How to Switch Codex CLI Accounts (CODEX_HOME)
Short answer: run codex logout, then codex login and sign in with the other ChatGPT account. To keep several accounts signed in, give each one its own CODEX_HOME directory, or save each login once in a switcher. Either way, restart open Codex sessions afterwards: a running session keeps the account it started with.
Checked 29 September 2026 against OpenAI’s Codex authentication docs and the Codex CLI 0.153.4 source.
TL;DR
- The login lives in
$CODEX_HOME/auth.json(default~/.codex/auth.json), unless you switched Codex to the OS keyring. codex logout+codex login: built in; a browser sign-in on every switch.- One
CODEX_HOMEper account + shell aliases: several accounts signed in at once; you pick one when you startcodex. - Open sessions need a restart after any switch.
- FavTray (Pro) saves each ChatGPT login once and switches from the account chip on the Codex card. CodexBar does Codex switching too, free.
- Switching doesn’t add usage: every account keeps its own limits. Use accounts you own and follow OpenAI’s terms.
Where does the Codex CLI store your login?
According to OpenAI’s Codex authentication docs, Codex caches your login in auth.json under CODEX_HOME, which defaults to ~/.codex. A cli_auth_credentials_store setting in config.toml changes that:
| Value | Where the login goes |
|---|---|
file | $CODEX_HOME/auth.json |
keyring | The OS credential store (fails if it’s unavailable) |
auto | The OS store when available, otherwise auth.json |
ephemeral | Memory only, for the current process |
In Codex 0.153.4’s source, a ChatGPT sign-in writes auth.json with an auth_mode, a tokens block (ID, access and refresh tokens plus the ChatGPT account_id) and a last_refresh time. The docs’ warning applies: “Treat ~/.codex/auth.json like a password.” Don’t commit it or paste it anywhere.
The docs also note the CLI and the IDE extension share this cache: logging out of one logs out the other.
How do you switch with codex logout and codex login?
codex logout # clears the cached login
codex login # opens the browser; sign in with the other account
codex login status # shows how you're signed in
On a machine without a browser, codex login --device-auth gives you a code to enter elsewhere. To use an API key instead of ChatGPT, pipe it to codex login --with-api-key.
This is fine for an occasional switch. The catch is that only one login is cached per CODEX_HOME, so every switch back is another browser sign-in.
How do you use multiple Codex accounts with CODEX_HOME?
Give each account its own directory and sign in once in each:
CODEX_HOME=~/.codex-work codex login
CODEX_HOME=~/.codex-client codex login
Then add aliases to ~/.zshrc:
alias codex-work='CODEX_HOME=~/.codex-work codex'
alias codex-client='CODEX_HOME=~/.codex-client codex'
codex keeps using ~/.codex, and each alias starts Codex on its own account. Two terminals can run two accounts side by side.
Trade-offs:
- Everything in
CODEX_HOMEis per account, not just the login:config.toml, history and sessions too. Copy or symlinkconfig.tomlif you want the same settings everywhere. - The IDE extension and other apps use
~/.codexunless they’re launched with the variable set. - You choose at launch. There’s no switching a running session.
Why not just copy auth.json between accounts?
Keeping auth-work.json and auth-personal.json and copying one over auth.json looks like the simplest switcher, and it works for a while. The problem is refresh. In the 0.153.4 source, Codex refreshes a ChatGPT login shortly before the access token expires, or eight days after last_refresh, and the refresh replaces the refresh token. A copy you saved last week may then be rejected with refresh_token_reused, refresh_token_expired or refresh_token_invalidated, and you’re back to codex login.
Two rules keep a manual switcher working: save a fresh copy of the outgoing account right before each swap, and write the new file atomically (write to a temp file with mode 0600, then rename it over auth.json) so Codex never reads half a file.
Why do open Codex sessions need a restart after switching?
A running Codex session loads its credentials when it starts and keeps them in memory. From the 0.153.4 source, it only re-reads auth.json when the file still holds the same account, which is how it picks up its own refreshed tokens. A different account in the file is ignored until you restart.
So after any switch, by hand or with an app:
- Quit open
codexsessions and start them again. - Reload the IDE extension if you use it.
OpenAI doesn’t document this behaviour; it’s what the current source does and may change.
Claude Code behaves differently: open sessions follow a switch within about 30 seconds. See how to switch Claude Code accounts on Mac.
How do you switch Codex accounts in one click with FavTray?
FavTray’s AI usage tracker shows your Codex session and weekly limits in the menu bar. From 2.0.5, FavTray Pro adds saved accounts:
- Save current login: click the account chip on the Codex card in AI Usage and save the account you’re signed in with.
- Add account…: FavTray runs
codex loginwith a temporaryCODEX_HOME, so your current login isn’t touched. Sign in with the other account in the browser and FavTray saves it. - Switch: click the chip and pick an account. The toast reminds you to restart open Codex sessions.
How it works:
- Fresh copy first. Before a swap, FavTray saves the current
auth.jsonfor the outgoing account, then writes the new one as a 0600 temp file and renames it into place. It reads the file back to confirm and restores the old one if anything’s off. - Saved logins stay on your Mac, in FavTray’s own Keychain items.
- Last-known limits, no renewing. The menu shows each inactive account’s limits as of when you last used it. FavTray never signs in or renews a login: after a switch, Codex renews it itself when it next runs. An account unused for a long time may need one more
codex login, and FavTray marks it Sign in again only when OpenAI has actually rejected the login. - A nudge, not an autopilot. Near about 90% of the active account’s session or weekly limit, a notification suggests the saved account with the most room. It never switches for you.
Limits of this version: it switches ChatGPT sign-ins in the default ~/.codex (not API-key logins, and not the keyring store). Account switching is part of FavTray Pro, a one-time Lifetime licence (pricing); the Codex usage bars stay free.
If you want a free option, CodexBar (open source, MIT) has managed Codex accounts with a System Account switch, and restarts Codex’s background app server after a switch. We compare them in multiple Claude Code accounts: the best tools.
Which method should you use?
| You want to… | Use |
|---|---|
| Switch now and then | codex logout + codex login |
| Run two accounts side by side, or keep clients isolated | A CODEX_HOME per account |
| Switch your default Codex login from the menu bar and see each account’s last-known limits | FavTray Pro or CodexBar |
For how Codex and Claude Code compare as agents, see OpenAI Codex vs Claude Code.
Sources (checked 29 September 2026): Codex authentication, CodexBar releases, Codex CLI 0.153.4 source (codex-rs/login). Refresh and session behaviour come from the source, not the docs, and may change.
Frequently Asked Questions
How do I switch accounts in the Codex CLI?
Run codex logout, then codex login and sign in with the other ChatGPT account in the browser. Check it with codex login status. To keep more than one account signed in, give each its own CODEX_HOME directory, or save each login once in a switcher such as FavTray or CodexBar.
Where does Codex store its login?
In auth.json inside CODEX_HOME, which is ~/.codex by default. If you set cli_auth_credentials_store = "keyring" in config.toml, Codex uses the operating system's credential store instead. OpenAI says to treat auth.json like a password: it contains access tokens.
How do I use two Codex accounts with CODEX_HOME?
Point CODEX_HOME at a different directory per account and log in once in each, for example CODEX_HOME=~/.codex-work codex login. Then start Codex with the same variable, ideally through a shell alias such as alias codex-work='CODEX_HOME=~/.codex-work codex'.
Why doesn't my open Codex session use the new account?
Codex keeps its credentials in memory for the life of a session and doesn't pick up a different account from auth.json while it runs. After switching, quit and restart open Codex sessions (and reload the IDE extension, which shares the login).
Can I copy auth.json to switch Codex accounts?
It works for a while, but Codex refreshes its tokens and replaces the refresh token, so a stale copy can fail with refresh_token_reused or refresh_token_expired. Separate CODEX_HOME directories, or a switcher that saves a fresh copy before each swap, avoid that.
Does switching Codex accounts increase my usage limits?
No. Each ChatGPT account has its own plan and its own Codex limits; nothing is pooled. Switching is for moving between accounts you own, such as personal and work, and each account stays under OpenAI's terms.