{"id":48903951,"url":"https://github.com/minanagehsalalma/codex-multiaccount-patcher","last_synced_at":"2026-04-23T07:00:37.670Z","repository":{"id":351409200,"uuid":"1210842534","full_name":"minanagehsalalma/codex-multiaccount-patcher","owner":"minanagehsalalma","description":"Persistent multi-account patcher for Codex auth hot-reload across upstream releases.","archived":false,"fork":false,"pushed_at":"2026-04-16T18:09:47.000Z","size":171,"stargazers_count":1,"open_issues_count":0,"forks_count":1,"subscribers_count":0,"default_branch":"main","last_synced_at":"2026-04-16T18:37:20.270Z","etag":null,"topics":["cli","codex","linux","multiaccount","openai","patcher","windows"],"latest_commit_sha":null,"homepage":"https://github.com/minanagehsalalma/codex-multiaccount-patcher","language":"JavaScript","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/minanagehsalalma.png","metadata":{"files":{"readme":"README.md","changelog":"CHANGELOG.md","contributing":"CONTRIBUTING.md","funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null,"zenodo":null,"notice":null,"maintainers":null,"copyright":null,"agents":null,"dco":null,"cla":null}},"created_at":"2026-04-14T20:11:26.000Z","updated_at":"2026-04-16T18:33:30.000Z","dependencies_parsed_at":null,"dependency_job_id":null,"html_url":"https://github.com/minanagehsalalma/codex-multiaccount-patcher","commit_stats":null,"previous_names":["minanagehsalalma/codex-hotpatch","minanagehsalalma/codex-multiaccount-patcher"],"tags_count":3,"template":false,"template_full_name":null,"purl":"pkg:github/minanagehsalalma/codex-multiaccount-patcher","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/minanagehsalalma%2Fcodex-multiaccount-patcher","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/minanagehsalalma%2Fcodex-multiaccount-patcher/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/minanagehsalalma%2Fcodex-multiaccount-patcher/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/minanagehsalalma%2Fcodex-multiaccount-patcher/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/minanagehsalalma","download_url":"https://codeload.github.com/minanagehsalalma/codex-multiaccount-patcher/tar.gz/refs/heads/main","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/minanagehsalalma%2Fcodex-multiaccount-patcher/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32169657,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-23T02:19:40.750Z","status":"ssl_error","status_checked_at":"2026-04-23T02:17:55.737Z","response_time":53,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["cli","codex","linux","multiaccount","openai","patcher","windows"],"created_at":"2026-04-16T18:06:00.724Z","updated_at":"2026-04-23T07:00:37.658Z","avatar_url":"https://github.com/minanagehsalalma.png","language":"JavaScript","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\n  \u003cp\u003e\n    \u003cimg width=\"240\" alt=\"Codex multiaccount patcher mascot\" src=\"https://github.com/user-attachments/assets/8ee532dc-9cf2-4e30-ae1c-02d4261c28a8\" /\u003e\n  \u003c/p\u003e\n  \u003ch1\u003ecodex-multiaccount-patcher\u003c/h1\u003e\n  \u003cp\u003e\u003cstrong\u003ePatch Codex once, keep account switching seamless across turns.\u003c/strong\u003e\u003c/p\u003e\n  \u003cp\u003e\n    \u003ca href=\"https://github.com/minanagehsalalma/codex-multiaccount-patcher/releases/latest\"\u003e\u003cimg alt=\"Latest Release\" src=\"https://img.shields.io/github/v/release/minanagehsalalma/codex-multiaccount-patcher?display_name=tag\u0026label=release\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://github.com/minanagehsalalma/codex-multiaccount-patcher/blob/main/LICENSE\"\u003e\u003cimg alt=\"License\" src=\"https://img.shields.io/badge/license-Apache--2.0-4b5563\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://nodejs.org/\"\u003e\u003cimg alt=\"Node 20+\" src=\"https://img.shields.io/badge/node-%3E%3D20-0f766e\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://github.com/minanagehsalalma/codex-multiaccount-patcher\"\u003e\u003cimg alt=\"Platforms\" src=\"https://img.shields.io/badge/platforms-windows%20%7C%20linux-1d4ed8\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://github.com/minanagehsalalma/codex-multiaccount-patcher/actions/workflows/publish-hotpatch.yml?query=branch%3Amain\"\u003e\u003cimg alt=\"Publish Hotpatch\" src=\"https://github.com/minanagehsalalma/codex-multiaccount-patcher/actions/workflows/publish-hotpatch.yml/badge.svg?branch=main\"\u003e\u003c/a\u003e\n    \u003ca href=\"https://github.com/minanagehsalalma/codex-multiaccount-patcher/actions/workflows/compatibility-sweep.yml?query=branch%3Amain\"\u003e\u003cimg alt=\"Compatibility Sweep\" src=\"https://github.com/minanagehsalalma/codex-multiaccount-patcher/actions/workflows/compatibility-sweep.yml/badge.svg?branch=main\"\u003e\u003c/a\u003e\n  \u003c/p\u003e\n\u003c/div\u003e\n\n`codex-multiaccount-patcher` is now a single toolkit: it keeps a patched `codex` binary in front of the upstream install and bundles the `codex-auth` account manager behind the same install. The point is still narrow and practical: switch accounts cleanly, auto-switch when thresholds are hit, and let Codex pick up auth changes between turns without making you rebuild locally or restart the CLI.\n\n## Why This Exists\n\nOpenAI Codex still behaves like a single-account CLI in practice. If you rotate between personal, work, or quota-spillover accounts, the official flow is still mostly `login`, overwrite auth state, and restart the session. This toolkit exists to close that gap with the smallest surface area possible:\n\n- keep upstream Codex installed normally\n- keep account state in the same `~/.codex` home Codex already uses\n- put a managed shim in front of `codex`\n- fail closed when the upstream binary hash is unknown instead of guessing\n\nThat is the whole bet. It is not trying to be a fork of Codex, a custom backend, or a traffic proxy.\n\n## Trust Model\n\n| Concern | This toolkit's contract |\n| --- | --- |\n| Credentials | It does not ask for your OpenAI password, proxy your prompts, or upload `auth.json` / `accounts/` anywhere. Auth switching works by managing the same local Codex auth files you already have under `~/.codex`. |\n| Filesystem writes | It writes only to `~/.codex-multiaccount` for shims, overlays, manifests, and state. It reads `~/.codex` because that is where Codex auth already lives. It does not patch the upstream vendor binary in place. |\n| Network access | Network use is narrow and explicit: fetch the configured manifest and download published overlays from GitHub Releases, or pull a newer toolkit package when you run `upgrade`. It does not sit in the middle of Codex API traffic. |\n| Updates | The managed runtime can refresh its manifest/overlay state automatically. The toolkit package does not silently self-update; users must reinstall, run `codex-multiaccount upgrade`, or `self-install` from a checkout. |\n| Breakage | Overlay selection is hash-matched. If the installed upstream Codex binary is unknown, launch fails closed instead of trying a near match. |\n| Reversibility | `codex-multiaccount uninstall` removes the managed runtime and restores normal `codex` launch behavior. Your upstream Codex install and `~/.codex` auth data stay yours. |\n\n## Before You Install\n\nThis project is meant for people who are comfortable auditing what a CLI touches on their own machine. If that is not you, wait for a better official multi-account workflow in Codex itself.\n\nIf it is you, the important facts are simple:\n\n- it does not modify upstream Codex in place\n- it does not invent a custom auth store\n- it does not silently apply overlays for unknown upstream binaries\n- it does not hide uninstall behind manual cleanup\n- it is easiest to reason about on a personal machine, not a shared workstation\n\n## Compared To Other Approaches\n\nThe main alternatives today are still auth-file switchers, small wrapper scripts, or profile managers that sit next to stock Codex. They solve part of the problem. This project is aimed at the full \"switch accounts and keep the Codex runtime in sync\" problem.\n\n| Approach | Auth switching | Auto-switch | Runtime hot-reload fix | Cross-platform | Health check / fail-closed |\n| --- | --- | --- | --- | --- | --- |\n| Manual `auth.json` swapping | ✅ | ❌ | ❌ | ✅ | ❌ |\n| [`codex-auth`](https://github.com/Loongphy/codex-auth) | ✅ | ✅ | ❌ | ✅ | ❌ |\n| Simple switcher scripts | ✅ | ❌ | ❌ | ❌ | ❌ |\n| Profile managers / wrappers | ✅ | sometimes | ❌ | sometimes | ❌ |\n| `codex-multiaccount-patcher` | ✅ | ✅ | ✅ | ✅ | ✅ |\n\nIf you only want to swap auth snapshots manually, lighter tools are fine. If you want the auth manager and patched Codex runtime to stay aligned under one install, this is the stronger model.\n\n## Flight Path\n\n```mermaid\nflowchart TD\n    A[Installed upstream codex] --\u003e B[patcher-owned shim]\n    B --\u003e C[hash upstream binary]\n    C --\u003e D{matching overlay in manifest?}\n    D --\u003e|yes| E[reuse cached overlay]\n    D --\u003e|no| F[fail closed]\n    E --\u003e G[launch patched codex]\n    G --\u003e H[reload auth snapshot between turns]\n    H --\u003e I[switch accounts without restarting]\n```\n\nThat is the whole shape of the project: discover the real upstream binary, match it by exact hash, hydrate the right overlay, then launch the patched executable through a shim the patcher controls.\n\n## Quickstart\n\n1. Install Codex normally first. The toolkit expects an existing global `@openai/codex` install.\n2. Install the toolkit itself:\n\n```bash\nnpm install -g github:minanagehsalalma/codex-multiaccount-patcher\n```\n\n3. Install the managed Codex shims and pull the latest validated manifest:\n\n```bash\ncodex-multiaccount install\n```\n\n4. Check the patched Codex runtime:\n\n```bash\ncodex-multiaccount status\ncodex-multiaccount doctor\n```\n\n5. Check the bundled auth toolkit:\n\n```bash\ncodex-multiaccount auth status\ncodex-multiaccount auth list\n```\n\n6. Enable auto-switch if you want the patcher and auth manager to work together hands-free:\n\n```bash\ncodex-multiaccount config auto enable\ncodex-multiaccount config auto --5h 10 --weekly 1\n```\n\nIf `auth status` already shows `auto-switch: ON`, leave it as-is. After that, plain `codex` should route through the managed shim automatically and keep picking up auth changes between turns. `codex-auth` is also installed as a compatibility alias, and the legacy alias `codex-hotpatch` still works during the transition.\n\n7. Refresh the toolkit when a new published build lands:\n\n```bash\ncodex-multiaccount upgrade\n```\n\nMaintainers working from a local checkout can refresh the global install from that checkout instead:\n\n```bash\ncodex-multiaccount self-install\n```\n\nPublished installs do not auto-refresh every time the repo changes. The toolkit upgrades the managed Codex runtime automatically, but the toolkit package itself only changes when you reinstall or run `upgrade`.\n\n## Toolkit Home\n\nThe toolkit has two runtime roots:\n\n- `~/.codex-multiaccount`\n  This is the toolkit-managed home for shims, overlays, manifests, and patch runtime state.\n- `~/.codex`\n  This remains the upstream Codex home, and it is still the live source of truth for `auth.json`, `accounts/`, session rollouts, and the auth registry that `codex-auth` manages.\n\n`codex-multiaccount doctor` checks both homes together so users do not have to guess which side is broken.\n\nIf you are evaluating the tool skeptically, `doctor` is the first command to run after install because it shows both the patch runtime and auth runtime in one place, including whether auto-switch is actually enabled.\n\n## What Happens When You Type `codex`\n\n```mermaid\nsequenceDiagram\n    participant You\n    participant Shim as codex shim\n    participant Patcher as codex-multiaccount\n    participant Manifest as active manifest\n    participant Cache as overlay cache\n    participant Patched as patched codex\n\n    You-\u003e\u003eShim: codex\n    Shim-\u003e\u003ePatcher: launch -- [args]\n    Patcher-\u003e\u003ePatcher: discover upstream binary + sha256\n    Patcher-\u003e\u003eManifest: find exact platform/hash match\n    Manifest--\u003e\u003ePatcher: overlay record\n    Patcher-\u003e\u003eCache: ensure overlay exists locally\n    Cache--\u003e\u003ePatcher: managed overlay path\n    Patcher-\u003e\u003ePatched: exec patched binary\n    Patched--\u003e\u003eYou: same Codex CLI, fixed auth reload behavior\n```\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eWhat install writes to the machine\u003c/strong\u003e\u003c/summary\u003e\n\nThe patcher creates a managed home at `~/.codex-multiaccount`, stores overlay binaries under `overlays/`, writes the active manifest under `manifests/`, and places shims under `bin/`. It does not mutate the vendor Codex binary in place.\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eWhy updates survive better than direct patching\u003c/strong\u003e\u003c/summary\u003e\n\nWhen upstream Codex changes, the patcher hashes the new binary on the next launch and looks for a matching published overlay. If one exists, it switches cleanly. If one does not, it fails closed instead of silently launching a stale or mismatched binary.\n\n\u003c/details\u003e\n\n\u003cdetails\u003e\n\u003csummary\u003e\u003cstrong\u003eWhy the release pipeline matters\u003c/strong\u003e\u003c/summary\u003e\n\nThe runtime stays simple because the heavy work moves to CI: apply the maintained patch program, run the two focused regressions, build the overlays, generate the manifest, and only then publish a release that the CLI can consume.\n\n\u003c/details\u003e\n\n## Release Pulse\n\n```mermaid\nflowchart LR\n    A[detect upstream release] --\u003e B[apply maintained patch program]\n    B --\u003e C[run focused regressions]\n    C --\u003e D[build Windows and Linux overlays]\n    D --\u003e E[generate manifest slices]\n    E --\u003e F[validate release URLs]\n    F --\u003e G[publish release]\n```\n\nThe automation is designed to stop before publishing when the patch program drifts, a regression breaks, or the manifest points at the wrong repo/tag. That last check exists specifically to prevent the kind of release cleanup that makes a public release page look sloppy.\n\n## Unattended Maintenance Loop\n\n```mermaid\nflowchart LR\n    A[scheduled auto-maintain-upstream] --\u003e B{release tag already exists?}\n    B --\u003e|yes| C[skip build and close tracked issue]\n    B --\u003e|no| D[call publish-hotpatch]\n    D --\u003e E{publish succeeded?}\n    E --\u003e|yes| F[release manifest and overlays]\n    F --\u003e G[close tracked issue]\n    E --\u003e|no| H[open or update tracked failure issue]\n    H --\u003e I[optionally assign Copilot cloud agent]\n```\n\nThe green path is now zero-touch: detect the latest upstream Codex release, skip work if the matching patch release already exists, otherwise run the existing publish pipeline and close any tracked failure issue after success. Human attention is only pulled in when the deterministic path fails closed.\n\n## Command Surface\n\n| Command | Purpose |\n| --- | --- |\n| `codex-multiaccount install [--overlay-path \u003cpath\u003e] [--manifest \u003cfile-or-url\u003e] [--path \u003cupstream-binary\u003e] [--force]` | Install shims, discover upstream Codex, and materialize the matching overlay |\n| `codex-multiaccount status` | Show upstream hash, active overlay, manifest source, and install health |\n| `codex-multiaccount doctor` | Check both the patch runtime and auth runtime in one report |\n| `codex-multiaccount upgrade` | Replace the global toolkit install with the latest published build from GitHub |\n| `codex-multiaccount self-install` | Pack the current checkout and install it globally as a self-contained package |\n| `codex-multiaccount repair` | Re-resolve the manifest and refresh the managed runtime |\n| `codex-multiaccount uninstall` | Remove the managed runtime and restore normal `codex` launch behavior |\n| `codex-multiaccount launch -- [codex args...]` | Internal entrypoint used by the managed shims |\n| `codex-multiaccount auth \u003ccodex-auth args...\u003e` | Run the bundled auth toolkit through the same install |\n| `codex-multiaccount list` | Convenience alias for `codex-multiaccount auth list` |\n| `codex-multiaccount login [--device-auth]` | Convenience alias for `codex-multiaccount auth login` |\n| `codex-multiaccount switch [\u003cquery\u003e]` | Convenience alias for `codex-multiaccount auth switch` |\n| `codex-multiaccount remove ...` | Convenience alias for `codex-multiaccount auth remove` |\n| `codex-multiaccount import ...` | Convenience alias for `codex-multiaccount auth import` |\n| `codex-multiaccount clean` | Convenience alias for `codex-multiaccount auth clean` |\n| `codex-multiaccount config ...` | Convenience alias for `codex-multiaccount auth config` |\n| `codex-auth ...` | Backward-compatible shim to the bundled auth toolkit |\n\nNormal users should usually need `install`, `status`, `doctor`, `auth status`, `auth list`, `config auto enable`, and `switch`.\n\n## Auth Toolkit\n\nThe bundled auth engine is the same native `codex-auth` toolchain, now shipped behind this package so users do not have to install and coordinate a second CLI manually.\n\nOn Windows, the toolkit now prefers a vendored snapshot of the known-good working `codex-auth` machine install before falling back to any other copy. Existing standalone installs still work as a secondary fallback, and fresh installs can still fall back to the npm-bundled auth engine when needed.\n\n```bash\ncodex-multiaccount auth status\ncodex-multiaccount auth list\ncodex-multiaccount switch work\ncodex-multiaccount config auto enable\ncodex-multiaccount config auto --5h 10 --weekly 1\n```\n\nThe compatibility alias still works too:\n\n```bash\ncodex-auth status\ncodex-auth list\n```\n\n## Maintained Patch Model\n\nThe repo no longer depends on hand-refreshing one giant patch for every Codex release. The durable part is a small patch program plus two regressions that prove the behavior still works.\n\n| Layer | Role |\n| --- | --- |\n| [src/lib/maintained-patch.js](src/lib/maintained-patch.js) | Applies the runtime rewrite logic |\n| [patches/codex-hot-reload-tests.patch](patches/codex-hot-reload-tests.patch) | Carries the smaller fallback test changes |\n| `current_client_setup_reloads_auth_from_disk_between_turns` | Proves auth state reloads between turns |\n| `responses_websocket_reconnects_when_auth_snapshot_changes_between_turns` | Proves websocket auth reconnects when the snapshot changes |\n\n## CI Strategy\n\nGitHub Actions stays the primary path because the repo already lives on GitHub and the workflow needs first-class Windows runners. The current setup optimizes for two lanes instead of one noisy everything-pipeline:\n\n- [publish-hotpatch.yml](.github/workflows/publish-hotpatch.yml) publishes validated overlays and `manifest.json`\n- [compatibility-sweep.yml](.github/workflows/compatibility-sweep.yml) pressure-tests multiple upstream versions without publishing\n\nThe compatibility sweep can run in `fast` mode for Linux-only validation or `full` mode for Linux plus Windows. The current baseline starts at Codex `0.119.0`, and the latest published validation snapshot is [Codex 0.121.0 validation](latest-validation-0.121.0.md).\n\nA deeper note on CI speed and unattended maintenance is in [docs/CI-STRATEGY.md](docs/CI-STRATEGY.md).\n\n## Maintainer Shortcuts\n\n```bash\nnpm test\nnpm run patch:check -- --upstream-root \u003cpath\u003e\nnpm run patch:apply -- --upstream-root \u003cpath\u003e\nnpm run manifest:validate -- --manifest \u003cpath\u003e --repo minanagehsalalma/codex-multiaccount-patcher --tag multiaccount-patcher-\u003cversion\u003e\nnpm run upstream:detect\nnpm run upstream:fetch -- --codex-version \u003cversion\u003e --platform \u003cplatform\u003e --arch \u003carch\u003e --output \u003cpath\u003e\nnpm run versions:matrix -- --count 5 --min-version 0.119.0 --target-set fast\n```\n\n## Reality Check\n\n| Topic | Current state |\n| --- | --- |\n| Windows x64 | Validated live end to end |\n| Linux x64 | Supported in release + compatibility CI, still worth a real publish-install pass on Linux |\n| Release automation | `auto-maintain-upstream` watches upstream Codex, skips already-published versions, and only opens a tracked issue when the deterministic path fails |\n| CI ownership | GitHub Actions is the only maintained automation surface |\n| Unsupported upstream builds | Launch fails closed until CI publishes a matching overlay |\n\n## Acknowledgements\n\n- [openai/codex](https://github.com/openai/codex) for the upstream Codex CLI this toolkit layers on top of\n- [loongphy/codex-auth](https://github.com/loongphy/codex-auth) for the auth management toolchain this project integrates and ships behind the unified CLI\n\nTrust files: [LICENSE](LICENSE), [CONTRIBUTING.md](CONTRIBUTING.md), [SECURITY.md](SECURITY.md), [CHANGELOG.md](CHANGELOG.md).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fminanagehsalalma%2Fcodex-multiaccount-patcher","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fminanagehsalalma%2Fcodex-multiaccount-patcher","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fminanagehsalalma%2Fcodex-multiaccount-patcher/lists"}