.codex\auth.json usernameserver_ip:~/.codex/auth.json服务器上立刻收紧权限chmod 700 ~/.codex chmod 600 ~/.codex/auth.json4. 验证请求curl 检查登录态与出口是否生效配置写完不代表生效必须验证。验证分两层先验证网络出口再验证 Codex 登录态。第一层检查服务器到 TaoToken 端点的连通性。执行curl -I https://taotoken.net/api正常应返回 HTTP 状态码如 200 或 401。401 是正常的说明网络通但没带 Key。如果返回Connection timed out说明服务器出口有问题需要检查代理或网络策略。第二层带上 Key 发一个真实请求确认 Key 和 Model ID 可用curl https://taotoken.net/api/v1/chat/completions \ -H Authorization: Bearer $TAOTOKEN_API_KEY \ -H Content-Type: application/json \ -d { model: your-model-id, messages: [{role: user, content: ping}] }如果返回包含choices字段的 JSON说明 Base URL、Key、Model ID 三件套全部生效。如果报 401检查 Key 是否复制完整如果报 model not found回到模型对话页确认 Model ID 拼写。第三层验证 Codex 登录态。服务器上执行conda activate codex-node unset OPENAI_API_KEY unset CODEX_API_KEY codex login status期望输出是Logged in using ChatGPT。同时用 Python 读一下 auth.json 的 auth_modepython -c import json, os; print(json.load(open(os.path.expanduser(~/.codex/auth.json))).get(auth_mode))输出chatgpt即正确。如果输出apikey或报文件不存在回到第 3 节检查 config.toml 和登录流程。最后启动 Codex 做一次真实交互codex --sandbox workspace-write --ask-for-approval on-request进入交互界面后输入一个只读任务比如让它读取 README 并总结确认不再出现 Quota exceeded。到这里登录缓存迁移和出口配置就都验证通过了。5. 本篇常见报错排查401、local proxy failed、reading choices、OAuth迁移过程中最容易撞上的几类报错这里逐一对照。401 Unauthorizedcurl 请求 TaoToken 返回 401通常是 Key 没带、Key 复制不全、或者环境变量没 export 成功。检查echo $TAOTOKEN_API_KEY是否有值注意不要有多余空格或换行。如果 Codex 侧报 401检查auth.json的auth_mode是否为chatgpt以及是否残留了OPENAI_API_KEY。local proxy failed / connection refused这类报错说明服务器本地代理端口不通。先确认代理进程在监听再确认HTTP_PROXY、HTTPS_PROXY、ALL_PROXY以及对应小写变量都设置了。大小写都要设因为 Node 和 Codex 在不同环节读取的变量名可能不同。设置后重新curl -I https://taotoken.net/api验证。reading choices / choices 字段缺失请求返回了 JSON 但没有choices常见原因是 Model ID 写错或者请求体格式不对。回到模型对话页核对 Model ID确认messages数组格式正确。如果返回的是错误对象先看error.message字段。OAuth / device-auth 403服务器上执行codex login --device-auth报 403 或error sending request for https://auth.openai.com/...说明服务器侧 OAuth 链路不可用。不要硬试直接改用本地生成 auth.json 再复制的方式这正是本篇方案要解决的场景。auth.json 权限或路径错误如果codex login status显示 Not logged in检查~/.codex/auth.json是否存在、权限是否为 600、auth_mode是否为chatgpt。路径必须是当前用户的 home 目录下不要放到项目目录里。Codex 仍走 API 计费如果迁移后仍报 Quota exceeded说明环境里还有 API key 残留。执行unset OPENAI_API_KEY和unset CODEX_API_KEY并检查~/.bashrc里是否写死了 Key有的话删掉。排查时记住一个原则先确认网络出口curl TaoToken再确认登录态codex login status最后确认模型配置Model ID。三层逐层排除比盲目重装高效得多。6. 稳定使用建议与接入入口迁移完成后日常使用有几个习惯能帮你少踩坑。第一auth.json只放在可信机器的~/.codex/下权限 600永远不要提交到 Git 或放进项目目录。第二服务器启动 Codex 前先unset OPENAI_API_KEY和CODEX_API_KEY避免登录态被 API key 覆盖。第三用--sandbox workspace-write --ask-for-approval on-request而不是全权限模式让敏感操作需要审批。第四第一次让 Codex 处理项目时先给只读任务比如让它读 README 和主要脚本、列出修改计划确认后再让它动文件。如果你需要长期在服务器上做编码或 Agent 任务建议把 Base URL、Key、Model ID 三件套固定到config.toml和环境变量里配合 Coding Plan 使用入口在 https://taotoken.net/coding-plan?utm_sourcetaotoken_aicg_blog_endutm_contentcoding-planutm_campaignrewrite 。需要新建或轮换 Key 时到 https://taotoken.net/api-keys?utm_sourcetaotoken_aicg_blog_endutm_contentapi-keysutm_campaignrewrite 。字段不确定时查接入文档 https://taotoken.net/doc?utm_sourcetaotoken_aicg_blog_endutm_contentdocutm_campaignrewrite 想先验证模型效果可以到模型对话页 https://taotoken.net/models?utm_sourcetaotoken_aicg_blog_endutm_contentmodelsutm_campaignrewrite 试跑。最后给一个日常启动脚本模板把激活环境、设置出口、清理 API key、启动 Codex 串起来#!/usr/bin/env bash source ~/miniconda3/etc/profile.d/conda.sh 2/dev/null || source ~/anaconda3/etc/profile.d/conda.sh conda activate codex-node cd ~/your_project export TAOTOKEN_API_KEYsk-你的Key export HTTP_PROXYhttp://127.0.0.1:2333 export HTTPS_PROXYhttp://127.0.0.1:2333 export ALL_PROXYhttp://127.0.0.1:2333 export http_proxyhttp://127.0.0.1:2333 export https_proxyhttp://127.0.0.1:2333 export all_proxyhttp://127.0.0.1:2333 unset OPENAI_API_KEY unset CODEX_API_KEY codex --sandbox workspace-write --ask-for-approval on-request保存为~/start_codex.sh并chmod x以后每次开服务器只要bash ~/start_codex.sh。脚本里的代理地址和端口按你服务器实际情况替换Key 建议从更安全的地方读取而不是明文写在脚本里。跑起来后先用只读任务验证一次确认codex login status是Logged in using ChatGPT再进入正式编码。