Skip to content

fix(openai): openai ChatGPT OAuth requests using Zen API key - #49849

Open
jhsu wants to merge 1 commit into
anomalyco:devfrom
jhsu:oauth-credential
Open

jhsu wants to merge 1 commit into
anomalyco:devfrom
jhsu:oauth-credential

Conversation

@jhsu

@jhsu jhsu commented Sep 18, 2026

Copy link
Copy Markdown

Issue for this PR

Closes #49847

Type of change

  • Bug fix
  • New feature
  • Refactor / code improvement
  • Documentation

What does this PR do?

Fixes an issue where the incorrect auth was being used for openai.

It was causing requests with the correct Codex endpoint and ChatGPT account header, but with the Zen API key in Authorization. Codex rejects these requests with API keys are not supported by this endpoint.

How did you verify your code works?

tested a similar implementation with a plugin

Also, added a regression test with both a Zen API key and ChatGPT OAuth credential configured. It verifies that the provider remains available and the Codex request uses the ChatGPT OAuth token.

Checklist

  • I have tested my changes locally
  • I have not included unrelated changes in this PR

Console-provided OpenAI catalogs were left owned by the Zen integration after the OpenAI plugin rerouted them to the ChatGPT Codex endpoint. Rebind both credential ownership and source connection to the active ChatGPT OAuth connection.
@github-actions

Copy link
Copy Markdown
Contributor

Hey! Your PR title fix openai ChatGPT OAuth requests using Zen API key doesn't follow conventional commit format.

Please update it to start with one of:

  • feat: or feat(scope): new feature
  • fix: or fix(scope): bug fix
  • docs: or docs(scope): documentation changes
  • chore: or chore(scope): maintenance tasks
  • refactor: or refactor(scope): code refactoring
  • test: or test(scope): adding or updating tests

Where scope is the package name (e.g., app, desktop, opencode).

See CONTRIBUTING.md for details.

@github-actions

Copy link
Copy Markdown
Contributor

The following comment was made by an LLM, it may be inaccurate:

@jhsu jhsu changed the title fix openai ChatGPT OAuth requests using Zen API key fix(openai): openai ChatGPT OAuth requests using Zen API key Sep 18, 2026
@simontretter

simontretter commented Sep 19, 2026 •

Copy link
Copy Markdown

Confirming this bug on v2.0.12 (also reproduced on v2.0.8) - Linux, logged into the OpenCode Console and ChatGPT OAuth (chatgpt-headless, Plus plan) at the same time.

Every openai/* model fails with Provider request failed with HTTP 401, and re-authenticating OpenAI does not help.

I verified the diagnosis in this PR independently:

  • The request does route to the correct endpoint — I proxied OpenCode's traffic: 10 connections to chatgpt.com:443, zero to api.openai.com. The chatgpt-account-id header is present.
  • But the Authorization bearer is the Zen API key, not the ChatGPT OAuth token. Curling POST https://chatgpt.com/backend-api/codex/responses with my Zen key reproduces the exact failure: HTTP 401 {"message": "API keys are not supported by this endpoint.", "code": "api_key_not_supported"}.
  • My ChatGPT OAuth token itself is fine — the same request with the OAuth bearer returns HTTP 200 and streams completions for gpt-5.5 and gpt-5.6-luna. So the stored credential is valid; the provider just never sends it, exactly as described here.
  • I also checked the openai.ts source at the v2.0.11 and v2.0.12 tags: the integrationID pin from this PR is absent in both, so no released version contains the fix yet.

Happy to test a build with this merged.

@kostrse

kostrse commented Sep 23, 2026

Copy link
Copy Markdown

It happens when BYOK key enabled in the OpenCode Console.

@simontretter

Copy link
Copy Markdown

Removing my BYOK OpenAI account from the web console resolves it immediately, which points at the Console-supplied credential winning over the ChatGPT OAuth token.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

openai: ChatGPT OAuth requests use Zen API key

3 participants