{"_id":"@brantes/codex-get-auth-conf","_rev":"4-32232d3b8950f9586677367baf006871","name":"@brantes/codex-get-auth-conf","dist-tags":{"latest":"1.0.2"},"versions":{"1.0.0":{"name":"@brantes/codex-get-auth-conf","version":"1.0.0","keywords":["openai","codex","auth","cli","automation"],"author":{"name":"Pedro Brantes"},"license":"MIT","_id":"@brantes/codex-get-auth-conf@1.0.0","maintainers":[{"name":"brantes","email":"pedroherrique222@gmail.com"}],"homepage":"https://github.com/pedrobrantes/codex-get-auth-conf#readme","bugs":{"url":"https://github.com/pedrobrantes/codex-get-auth-conf/issues"},"bin":{"getcodexauth":"dist/run.js"},"dist":{"shasum":"d395c0c07d684d5dedc3564db76e37af1cbcc060","tarball":"https://registry.npmjs.org/@brantes/codex-get-auth-conf/-/codex-get-auth-conf-1.0.0.tgz","fileCount":4,"integrity":"sha512-83cHzOJAGSOtoiSZpfNujZu5Rpmjq6ZNsK/5eywkIMr335hBlT1gDV2AFFSF+YpXiRxyaas7LVPdnI07OI7KoQ==","signatures":[{"sig":"MEQCIFAhsRwwr4s7XdEAM3HgVznZLLsB3CJjZwk+sAUKENhHAiBFXzhwk+KogYUR6wjIN+b2F8UKsok9o8Ua0xTNTi6M5g==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":29240},"main":"dist/run.ts","gitHead":"cf5139435ab762fd81ff55562ae226427f1c7856","private":false,"scripts":{"build":"tsc","start":"ts-node run.ts"},"_npmUser":{"name":"brantes","actor":{"name":"brantes","type":"user","email":"pedroherrique222@gmail.com"},"email":"pedroherrique222@gmail.com"},"repository":{"url":"git+https://github.com/pedrobrantes/codex-get-auth-conf.git","type":"git"},"_npmVersion":"10.9.2","description":"A standalone script to obtain an auth.json to OpenAI codex-cli","directories":{},"_nodeVersion":"22.16.0","dependencies":{"ink":"^3.2.0","open":"8.4.2","chalk":"4.1.2","react":"^17.0.2","express":"^4.18.2"},"_hasShrinkwrap":false,"devDependencies":{"ts-node":"^10.9.2","typescript":"^5.3.3","@types/node":"^20.11.24","@types/react":"^17.0.0","@types/express":"^4.17.17"},"_npmOperationalInternal":{"tmp":"tmp/codex-get-auth-conf_1.0.0_1751581827641_0.4856736058584348","host":"s3://npm-registry-packages-npm-production"}},"1.0.2":{"name":"@brantes/codex-get-auth-conf","version":"1.0.2","description":"A standalone script to obtain an auth.json to OpenAI codex-cli","private":false,"main":"dist/run.ts","bin":{"getcodexauth":"dist/run.js"},"scripts":{"start":"ts-node run.ts","build":"tsc && chmod +x dist/run.js"},"repository":{"type":"git","url":"git+https://github.com/pedrobrantes/codex-get-auth-conf.git"},"keywords":["openai","codex","auth","cli","automation"],"author":{"name":"Pedro Brantes"},"license":"MIT","dependencies":{"chalk":"4.1.2","express":"^4.18.2","ink":"^3.2.0","open":"8.4.2","react":"^17.0.2"},"devDependencies":{"@types/express":"^4.17.17","@types/node":"^20.11.24","@types/react":"^17.0.0","ts-node":"^10.9.2","typescript":"^5.3.3"},"_id":"@brantes/codex-get-auth-conf@1.0.2","gitHead":"49edfc383d854622477db2c09bb58a2b1f5d7969","bugs":{"url":"https://github.com/pedrobrantes/codex-get-auth-conf/issues"},"homepage":"https://github.com/pedrobrantes/codex-get-auth-conf#readme","_nodeVersion":"22.16.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-ABS9gJsjyOdE3FHGCKPw0ZlP34RGAt2QWdd1gLbFZkh60dveNPf6uRW5Wuo6I4NRWdBUtNnahd2ofJB9vydIow==","shasum":"9f20d3b3f4ef6f82ce3930e8dbc81371df65f2c7","tarball":"https://registry.npmjs.org/@brantes/codex-get-auth-conf/-/codex-get-auth-conf-1.0.2.tgz","fileCount":4,"unpackedSize":29713,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEDcMPib9ZZrJFImZu6N2vMang48q5faa4meWIWFTZ6CAiEA/rNBOSw3C+Fu6UbWPX8f/Mlip+0jCOVyxTPTrSErVVM="}]},"_npmUser":{"name":"brantes","email":"pedroherrique222@gmail.com","actor":{"name":"brantes","email":"pedroherrique222@gmail.com","type":"user"}},"directories":{},"maintainers":[{"name":"brantes","email":"pedroherrique222@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/codex-get-auth-conf_1.0.2_1751584877218_0.5267802881765327"},"_hasShrinkwrap":false}},"time":{"created":"2025-07-03T22:30:27.543Z","modified":"2025-07-03T23:21:17.562Z","1.0.0":"2025-07-03T22:30:27.830Z","1.0.1":"2025-07-03T22:40:17.175Z","1.0.2":"2025-07-03T23:21:17.389Z"},"bugs":{"url":"https://github.com/pedrobrantes/codex-get-auth-conf/issues"},"author":{"name":"Pedro Brantes"},"license":"MIT","homepage":"https://github.com/pedrobrantes/codex-get-auth-conf#readme","keywords":["openai","codex","auth","cli","automation"],"repository":{"type":"git","url":"git+https://github.com/pedrobrantes/codex-get-auth-conf.git"},"description":"A standalone script to obtain an auth.json to OpenAI codex-cli","maintainers":[{"name":"brantes","email":"pedroherrique222@gmail.com"}],"readme":"# Codex Get Auth Conf (auth.json)\n\n![NPM Version](https://img.shields.io/npm/v/%40brantes%2Fcodex-get-auth-conf) ![NPM Downloads dw](https://img.shields.io/npm/dw/%40brantes%2Fcodex-get-auth-conf) ![GitHub License](https://img.shields.io/github/license/pedrobrantes/codex-get-auth-conf)\n\nA standalone Node.js script to programmatically obtain an OpenAI API key by replicating the authentiation flow of the `codex` CLI. This project is the result of a deep dive into reverse-engineering a real-world OAuth 2.0 PKCE authentication flow.\n\n## 🚀 Features\n\n-   **Automated Browser Login**: Initiates the OpenAI login flow directly in your default browser.\n-   **Secure OAuth 2.0 PKCE Flow**: Correctly implements the Proof Key for Code Exchange (PKCE) for secure authorization.\n-   **Local Callback Server**: Runs a temporary local server to handle the OAuth redirect and capture the authorization code.\n-   **Automatic Token Exchange**: Exchanges the temporary code for a final, long-lived API key.\n-   **Credential Storage**: Saves the obtained tokens and API key to `~/.codex/auth.json`, mimicking the official CLI's behavior.\n\n## 🤔 Why This Project Exists\n\nThis project began as an exploration to understand how modern CLI tools handle secure user authentication without asking the user to manually paste API keys. By reverse-engineering the `codex` CLI's login process, we can observe a complete, production-grade implementation of the OAuth 2.0 Authorization Code Grant with PKCE. It serves as a practical learning tool for anyone interested in API security and application authentication.\n\n## 📋 Prerequisites\n\n-   [Node.js](https://nodejs.org/) (v18.x or later recommended)\n-   [npm](https://www.npmjs.com/)\n\n## ⚙️ Installation & Usage\n\nRun with npx:\n\n```bash\nnpx @brantes/codex-get-auth-conf \n```\n---\n\nYou can install this tool globally via npm:\n\n```bash\nnpm install -g @brantes/codex-get-auth-conf\n```\n---\n\n1.  **Clone the repository:**\n    ```bash\n    git clone https://github.com/pedrobrantes/codex-get-auth-conf.git\n    ```\n\n2.  **Navigate to the project directory:**\n    ```bash\n    cd codex-get-auth-conf\n    ```\n\n3.  **Install the dependencies:**\n    ```bash\n    npm install\n    ```\n\n4.  **Run the script:**\n    ```bash\n    npm start\n    ```\n\nThe script will open a new tab in your browser. Log in with your OpenAI account. Upon success, the script will capture the credentials, save them, and print the new API key to the console.\n\n## 🛠️ How It Works\n\nThe script follows the standard OAuth 2.0 PKCE flow:\n\n1.  A local `express` server is started on `localhost:1455` to listen for the callback.\n2.  A cryptographic `code_verifier` and `code_challenge` are generated.\n3.  The user's browser is opened to the OpenAI authorization endpoint, passing the `client_id` and `code_challenge`.\n4.  After the user authenticates, OpenAI redirects them back to `http://localhost:1455/auth/callback` with a temporary `authorization_code`.\n5.  The local server receives this request, captures the code, and securely exchanges it (along with the original `code_verifier`) for the final API key by making a `POST` request to OpenAI's token endpoint.\n6.  The final API key and associated tokens are saved to `~/.codex/auth.json`.c\n","readmeFilename":"README.md"}