Security fixes are provided for the latest released version.
Codex Usage Bar reads the existing Codex authentication file from CODEX_HOME or %USERPROFILE%\.codex\auth.json in order to request the account's usage data.
The application:
- does not write to
auth.json; - does not print or log access tokens;
- does not persist tokens anywhere else;
- sends the token only over HTTPS to the ChatGPT usage endpoints used by the application;
- does not include analytics, telemetry, advertising, or third-party tracking.
The source is intentionally small so this behavior can be audited directly.
Please use GitHub's private security-advisory feature for vulnerabilities involving credentials, authentication, or code execution. Do not publish access tokens, account identifiers, or private Codex files in a public issue.