Codex went down for 56 minutes on Friday, telling users their API keys were wrong
OpenAI's Codex suffered a 56-minute outage on September 25, serving bogus 401 errors to ChatGPT-authenticated users across web, desktop, and CLI before recovering; the root cause has not been disclosed.
On Friday afternoon, Codex users started seeing a message that blamed them for a problem on OpenAI's side. Across the web interface, the desktop app, and the CLI, requests began failing with 401 Unauthorized: Incorrect API key provided, even for users who had been working normally all day and whose credentials were fine. Re-authenticating did nothing.
The incident is now closed, and the timeline from OpenAI's status page tells the story in six updates. The official record opened at 22:58:48 UTC on September 25 with an internal issue found and mitigation underway. Elevated errors were confirmed five minutes later. At 23:19, about twenty minutes in, OpenAI advised affected users to sign in with an API key as a workaround. Root cause was identified at 23:34, though the company has not disclosed what it was. Mitigation landed at 23:45, and full recovery was declared at 23:54:41, 55 minutes and 53 seconds after the record opened.
Why the 401 matters
A 401 is the error that says "your credentials are wrong," which is why the first instinct of everyone affected was to check their own setup. One detailed GitHub issue filed during the outage walks through the full troubleshooting ritual: verifying the CLI version, logging out and back in on both CLI and desktop, confirming the endpoint was the ChatGPT Codex backend. None of it helped, because the failure was in auth routing on OpenAI's side, not in anyone's keys.
The API-key workaround is the most revealing detail. ChatGPT-plan authentication was broken, but direct API-key access worked, which points at the subscription-auth path rather than the underlying model infrastructure. For developers running Codex through their ChatGPT subscription, that distinction mattered: there was a way back in, but it meant reaching for a different billing identity mid-incident.
The developer takeaway
The outage threads on OpenAI's developer forum make the cost concrete. People lost running agent sessions mid-task. Long-running Codex jobs that had been churning for hours died with "reconnecting" spinners. Several subscribers asked whether OpenAI would reset usage limits to compensate for the lost time, a reasonable ask when the tool you pay for eats an evening of work through no fault of yours.
Two practical lessons. First, treat 401s during a suspected outage as possibly server-side: if re-authentication does not fix it and the status page shows an active incident, stop debugging your credentials. Second, if your workflow depends on Codex, having an API key configured as a fallback auth path is now a proven recovery option, not just a theoretical one. It is an odd kind of redundancy, keeping a second identity warm for the day the first one breaks, but Friday showed it works.
OpenAI has not published a postmortem or named the failed component. Until it does, the outage is a reminder that the thinnest part of the agentic coding stack is not the model. It is the plumbing between you and it.