SSD Nodes Learn Hosting plans →
Guides Matt ConnorBy Matt Connor

Can Codex use your ChatGPT subscription?

Yes. Codex CLI signs in with your ChatGPT Plus or Pro plan and no API key. Here is what the plan covers, and why the unofficial bridge tools keep breaking.

Yes, Codex uses your ChatGPT subscription

Codex can use your ChatGPT subscription, and that is the supported way to run it. Run codex login, finish the browser step, and the CLI charges your ChatGPT plan instead of an API key. As of September 2026 the plans that include Codex are Plus, Pro, Business, Edu and Enterprise. Free and Go do not include it, so on those two plans the CLI needs an API key.

npm install -g @openai/codex
codex login
codex login status

codex login status reports which account the CLI is holding and which auth method it will use. On macOS you can install the same binary with brew install --cask codex. If the status output names an API key when you wanted the subscription, run codex logout and log in again.

So the short answer is yes, for Codex. The question usually arrives from the other direction: you installed some other agent, it demanded a key starting with sk-, and you want to know why the plan you already pay for is not enough. That has a real mechanism behind it, and it is worth understanding before you go looking for a workaround.

Why a coding agent asks for a separate API key

A ChatGPT plan and the OpenAI API are two products with two billing systems. The plan is a seat on a consumer service. The API is a metered service with its own balance under platform.openai.com. They do not share a wallet, and they do not share a credential.

What codex login stores is not an API key. It is an OAuth (open authorization) token, written to ~/.codex/auth.json, issued to OpenAI's own client software. First-party clients accept it: the CLI and the IDE extension. api.openai.com does not accept it as a bearer key. So a third-party agent that speaks the OpenAI API has nothing it can send on your behalf, which is why tools like Cline and aider ask for an API key. It is the only credential the public API will take.

This split is not specific to OpenAI. The same subscription login versus API key decision in Claude Code works the same way for the same reason, and comparing the major coding agents on how they bill largely comes down to whether the vendor ships a CLI of its own.

What the ChatGPT plan actually covers

ChartChatGPT plan list price per month in USD, September 2026
The data behind this chart
[
  {
    "plan": "Free",
    "usd_per_month": 0,
    "codex_cli": "no"
  },
  {
    "plan": "Go",
    "usd_per_month": 8,
    "codex_cli": "no"
  },
  {
    "plan": "Plus",
    "usd_per_month": 20,
    "codex_cli": "yes"
  },
  {
    "plan": "Pro",
    "usd_per_month": 100,
    "codex_cli": "yes"
  },
  {
    "plan": "Business",
    "usd_per_month": 25,
    "codex_cli": "yes"
  }
]

Those are published list prices as of September 2026, for the 5 individual and small-team plans. The Business figure is per user on monthly billing, and it is lower on annual billing. Plus costs 20 dollars a month, and Pro starts at 100 with a higher Pro tier available for larger limits. Read the pricing page before you buy, because these numbers move.

Subscription usage is metered on a rolling five-hour window, with a weekly cap over the top of it. Inside a Codex session, /status prints how much of each window is left and when each one resets. Run it before you start a long refactor, because the five-hour window is the one that ends a working session early.

One detail catches people out. Local CLI sessions and cloud Codex tasks draw on the same plan allowance, and so does ordinary chat in the app. A heavy afternoon in the terminal leaves less for everything else that day. On Plus and Pro you can buy extra credits when you reach the cap instead of moving up a plan.

A bridge is a small local server. It signs into the consumer web product using your account, then exposes an endpoint shaped like /v1/chat/completions on localhost. You point your agent at that address, the agent believes it is talking to the API, and the bridge replays the browser session's own requests underneath. Some variants skip the browser and call an internal endpoint directly, which is the same idea with fewer moving parts.

Automating a consumer web session this way is against OpenAI's terms of use, and the account it can cost you is your own. This guide does not cover installing these tools, handling session credentials, extracting cookies, or any other step involved in making one work.

The engineering problem is separate from the terms problem, and it is just as decisive. The interface a bridge imitates is internal. Nothing promises it will stay the same, so it does not. A field gets renamed, an integrity check is added, the streaming format changes, and every bridge built on top starts returning 401 or 403 until a maintainer patches it. That is why a recipe from a blog post six weeks old fails today. The shelf life of a working bridge is measured in weeks, and the break lands in the middle of work you were doing. You are maintaining an unpaid integration against a target that has no reason to hold still.

Route 1: the subscription login the vendor ships

When the vendor ships its own CLI, this is the cheapest supported route, because you already pay for it. For Codex that is codex login. Two situations need more than the bare command.

On a server with no browser, use device code login:

codex login --device-auth

That prints a code you type into a browser on your laptop. The alternative is to forward the callback port over SSH and run the normal flow on the server:

ssh -L 1455:localhost:1455 user@remote
codex login

You can also copy ~/.codex/auth.json from a machine that is already signed in. Treat that file like a password, because it holds live access tokens. Mode 600, owned by the user that runs the agent, and never inside a git repository or a synced folder.

If a machine keeps picking the wrong credential, pin it in ~/.codex/config.toml:

forced_login_method = "chatgpt"

Set it to "api" for the opposite behaviour. Pinning is worth doing on a shared box where OPENAI_API_KEY is exported for some other tool, so a plain codex run cannot end up billing the metered API when you meant to spend plan allowance.

Route 2: an API key with a hard spend cap

An API key buys two things the plan does not: no weekly window, and a credential every agent accepts. It also charges per token, so an agent stuck in a retry loop spends real money at machine speed. Cap it before you paste the key anywhere.

The only cap that cannot be argued with is a prepaid balance with auto recharge turned off. You cannot spend credits you do not have. Load twenty dollars, leave auto recharge off, and your worst case is twenty dollars. Layer the platform's monthly budget and its spend alerts on top of that, and read the budget as an alarm rather than a guaranteed stop: notification thresholds and hard enforcement are separate features, and they have changed more than once.

When the money is gone, requests fail with HTTP 429 and an insufficient_quota error. That is the behaviour you want. The agent stops and says so, instead of continuing at a cost you discover at the end of the month.

Create one project and one key per machine. Platform usage then shows you which box spent what, and revoking the key on a laptop you no longer use does not break the server. Sign Codex in by piping the key, so it never becomes a command argument or a shell history line:

printenv OPENAI_API_KEY | codex login --with-api-key

Keep the export in a file only your own user can read. If you run agents on a server, running OpenCode on a VPS covers the same key handling for an agent that has no first-party login at all, and working out a monthly bill from your own token counts is the exercise that tells you whether metered billing is really cheaper for you than a flat plan.

Route 3: a local model for the bulk, a hosted model for the hard parts

Most of what a coding agent does is mechanical: reading files, renaming symbols, writing a test that looks like three existing ones, summarising a diff. A local model handles that at no marginal cost. Keep the hosted model for the work that needs judgement.

Codex supports this directly. codex --oss points it at a local OpenAI-compatible server, with Ollama as the default:

ollama pull gpt-oss:20b
codex --oss -m gpt-oss:20b

To make it permanent, declare the provider in ~/.codex/config.toml:

model = "gpt-oss:20b"
model_provider = "ollama"

[model_providers.ollama]
name = "Ollama"
base_url = "http://localhost:11434/v1/"
wire_api = "responses"

Two constraints decide whether this is practical for you. Ollama's own Codex page asks for a context window of at least 64k tokens, and an agent fills context quickly because it pastes whole files into the prompt. That means memory. A 20b model quantised to 4 bits wants roughly 16 GB of RAM before you add the context window, and the larger gpt-oss:120b is out of reach on an ordinary VPS plan. Sizing RAM and CPU for a coding agent VPS has the working numbers.

Switching between local and hosted by hand works fine. Automating the choice is what a gateway is for. A self-hosted LiteLLM gateway gives every agent one endpoint and one place to read spend, and routing cheap work to a local model and hard work to a hosted one covers where to draw that line without making the agent worse at its job.

Picking a route

If you already pay for ChatGPT and you work from one machine, use codex login and keep an eye on /status. That is the whole answer, and it costs nothing extra.

If you drive several agents, or run unattended jobs, or use tools with no first-party login, buy an API key, prepay a small balance, and turn auto recharge off. Add a local model for the bulk work once the metered bill starts to bother you.

What failure looks like on each route

Subscription at the cap: Codex refuses the request and tells you when the window resets, and /status shows the exhausted window. Nothing is broken. Wait for the reset, buy credits, or move that session to a local model.

API key with an empty balance: HTTP 429 with insufficient_quota. Top up the balance, or raise the cap deliberately. If you never want this to happen mid-task, the plan is the better fit.

Wrong credential in use: codex login status names the auth method in force. If it reports an API key with an empty balance while your ChatGPT allowance sits untouched, that is the entire bug. Run codex logout, then codex login, then pin forced_login_method so it cannot drift back.

A bridge: a 401 or 403 from your local proxy, or a stream that dies halfway through a reply. The upstream interface changed. There is no fix you can apply from your side, which is the point.

FAQ

Can Codex use my ChatGPT Plus subscription instead of an API key?

Yes. Run codex login, finish the browser step, and Codex bills your ChatGPT plan. As of September 2026 Codex is included with Plus, Pro, Business, Edu and Enterprise. It is not included with Free or Go, so on those plans the CLI needs an API key. Confirm which credential is active with codex login status.

Why does my other coding agent still want an OpenAI API key?

Because your ChatGPT plan does not issue a credential the public API accepts. codex login writes an OAuth token to ~/.codex/auth.json for OpenAI's own clients, and api.openai.com will not take that token as a bearer key. Any agent that talks to the public API, such as aider, Cline or OpenCode, needs a key from platform.openai.com with its own balance.

Is it against the rules to route a coding agent through my ChatGPT web session?

Yes. Automating a consumer web session is against OpenAI's terms of use, and it can cost you the account. These bridges also break constantly, because they depend on an internal interface that changes with no notice, so a working setup rarely survives more than a few weeks.

Does Codex CLI usage eat into my ChatGPT app limits?

Yes. Local CLI sessions, cloud Codex tasks and ordinary chat all draw on the same plan allowance. Usage is metered on a rolling five-hour window with a weekly cap over it. Run /status inside a Codex session to see how much of each window is left and when it resets.

How do I stop an API key from running up a large bill?

Prepay a balance and turn auto recharge off, because you cannot spend credits you do not have. Set the platform's monthly budget and spend alerts as a second layer, and treat the budget as a warning rather than a guaranteed cut-off. When the balance is empty, requests return HTTP 429 with insufficient_quota, so the agent stops instead of spending quietly.