The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →If Codex CLI returns 401 Unauthorized, check the credentials and API access settings used for that request; reinstalling the CLI will not fix an invalid key. If installation fails or codex is not found, troubleshoot the installer, package manager, architecture, or shell path instead. For normal CLI sign-in, run codex login and complete the browser flow, or sign in with an API key using printenv OPENAI_API_KEY | codex login --with-api-key.
First identify which part is failing
“Codex CLI 401 Unauthorized,” “Codex login not working,” and “Codex CLI installation failed” can describe different problems. Note the command you ran, the exact error text, and whether it appeared during installation, browser sign-in, or an API request. A missing codex command or failed download is not evidence of a bad API key.
- Installer or package-manager error: follow the installation checks below.
- Browser or remote sign-in trouble: use the login options in the remote sign-in section.
- 401 from an API request: check the key, account context, permissions, and IP restrictions.
Install Codex CLI using an official route
The OpenAI Codex README documents standalone installers, npm, Homebrew, and manual release binaries. Choose the route that fits your operating system and existing tools; use the binary for your machine’s architecture when installing manually. The README lists macOS Apple Silicon/arm64 and x86_64 binaries, and Linux arm64 and x86_64 binaries. See the Codex CLI README for current installation instructions and releases.
macOS or Linux standalone installer
Run:
curl -fsSL https://chatgpt.com/codex/install.sh | sh
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
Windows standalone installer
In PowerShell, run:
powershell -ExecutionPolicy ByPass -c "irm https://chatgpt.com/codex/install.ps1 | iex"
npm or Homebrew
- npm:
npm install -g @openai/codex - Homebrew:
brew install --cask codex
Manual release binary or download fallback
Download the release binary matching your platform from the GitHub release and rename the extracted executable to codex if needed. The standalone installer uses https://releases.openai.com/codex by default and can fall back to GitHub Releases if metadata or an asset is unavailable. To force that fallback, set CODEX_INSTALLER_USE_RELEASES_OPENAI_COM=false in the macOS/Linux environment or PowerShell environment before running the installer, as documented in the README.
If the installation completes but the shell reports command not found, or you encounter a permissions, proxy, or package-manager error, the correct fix depends on your OS, shell, installation method, and full error output. Verify whether codex --version works; do not rotate API keys to address a download or executable-path problem.
Choose the sign-in method that matches your access
Codex CLI supports ChatGPT sign-in for subscription access and OpenAI API-key sign-in for usage-based access. These are different access paths, not interchangeable ways to describe one credential. OpenAI’s Authentication guide explains the supported sign-in methods and credential handling.
Rank #3
| Sign-in method | How to sign in | Access and billing | Considerations |
|---|---|---|---|
| ChatGPT | codex login, then complete browser sign-in |
Subscription access through the signed-in ChatGPT workspace or plan | Workspace policies apply. Codex cloud requires ChatGPT sign-in. |
| OpenAI API key | printenv OPENAI_API_KEY | codex login --with-api-key |
Usage-based access billed at standard OpenAI API rates | Some ChatGPT workspace or cloud-dependent features may be limited or unavailable. |
For API-key sign-in, confirm that OPENAI_API_KEY contains the intended key. Merely setting the environment variable does not complete CLI login: pipe it to codex login --with-api-key. Avoid displaying or sharing the key in logs, tickets, or chat. Workspace administrators can enforce a login method or workspace; if the active credentials conflict with those restrictions, Codex may log the user out and exit. Ask the administrator which method and workspace are permitted before repeatedly switching credentials.
Fix an API 401 Unauthorized response
When an API request returns 401, use the error text and API context to check the likely access problem. OpenAI’s API error-code guide documents invalid authentication and access-related causes. Review the API error-code guidance.
- Check whether the key is valid and active. Look for a typo, extra whitespace, or a key that was deleted, deactivated, or revoked. If it may be invalid, create a replacement and update the application or CLI configuration that uses it.
- Verify the intended project and organization. Confirm that the key and the request’s organization context match the account or project you mean to use.
- Check endpoint permissions. Ensure the key has the permissions required for the endpoint being called.
- Resolve organization membership errors. If the message says the account must be a member of an organization, ask that organization’s owner for an invitation or access.
- Check IP authorization. If the message identifies an IP restriction, compare the request’s source IP with the project or organization allowlist. Use an authorized network or ask the appropriate owner to update the allowlist.
A 401 is not, by itself, evidence that API credits are exhausted or that a rate limit was reached; OpenAI classifies those as 429 errors. Use the specific response and the component that returned it to select the troubleshooting path.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.When browser sign-in fails on a remote or headless machine
The usual codex login flow opens a browser and returns credentials to Codex. On a remote or headless host, the browser may be unavailable or the localhost callback may be blocked. OpenAI’s Authentication guide documents codex login --device-auth for device-code sign-in where that option is enabled in personal security or workspace permissions. If it is unavailable, the guide also describes authenticating on a browser-capable machine and copying the credential cache, or forwarding the localhost callback over SSH when forwarding is available.
Copied credentials are sensitive. Codex may store login details in the operating system credential store or in ~/.codex/auth.json. Treat auth.json as a password: do not commit it to a repository or share it in a ticket or chat. A copied ChatGPT session cache is not a fix for an invalid API key.
Quick Recap
Check or reset the CLI’s saved login
- Run
codex login statusto see the active authentication method. - If the saved login is wrong or stale, run
codex logoutto clear stored credentials. - Sign in again with
codex loginfor the ChatGPT browser flow, or useprintenv OPENAI_API_KEY | codex login --with-api-keyfor API-key access.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




