Codex

Codex: "An error occurred during authentication (codex_cli_workspace_disabled)"

Last checked

The error

An error occurred during authentication (codex_cli_workspace_disabled). Please try again. You can contact us through our help center at help.openai.com if you keep seeing this error. (Please include the request ID <request-id> in your email.)

Shown on the ChatGPT sign-in page when signing in to the Codex app, CLI or IDE extension with a Business or Enterprise workspace account.

This is a workspace policy, not a Codex bug. Your ChatGPT Business, Enterprise or Edu workspace has local Codex use switched off, so sign-in for the Codex app, CLI and IDE extension is refused. Retrying will not help. Ask a workspace admin to enable "Allow members to use Codex locally", or sign in with an OpenAI API key if your organisation allows it.

Why it happens

Codex local access is controlled per workspace. When an admin has it off, or your role does not include it, the sign-in flow returns this error code instead of a token. An OpenAI maintainer closed issue #17833 with "This sounds like an account issue, not a bug in Codex."

  1. The workspace setting that allows members to use Codex locally is off. Depending on the workspace layout it is labelled "Allow members to use Codex locally" or the combined "Allow members to use Codex and Work Locally".
  2. Codex is enabled, but only for some roles or groups through role-based access control, and your account is not in one of them.
  3. You signed in to the wrong workspace. If you belong to both a personal and a company workspace, the company one may block Codex while the personal one would not.
  4. Your organisation pins Codex to specific workspaces or login methods through managed config (forced_chatgpt_workspace_id, forced_login_method), so the workspace you picked is not permitted.

The fix

  1. 1 Run codex logout, then sign in again and pick the intended workspace on the ChatGPT account screen.
  2. 2 Run codex login status to confirm which method and account Codex is using.
  3. 3 Ask a workspace admin to turn on Allow members to use Codex locally in the workspace settings, and to check that your role or group includes Codex.
  4. 4 On a headless or SSH machine, use codex login --device-auth, which some workspaces also require the admin to enable.
  5. 5 If your company allows Platform API usage, sign in with an API key instead: printenv OPENAI_API_KEY | codex login --with-api-key. Usage is then billed to that API organisation, not the ChatGPT seat.
printenv OPENAI_API_KEY | codex login --with-api-key

What to send your admin

Give them the full error text with the request ID, the client you used (Codex app, CLI or IDE extension) and the workspace name you selected. Ask them to confirm three things: that the workspace allows Codex locally, that your role or group has Codex access, and whether a managed Codex config restricts login method or workspace.

Codex cloud and local Codex can be governed separately, so having one working does not mean the other is allowed.

Still failing?

  • Wait a few minutes after the admin changes the setting, then sign out and in again so a fresh token is issued.
  • If an API key login is refused too, check for a managed config that sets forced_login_method to chatgpt.
  • If the admin confirms everything is enabled, contact OpenAI support at help.openai.com with the request ID from the error.

Related errors

Hit a different error?

Paste any agent error and get the cause and fix in seconds.

Open the decoder

Frequently asked questions

Can I fix this myself?

Not within the workspace. Only an admin can change the setting. Your options are an API key login, if permitted, or a different workspace that allows Codex.

Is this the same as running out of Codex usage?

No. Usage limits appear after you are signed in. This error blocks the sign-in itself.

Will it affect Hermes or OpenClaw using my ChatGPT login?

Tools that sign in through the Codex ChatGPT flow use the same workspace account, so expect the same refusal until the admin enables Codex.

Stop firefighting agent errors

Decoding errors one at a time is the manual version of what BetterClaw automates. Run your agents on a no-code AI agent platform with managed models, retries and config validation built in.

Free plan available · Pro $49/mo · BYOK · 7-day money-back guarantee