Operator GuideAuthenticationAgent Authentication

Codex

Register Codex accounts and authorize them for workspaces

Codex profiles use ~/.codex by default. jackin❯ scans that location on first start and imports an account only when it finds credentials in auth.json. Importing an account does not grant it to a workspace.

Register and assign a profile

Complete the agent's login flow on the host, then scan and list the imported accounts:

jackin account scan
jackin account list

To register a specific profile explicitly:

jackin account add codex-work --agent codex --directory ~/.codex
jackin workspace account assign my-app codex-work
jackin workspace account select my-app codex-work --agent codex

For an additional login, select the same directory that your host alias uses. A custom profile stays separate from the default profile. jackin❯ validates credential evidence inside the selected directory before registration.

API-key account

Register a provider key with the masked prompt, then authorize and select it:

jackin account add openai-key --provider openai --api-key
jackin workspace account assign my-app openai-key
jackin workspace account select my-app openai-key --agent codex

Use --secret-ref '$OPENAI_API_KEY' to reference a host environment variable, or --secret-ref 'op://Work/Codex/api-key' for a 1Password reference. The account stores the reference; jackin❯ resolves it when launching an authorized workspace.

Runtime trust prompts

jackin❯ passes Codex an in-container trust_level = "trusted" override for workspace-backed launches, so Codex does not stop on the "Do you trust this directory?" prompt after the workspace is already mounted into the container. This does not write to your host ~/.codex/config.toml or mark the host checkout trusted outside jackin❯.

Check workspace access

jackin workspace account list my-app

The account must be assigned and support codex. When several assigned accounts support the same agent, select one explicitly; role-specific selection uses --role <ROLE>. An empty account allowlist forwards no coding-agent credentials.

See Account commands and Agent authentication for the registry and authorization rules.

On this page