GuidesGetting started

The ChatGPT setting that makes device-code sign-in work

Enable Codex device-code login in ChatGPT Security settings or workspace permissions, start a fresh sign-in, and distinguish account, code and model errors.

July 31, 2026Updated September 13, 2026The Everpod team
The short answer

If Codex asks you to enable device-code authorization, open ChatGPT’s Settings → Security and enable device-code login for your personal account. For a workspace account, an admin controls it in workspace permissions. Then start a fresh sign-in, open the URL it prints and enter the new code. This is the personal/workspace split documented in OpenAI’s headless sign-in instructions.

What device-code authorization does

The terminal displays a code; you approve that sign-in in a browser. The browser can be on a different computer from the tool you are signing into. OpenAI recommends this beta flow for headless machines and for setups where the ordinary browser login cannot reach its localhost callback.

A normal browser-based Codex sign-in does not use this permission. Device-code login is not limited to servers, either: a laptop can use it when its usual callback is blocked.

Enable it, then start the right sign-in

  1. Check the account. In the browser, sign into the ChatGPT account you want the tool to use. Enable device-code authorization in its Security settings, or ask the workspace admin to enable the workspace permission.
  2. Start a fresh attempt. For Codex CLI, run:
    codex login --device-auth
    If you are connecting OpenClaw instead, use its own documented sign-in command:
    openclaw models auth login --provider openai --device-code
    These commands sign into different tools; use the one you are setting up.
  3. Approve your code in the browser. Open the printed URL, enter the code and complete the approval. If the link opens in a browser without your ChatGPT session, sign in there or move it to the browser you normally use.
  4. Check the terminal finishes. For Codex CLI, use codex login status to check the active login, then try a small task. For OpenClaw, send a test message to your agent. Authentication and permission to use the selected model are separate checks.

If the new code still fails

Only approve a code from a sign-in you started. If device-code login is unavailable, OpenAI also documents browser-based alternatives for Codex CLI, including forwarding the callback over SSH. On a work account, use a method your organization permits.

Your own cloud agent, set up for you.

Everpod runs OpenClaw on a private, always-on computer of its own: set up, secured and backed up, with model usage included. You name your agent, and say hello about fifteen minutes later.

Create your agent

First month half price, then $29/mo · model usage included · cancel anytime

Wondering what you’d do with one? See what a cloud agent can do