On September 25, 2026, between approximately 3:33 p.m. PDT and 4:47 p.m. PDT, Codex users signing in with ChatGPT experienced elevated authentication errors and failed requests. A false-positive security alert prompted an internal access change that prevented Codex from processing these requests. Service largely recovered by approximately 4:47 p.m. PDT.
During this period:
Users accessing Codex through Sign in with ChatGPT experienced authentication errors (401) and gateway errors (502).
Codex access through customer-provided API keys was unaffected.
Our credential leak detection and enforcement system incorrectly flagged credentials used for communication between internal services supporting Codex as potentially leaked. These credentials were subsequently revoked through a manual operation that bypassed existing safeguards. We confirmed that the triggering traffic was legitimate and the affected internal credentials had not been leaked.
Engineers restored the affected credentials and deployed replacement credentials in parallel. The original credentials were re-enabled by 4:39 p.m. PDT, with service recovery continuing as the changes took effect. Service recovered by approximately 4:47 p.m. PDT.
We plan to make the following improvements to reduce the likelihood and impact of similar incidents:
Strengthen safeguards for operations that could affect credentials used by internal services.
Improve recovery tooling to restore mistakenly disabled credentials more quickly.
Update how internal services authenticate to reduce their dependence on this type of credential.
We apologize for the disruption this caused to your work.