跳转至

OpenAI Codex

Required secret Overlay
DISCORD_BOT_TOKEN values-openai-codex.yaml

When to use it

Use this provider for account-backed Codex access. It is separate from openai-api, which requires OPENAI_API_KEY. Model availability follows the ChatGPT plan and the live Codex catalog returned for the authenticated account.

Persistent storage is required because Hermes stores refreshable credentials in HERMES_HOME/auth.json.

Install

helm upgrade --install hermes-codex ./charts/hermes-agent \
  --namespace hermes-codex --create-namespace \
  -f charts/hermes-agent/values-openai-codex.yaml \
  --set-string env.DISCORD_BOT_TOKEN='<real-value>' --wait

Open the link posted to Discord, enter the one-time code, and complete the OpenAI sign-in. On later Pod starts the init container asks Hermes to validate or refresh the stored credentials and skips a new login when they remain usable.

kubectl logs deploy/hermes-codex-hermes-agent -n hermes-codex \
  -c auth-device-login -f

Login codes expire

A code is valid for about 15 minutes. If it expires before you approve it, the init container reports the timeout and requests a new code on its own, so enter the newest one. A live run showed exactly this: the first code expired, a second arrived, and approving it completed the login.

Larger context window

The Codex route advertises 272K for most models. Hermes can use about 900K when you opt in with a -900k suffix, such as gpt-6-luna-900k, and you should raise compression.threshold_tokens with it. The suffix is a Hermes alias, not an OpenAI model name, and a larger window uses your subscription quota faster. The overlay below explains the details.

Several releases on one ChatGPT account

Each release logs in on its own and keeps its credential in its own auth.json. Upstream documents that two logins of the same OpenAI account share one token family and that OpenAI revokes the older one. In a live check, three releases logged in to one Plus account within a minute, and a hermes auth refresh openai-codex in each release still succeeded, so no immediate revocation appeared. A later refresh was not checked.

  • For a team, prefer one account per release.
  • If a release starts failing to refresh, run hermes auth refresh openai-codex in each release to see which login died, then log in again there.
  • Do not copy one auth.json into several releases. The refresh token is single use, so the copies cannot all stay valid.

Open Raw YAML

Complete overlay

charts/hermes-agent/values-openai-codex.yaml
# values-openai-codex.yaml
#
# Hermes Agent backed by the account-authenticated OpenAI Codex provider. The
# auth init container sends a verification URL + one-time code to Discord,
# waits for approval, and stores the refreshable credential in
# HERMES_HOME/auth.json through Hermes' native auth-store helper.
#
# This is distinct from the `openai-api` provider and does not use an OpenAI API
# key. Your ChatGPT plan and the live Codex catalog determine model access.
#
# All secrets below are DUMMY placeholders. Do not commit real tokens.
#
#   helm upgrade --install hermes-codex ./charts/hermes-agent \
#     --namespace hermes-codex --create-namespace \
#     -f charts/hermes-agent/values-openai-codex.yaml \
#     --set-string env.DISCORD_BOT_TOKEN='<real-bot-token>' --wait
#
#   kubectl logs deploy/hermes-codex-hermes-agent -n hermes-codex \
#     -c auth-device-login -f

config:
  model:
    provider: openai-codex
    # Listed in the pinned Hermes Codex catalog. Your plan decides whether the
    # account can use it.
    # Use /model in Discord to select another model available to your account.
    default: gpt-5.6-terra
    # Optional larger context window. The Codex route advertises 272K for these
    # models. Hermes can use about 900K when you opt in with a `-900k` suffix,
    # for example:
    #   default: gpt-6-luna-900k
    # Notes (checked against Hermes v2026.9.24, the chart's pinned image):
    #   - `-900k` is a Hermes alias, not an OpenAI model name. It is removed
    #     from the model id sent to OpenAI, and Hermes caps the window at the
    #     account catalog's maximum. Hermes verified the larger window live; it
    #     is not an OpenAI-published guarantee, so drop the suffix if a request
    #     is rejected.
    #   - Only some models qualify (the gpt-5.6 and gpt-6 families, among
    #     others). The suffix on any other model is not a valid alias. This
    #     chart's live check used gpt-6-luna-900k; other models are untested.
    #   - It is opt-in because a large context uses your subscription quota
    #     faster.
    #   - The behavior is still evolving upstream (several fixes landed between
    #     2026-09-19 and 2026-10-01), so re-check it after an image bump.
  terminal:
    backend: local
  # Compaction fires at the lower of the ratio trigger and this absolute cap.
  # The default cap is 256000, so a 900K window would still compact at 256K.
  # Raise it (or set it to null for the ratio only) when you use `-900k`.
  # compression:
  #   threshold_tokens: 700000

auth:
  deviceFlow:
    enabled: true
    provider: openai-codex
    notify: discord

env:
  # Unused by openai-codex; overrides the chart's OpenAI placeholder.
  OPENAI_API_KEY: "unused"
  DISCORD_BOT_TOKEN: "MTA0DUMMYtoken000000000000.DUMMY.replace_me_with_a_real_token"

extraEnv:
  - name: DISCORD_HOME_CHANNEL
    value: "000000000000000000" # DUMMY - channel id for login delivery
  - name: DISCORD_ALLOWED_USERS
    value: "111111111111111111" # DUMMY - allowed Discord user id
  - name: DISCORD_ALLOW_ALL_USERS
    value: "false"

# Required so auth.json and its refresh token survive Pod replacement.
persistence:
  enabled: true
  storageClass: ""
  accessModes:
    - ReadWriteOnce
  size: 5Gi

resources:
  requests:
    cpu: 100m
    memory: 256Mi
  limits:
    cpu: "1"
    memory: 1Gi