Skip to main content
Run Pullfrog on the Codex access included in every ChatGPT plan, with no OpenAI API bill on top. One command signs you in and stores the credential.
A Codex subscription covers the OpenAI models in the picker, including GPT Astra, GPT Sol, GPT Terra and GPT Luna. For other providers, see Model access.

Setup

Run this inside a clone of the repository. The CLI uses the GitHub CLI to sign you in, and the Codex CLI must be on your PATH.
The CLI:
  1. Runs codex login --device-auth in a temporary Codex home, so your own ~/.codex/auth.json is untouched.
  2. Opens the sign-in URL and shows a one-time code. Sign in to ChatGPT and approve the code.
  3. Refreshes the new credential once, then saves it to Pullfrog’s encrypted store.
The next run on an OpenAI model uses the subscription. Run the command again to add another ChatGPT account or replace one. With several connections, or an OPENAI_API_KEY beside them, Pullfrog moves to the next credential when one is rejected or out of quota; see multiple subscriptions and fallback.
The Subscriptions row of the Providers section: Claude Pro/Max, ChatGPT (Codex) and Grok

Scope

On an organization repository, the CLI asks where to store the credential: A personal account has only the account scope, so the CLI does not ask. To skip the prompt or run outside a checkout, pass the scope as a flag:

Credential refresh

ChatGPT access tokens last about ten days, and every refresh replaces the refresh token. Pullfrog keeps the stored copy current on its own:
  • Before a run, Pullfrog refreshes the stored credential when less than a day is left on it.
  • After a run, Pullfrog saves any token the run refreshed back to its store.
The credential must stay in Pullfrog for this to work. A copy in a GitHub Actions secret cannot be updated after a refresh and stops working.

Troubleshooting