Skip to content

[Feature]: Automatic OpenAI model and capability discovery with account-aware pooling #6257

Description

@clairernovotny

Area

Catalog / models

What are you trying to accomplish?

Have OpenCodex automatically discover new OpenAI model IDs and their advertised capabilities, labels, defaults, and supported effort/speed/program options without recurring model-specific backend releases or manual custom IDs. Keep existing stock Codex installations and account pooling working. Use the primary account for the default menu, show partial coverage across pooled accounts, and route each selected combination only to supporting accounts.

What prevents this today?

OpenCodex already fetches authenticated model rosters, but much of native catalog membership and capability interpretation is rebuilt from compiled lists, pins, family rules, and fixed control mappings. Unknown rows can disappear from the picker even when inference works. Custom IDs borrow another model's traits, while the existing opt-in refresh scheduler refreshes this largely static interpretation. New IDs, effort values, or speed tiers can therefore still require registration changes, and model-level discovery alone does not establish capability support across a heterogeneous account pool.

What should OpenCodex do?

  • Discover authenticated account-scoped descriptors automatically and preserve unknown JSON fields for compatible future projections.
  • Present upstream identities and labels dynamically, with explicit operator overrides; expose new controls only when the upstream contract and stock client can represent them.
  • Base the default menu on the physical primary account and offer a clearly identified supplemental view for pool-only options. Keep partially supported selections available with an indicator such as “Supported by 2 of 4 pooled accounts.”
  • Preserve pool strategy, quota accounting, affinity, retry, upload, streaming, Reserve, and main-drain behavior within the eligible subset for the full requested combination. Do not infer entitlement from plan names, labels, or cost, or silently downgrade selected controls.
  • Update through stock Codex live-catalog or owned-file interfaces with no Codex fork, patch, custom build, or mandatory upgrade. State normal reload requirements and unsupported client controls honestly.
  • Handle discovery failure, incomplete responses, withdrawal, credential changes, and publication races without false availability or cross-account leakage.

The design below addresses the existing constants and aliases, client delivery limits, caller-owned credentials, refresh costs, maintainer concerns, and acceptance conditions. It is a design proposal only; implementation and a work breakdown are separate.

Example usage or interface

Illustrative future discovery, using hypothetical IDs and controls rather than claiming an existing OpenAI offering:

  1. OpenAI begins advertising model orion/preview-7 to the primary account, with its own instructions, context limits, effort deep, and service tier express_plus in fields supported by a qualified stock client.
  2. OpenCodex refreshes that account's descriptor inventory. The model and supported choices appear without adding a constant, pin, custom ID, or Sol-derived template.
  3. Of four persistent pool members, two have affirmative support for the selected model + effort + tier + program combination. The OpenCodex UI shows “Supported by 2 of 4 pooled accounts” and keeps the choice selectable.
  4. Requests use those two accounts under the existing pool strategy. Cooldown or quota exhaustion affects readiness; it does not change the support badge into an entitlement claim. A newer refusal or credential change re-evaluates eligibility before the next attempt.
  5. An unsupported stock-client widget leaves the affected control unavailable with an explanation; it does not prevent unrelated supported models from appearing.

Existing saved selections and requests that omit controls retain their behavior. Newly selected explicit UI intent remains stable across account rotation.

Alternatives or workarounds

Manual custom IDs, per-model native registration, and pins address individual omissions but keep requiring updates or can invent inherited traits. The existing opt-in refresh scheduler and proposed Desktop cache watcher are useful lifecycle pieces, but do not replace authenticated descriptor authority or full-combination dispatch filtering. A separate metadata service or documentation scraping cannot establish account-specific access. Blind passthrough would bypass compatibility and local policy.

Additional context

Full reviewed design proposal, source references, and prior discussions

OpenCodex automatic OpenAI model discovery

Design proposal · September 29, 2026 · Analysis only

Recommendation: preserve complete authenticated OpenAI model descriptors in an account-scoped inventory, then derive catalog publication, UI controls, and request eligibility from that inventory. New model IDs and new values within supported protocol fields should appear after discovery without a model-specific OpenCodex release or manual registration.

This is an infrastructure change entirely within OpenCodex. It preserves account pooling and existing Codex installations through their stock live-catalog or file interfaces; it requires no Codex fork, patch, custom build, or mandatory upgrade. A stock client may still require its normal reload or be unable to render an unfamiliar control. Retaining new metadata does not implement unknown wire operations or client orchestration.

Problem and scope

OpenCodex already fetches authenticated Codex model rosters, but discards most descriptors and reconstructs native membership and capabilities from compiled lists, pins, and family rules. The refresh timer therefore refreshes a largely static interpretation. Custom IDs work around membership by borrowing another model's capabilities; they do not provide reliable automatic discovery.

The desired result is one consistent answer to three questions: what this account advertises, what this client can represent, and which pooled accounts can execute the requested combination. Discovery supplies facts; operator policy, compatibility, and scheduling remain separate decisions.

Analysis uses the repository at the pinned commit, main 5ab6d52b2a4da722d398e4ab50a6c621ac3ce087 (2.72.0). Fetched dev 73289d46ae3c93d06b9add99d1c834d2e5733d9a differs only in version files. Architecture, wire contracts, UI, official sources, pooling, prior art, and failure cases were reviewed. No implementation or runtime/account validation was performed; installed-client behavior and actual rosters remain unverified. This proposal defines architecture and acceptance, not a work breakdown.

Current design and related work

Boundary Current behavior and required change
Roster parser Retains slug sets, selected programs, and availability text. Preserve complete descriptors and derive those indexes.
Native registry, configured IDs Compiled membership admits registered/configured IDs; Daybreak's manual inclusion illustrates the historical static-refresh limitation. Custom IDs inherit Sol traits. Discover exact identities and their own descriptors.
Catalog merge, HTTP models Merge drops unregistered bare rows or rebuilds selectors from templates; HTTP forwards client version but reconstructs static membership. Both must consume the shared inventory.
Effort policy, management rows Pins drive native clamps; tiers collapse to fastRowAvailable. Resolve exact account/model controls and publish descriptor lists.
Refresh configuration, API-key provider Broad refresh is opt-in, defaulting to one hour. API-key ID discovery already exists but retains selected hints. Native discovery needs automatic lifecycle and richer contents.

Repository docs distinguish static identity/projection from account dispatch authority: catalog, account evidence, and refresh guards. Reuse the canonical catalog/convergence and admission machinery rather than introduce independent picker or routing registries.

The following GitHub states were checked September 29, 2026. Search covered issues/PRs across all states and all 23 discussions with complete pagination. No discussion combining the entire proposed architecture was found; related work is substantial.

Prior work Status and implication
#6251: missing GPT-6.1 Sol, #6252: self-described registration Issue open; PR open/draft, created September 29. Reporter says a complete authenticated row and successful proxy inference coexist with native-picker omission; not independently reproduced here. Coordinate with the immediate pin/registration fix; this design prevents its repetition.
#3630: automatic refresh, #4584 Issue closed; PR merged September 14. Closure delivers opt-in scheduling, separately from discovered counts and already-open Desktop adoption. Local outcome confirms landing.
#2097: unentitled native routing, #2146 Issue closed; PR merged August 20. Established authenticated account rosters and selective pool filtering. Extend that isolation from model IDs to full combinations.
#2993: fallback Ultrafast, #2994 Closed August 30; PR unmerged. Maintainer rejected fabricated fallback choices without evidence of actual speed support.
#3429: native Ultrafast, #3478 Issue closed; PR merged September 4. Delivered scope forwards selected ultrafast and preserves opted-in descriptors; it does not establish entitlement or prove fulfillment.
#3255: capability/speed controls Closed September 9. Final response separates catalog axes from the Codex-owned composer.
#6143: Desktop cache watcher Open/draft, created September 27, updated September 28. Proposed observation/reconciliation trigger keeps new names within account selectors; it is not authenticated descriptor authority. Coordinate trigger reuse and loop prevention.

Discussions #1067 (August 5–14) document cache/restart adoption; #3422 (September 4–5) recommends a stock CLI update for a missing model. These establish client limits, not a requirement to patch Codex.

Architecture and authorities

flowchart TD
    A[Authenticated roster per account and client context] --> C[Bounded source snapshots]
    B[API model list per project] --> C
    C --> D[Immutable inventory with provenance]
    J[Bootstrap pins and local observations] -->|Tagged fallback| D
    D --> E[Shared policy and capability resolver]
    E --> F[OpenCodex UI and diagnostics]
    E --> G[Compatible live or file catalogs]
    E --> H[Request intent and eligible accounts]
Loading

Extend the existing roster cache. Publish immutable revisions into convergence, retained sync, HTTP models, management/desktop views, client exports, and dispatch. Different consumer schemas may project differently, but identity, source revision, account scope, and eligibility must agree. Activate dynamic publication and dispatch authority together; until dispatch enforces the same combinations, new publication stays observational. This is an architectural safety condition, not an implementation sequence.

Sources and retained facts

Source Authority and limit
Authenticated native Codex /models Rich operational descriptors advertised to that account and actual client-version/filter context; not universal access across all versions, transports, or plans. Primary native source.
API-key GET /v1/models API-project identities and basic object metadata. Not a complete effort/tier/program/endpoint manifest; audio or embedding availability does not prove Responses support.
App-server model/list Client-facing capabilities/defaults, visibility, modalities, and upgrades. Its paginated DTO is not full native ModelInfo; use it for client validation, exhaust pagination and hidden options when needed, and avoid recursively querying a client consuming this catalog.
Local cache and bundled pins Scoped bootstrap/compatibility observations, never fresh authenticated grants.

Keep native ChatGPT accounts and API projects separate. A future supported API capability manifest can use the same source interface; documentation scraping is not executable policy. Official app-server guidance recommends returned capabilities/defaults rather than hardcoded examples.

Each snapshot retains the complete parsed payload, including unknown nested fields and distinctions among missing, null, false, and empty values. “Lossless” means JSON-value preservation, not original whitespace. Record source/transport, account/project, credential generation, endpoint, actual requested client version and filters, fetch/freshness times, successful revision, optional ETag, completeness, and failure status. Validated indexes point back to raw rows. Operator overrides and compatibility rules are separate overlays; they never overwrite source facts. Retention is not unrestricted public export: preserve management authentication/privacy boundaries and omit credentials and trusted local ownership markers from wire projections. Enforce aggregate in-memory and durable byte budgets alongside per-response limits, depth, string-length and model-count validation; bounded entry counts alone can still permit excessive retained payloads. Stored-account and ephemeral-caller caches require separate budgets.

Use bounded structural validation, opaque exact model IDs, and reversible collision-safe local namespace encoding, including punctuation or slashes. A valid authenticated ID need not start with gpt-. Fresh scoped descriptors supersede pins for live views without importing access from another scope. Keep hidden/incompatible rows for diagnostics and saved selections. Quarantine malformed rows independently so valid additions survive; an incomplete response cannot prove withdrawal.

What becomes dynamic, and what stays constant

The issue is authority, not TypeScript's const keyword. Immutable snapshots and derived indexes remain appropriate; compiled membership must stop admitting or rejecting authenticated future rows.

Current fact or lookup New authority
BUILT_IN_NATIVE_OPENAI_MODELS, NATIVE_OPENAI_MODELS, SUPPORTED_NATIVE_OPENAI_SLUGS (source) Exact-ID inventory membership and immutable derived indexes. Tagged bootstrap membership preserves existing offline behavior without dropping live additions.
SELF_DESCRIBED_NATIVE_OPENAI_MODELS, capability aliases, NATIVE_OPENAI_ALIAS_PRESENTATION (source); PINNED_NATIVE_MODEL_ROWS (source) Each scoped descriptor supplies its own capabilities/presentation. Pins remain provenance-tagged fixtures; legacy aliases remain explicit bindings, never inherited capability authority over fresh data.
NATIVE_GPT6_CONTEXT, CONFIGURED_NATIVE_OPENAI_TEMPLATE_MODEL (source) Discovered limits, instructions, defaults, and modalities. Preserve existing operator-configured custom-model templates as tagged legacy overrides/fallbacks; newly discovered rows use their own descriptors without hidden Sol inheritance.
upstreamNativeEntryForSlug, UPSTREAM_NATIVE_ENTRIES, family/merge admission (source) Scoped inventory resolution plus catalog ownership. Shape-valid local observations cannot impersonate upstream provenance.
ACCOUNT_GATED_NATIVE_OPENAI_MODELS, per-model version floors (source) Scoped model/control evidence. Preserve permissive ordinary-model fallback and restricted safeguards while replacing floors; an old-version omission cannot deny a newer context.
RETIRED_NATIVE_OPENAI_MODELS (source) Scoped withdrawal/tombstones carrying existing retirement decisions. Prevent stale resurrection before retiring the list; fresh authenticated reappearance may supersede historical withdrawal, subject to current local deny policy.
CODEX_REASONING_LEVELS, rank/set helpers and native clamps (source) Advertised efforts/defaults with understood bindings. Known vocabulary remains localization/legacy data, not a whitelist. Unknown rank cannot justify an operator cap or invented ordering. Local __omit__ retains omission semantics and never becomes a wire effort.
fastRowAvailable, synthetic --fast, Fast resolution Tier descriptors with exact IDs, labels, defaults, and bindings. Existing Fast selections retain verified bindings/collision checks; new labels do not create model identities.
Program parsing (source) Preserve every group/value rather than requiring cyber. Generic controls require a supported declared request shape; unfamiliar structures remain metadata.
Vision, compaction, combo validation Shared resolver replaces repeated family/context/effort assumptions while retaining each feature's transport constraints. Picker-only migration leaves these consumers broken.

The build-time metadata generator remains useful for offline baselines and other providers. Generated files must not become another native registration prerequisite.

Stable contract or local policy Required treatment
Provider IDs and authentication/history domains Preserve native and separately billed API-key identities. Discovery neither retags sessions nor merges grants.
__main__, @main, account validation/reserved keys, selector kinds (identity, namespace) Stable local identities. Extend model encoding independently; never confuse an upstream ID with an account/provider/combo selector.
Wire keys/envelopes, schema profiles, auth, limits and ownership fences Supported keys such as reasoning.effort, service_tier, and access_programs can accept dynamic values where their contracts allow. Unknown JSON does not define an adapter. Closed enums still require compatible projection.
Pool strategy, quotas, affinity, uploads/fixed accounts, main drain Supply eligibility without redefining lifecycle. NATIVE_MAIN_DRAIN_SENTINEL_MODELS exceptions need explicit preserved policy, not accidental inheritance from discovered membership. Verify how that policy extends to future IDs.
Reserve and legacy Daybreak/Pro/Ultra bindings Keep authorization and transport-scoped compatibility rules. A discovered gpt-reserve row cannot authorize Reserve execution.
Operator allow/deny lists, caps, opt-ins, saved choices and curated helper defaults Independent overlays/preferences, never discovery membership or grants. Preserve existing custom configuration and omission semantics.
Catalog kind/origin markers, ownership/restore and generic UI translations Remain locally trusted contracts. Upstream cannot forge ownership; branding such as “OpenAI (Codex)” is not model evidence.

Identity, presentation, and executable controls

Separate wire model ID, provider/account scope, control IDs, and legacy binding from visible text. A label change must not change saved choices, combo references, cache identity/scope, history, or affinity; descriptor bytes and content revision do update. Identical labels must not merge IDs. Resolve presentation in this order: explicit operator override, scoped upstream text, applicable tagged bootstrap/known localized fallback, then exact ID. Preserve the raw label beneath overrides; append account aliases separately.

Backend management rows, GUI rows, client naming, and account-bound labels must use this resolver. Render upstream names/descriptions as bounded literal text, not HTML, commands, executable links, or constructed i18n keys. Effort settings currently construct such keys; unknown efforts need literal fallback. Descriptor order is presentation order unless semantic rank is declared.

Use descriptor lists in settings, memory, combos, compaction, vision, CLI and exports; remove duplicate GUI context assumptions. DTOs carry defaults, provenance/freshness and compatibility, retaining Fast Boolean/rows only as legacy projections. Preserve public helper exports through delegation if necessary; every consumer must derive from the same credential/policy/client-profile revision rather than its own global supported set.

Native instructions, tool policies, context, modalities, efforts, tiers and programs remain exact scoped facts, with explicit operator caps. Unknown ordering cannot silently bypass a cap. New executable controls require an understood binding; metadata preservation alone is insufficient. Requested tier, advertised support, and observable fulfillment are separate diagnostics; forwarding does not prove speed or cost. Never invent multipliers from labels.

Keep Daybreak native rewrite, virtual Pro rules, and legacy ultra mapper until transport-specific replacements are verified. Selected identity and serving wire ID stay distinct where a verified binding requires a rewrite. Client Ultra orchestration, wire effort, and Ultrafast tier are distinct. Exact-wire literal effort ultra or tier fast requires verified descriptor provenance and a client/request profile that distinguishes it from legacy ultra → max and fast → priority. Legacy aliases apply only in their established selection context. If the existing representation cannot distinguish those intents, mark the new control incompatible/metadata-only rather than globally reinterpret the string. Daybreak's API model and access_programs.cyber are separate selections with project permissions, not native account grants.

Primary-account UI and pooled execution

Presentation and coverage

Use native main identity __main__ as the default presentation account, consistent with the integration guide. It is not the mutable active routing cursor. Resolve it through credential admission; invalidate on authenticated identity changes. Request-owned credentials stay client-scoped and cannot redefine global management primary or import grants. HTTP/client catalogs project their admissible request scope; management's primary view cannot grant that caller another account's access.

The current models handler authenticates requests but does not forward caller OpenAI credentials for upstream discovery; inference authentication already has a separate caller-owned path. Add discovery for validated, forwardable caller-owned credentials using an isolated ephemeral inventory/projection/cache, preserving data-plane admission and credential-destination checks. Never publish these grants into stored main/pool evidence, background stored-account polling, or shared files.

When credentials exist only in the caller/keyring, serve a matching caller-scoped cache immediately. A cold request starts or joins a bounded caller-scoped single flight using that validated credential, with a response deadline below the consuming client's timeout. If no compatible projection is ready, return retryable discovery unavailability; completed discovery can satisfy the next normal refresh. Never substitute main/pool metadata, fabricated empty success, or a shared file. Qualify the stock runtime's cold-auth/refresh behavior before activating this path; if it cannot handle that contract, retain its existing owned integration and report the compatibility limitation. Two clients with different accounts must receive isolated catalogs without a globally admitted main account.

Refresh every configured, admitted account independently in matching client contexts. Primary supplies default rows, labels, controls, and suggested defaults; account-qualified views retain their own descriptors. An expandable Available on other pooled accounts group exposes compatible choices absent from primary, identifying source and coverage without claiming a primary grant. These remain normal pooled choices among supporting members: a donor annotation must not set fixedAccount. Only an explicit account selection binds the request. If primary is unavailable, show that state and matching stale data rather than substitute the last routing account.

A UI selection resolves its chosen primary default as explicit intent before eligibility, preventing pooled defaults from changing that choice. This must not write global defaults, change saved selections, or insert controls omitted by existing/third-party requests. Those retain their existing omission/default meaning.

The server computes coverage with the same evaluator used by dispatch for the full combination: model, resolved effort, tier, access program, required modality and context. Return the tuple and inventory revision; the badge is an observation, not a durable grant. Changing controls recalculates it.

Indicator in OpenCodex Meaning
Supported by 2 of 4 pooled accounts Keep selectable; strategy uses confirmed supporting members.
2 confirmed · 1 unsupported · 1 unconfirmed Refusal/incompatibility differs from stale, failed, incomplete or unknown discovery.
2 supported · 1 ready now Quota, cooldown, pauses, reauthentication and circuit state are readiness, not capability.
No eligible account ready / Availability unconfirmed Explain without silently downgrading or asserting unknown accounts are ineligible.

Count distinct identities in current persistent pool membership/plan-exclusion policy, including main only if configured, before temporary readiness filters. Do not count all stored accounts, GUI cards or aliases. Configuration changes recompute membership; unadmitted credentials are not probed and remain unconfirmed unless matching support is known. Detail uses existing account aliases, observation times and upstream reasons. Direct/fixed views describe only their bound account.

Current official guidance offers GPT-6 Astra Ultrafast on Pro $500 and eligible Enterprise/Edu plans subject to workspace and other conditions. That illustrates why plan names/prices cannot grant access: use exact discovered capabilities and binding, and distinguish billing multipliers from generation speed. Coverage belongs in OpenCodex's UI; stock Codex receives supported descriptors, with optional description hints where possible, not a promised new badge or composer widget.

Eligibility, pooling, and retries

Treat roster evidence as version-scoped advertisement: presence establishes that context; omission is not universal denial. Keep actual client-version/filter observations separate. Use the caller's exact version or verified selected runtime; never raise an actual inbound version. Retain the measured legacy floor workaround for implicit/background discovery until equivalent scoped completeness and omission behavior replaces it, recording the effective query version separately. An unknown headless version cannot establish definitive absence. Never union accounts into a synthetic capability row. Different limits require a conservative eligible-set limit or narrowed/sticky account group; if a combination cannot be represented, expose an explicit intersection/account-specific option.

Extend the modelEligibleAccountIds seam to strict full-combination eligibility and reassert it after fixed, affinity, fallback and alternate-account resolution. Do not use deniedModelAccountIds for restricted access: it is a soft preference that may restore candidates when a pool empties.

Existing strategies, priorities and usability checks continue within the eligible subset. Every newly discovered generic model requires affirmative matching scoped support per account, including its baseline request; another account's unconfirmed roster is uncertainty, not eligibility or explicit denial. Preserve permissive ordinary flagship fallback only as bounded existing legacy compatibility when evidence is stale, incomplete or from an older version; do not extend it routinely to new ordinary/gated IDs. Restricted controls require affirmative scoped support under their freshness policy. Explicit refusal overrides stale support immediately and triggers bounded refresh, scoped to the account/model/control/context.

Carry resolved intent and originating revision through retries, then revalidate current credentials, policy, capabilities and refusals before every send. Newer negatives override earlier positive snapshots; recompute eligibility without changing the requested combination. Preserve affinity, quota scopes, credential generations, state issuer cleanup and bounded account moves. Revalidate detours without resetting every thread or mutating the shared active/pinned cursor. Background discovery neither spends inference retry budgets nor changes routing health as an inference failure.

Preserve fixed-account/upload guards, streaming commitment, non-replayable response guards, same-workspace quota suppression and pool recovery admission. A fixed selection cannot alternate; uploaded files stay on their issuing account. Capability conflict must be explicit, never file migration, tier downgrade or new cross-provider fallback. Provider/history tags, authentication forwarding, login, remote compaction and config backup/restore remain unchanged.

Example: a future descriptor without registration

Suppose primary advertises opaque ID orion/preview-7, label “Orion Preview,” effort deep, and a new string service tier express_plus using the already-supported tier contract. Two of four pool members confirm that exact combination. It appears after refresh with those literal labels and Supported by 2 of 4 pooled accounts; no native list, pin, family regex, context table or i18n key is edited. Choosing it keeps the explicit model/effort/tier intent while existing strategy selects either supporting account and rechecks evidence on retry.

Later, primary changes only the label to “Orion.” Saved IDs/history remain stable; an operator label override still wins with raw upstream text retained. A stock client supporting these strings gets the live projection. An older client receives a compatible file/projection with the unsupported control or affected row explained, while other valid additions survive. It is never silently mapped to Sol, xhigh, or legacy Fast. Main-drain and Reserve behavior still follow explicit local policy, independent of this new membership.

Refresh, persistence, and withdrawal

When native integration is enabled and in use with admitted credentials, discovery should be automatic on startup/initial authenticated use, account/credential or runtime-context changes, and deduplicated background refresh. Preserve optional subsystem activation rather than enabling credential detection by default. Refresh admitted, in-use account/runtime contexts with bounded concurrency and cached-context counts, not every stored credential or historical client version. Start with the existing five-minute success-cache horizon, jitter, bounded bodies/timeouts, version/cache limits, single flights and failure backoff; this cadence is a recommendation to tune by measured cost. Stale reads may trigger refresh without blocking UI. Provide manual refresh. Keep broader all-provider polling opt-in with its existing minimum 15-minute interval; native discovery must not become five-minute full-provider sync.

Fetch outside profile/catalog write locks and release native-main credential leases before network I/O. Immediately before publication, revalidate configuration/credential generations, scope, ownership and evidence across every writer. Late responses from changed identities cannot publish. Hash successful parsed content to avoid churn; conditional requests require source support. Persist bounded last-known-good snapshots with original provenance/schema in private storage, excluding credentials/sensitive logs. Cache/watch triggers must deduplicate, suppress self-written loops, surface failures and recover; local observations never establish grants.

Withdrawal state must include source/transport, account/project, credential generation, client-version/filter context and model ID. The existing provider-scoped helper needs scope adaptation. Three complete successful omissions in the same scope is a reasonable initial presentation grace; other accounts/versions and failed/partial observations do not advance it. Preserve existing retirement decisions. Fresh authenticated reappearance can restore scoped availability; stale cache, pins or custom overrides cannot.

Observation Result
Timeout, authentication failure, malformed root or unexplained empty response Retain matching last-known-good as stale/unconfirmed; no mass retirement or deletion of another account's observations.
Partial response or quarantined row Safe valid additions survive; suppress absence/withdrawal inference.
Complete successful omission Record scoped withdrawal/grace; never global retirement. Explicit refusal removes that route immediately.
Credential/account change during or after fetch Invalidate all versions of old credential scope; no stale grant transfer or late publication.
Policy/refusal changes during outage Reproject current policy over matching source facts; cached successful bytes cannot bypass a disable/deny.

Display and dispatch permission differ. Stale data cannot newly grant restricted controls; existing saved routes need an explicit offline policy and upstream validation. Keep historical identities diagnosable even after withdrawal. One account's failure never invalidates another's correctly scoped result.

Stock-client catalog delivery and compatibility

The native HTTP envelope is {models: [ModelInfo]} with operational snake_case fields; app-server {data: [Model], nextCursor} and basic API model objects are different contracts. Preserve authoritative inventory separately from compatible materialized catalogs. Client profiles cover enum openness, required fields, auth, refresh behavior and response budgets; modelProvider/capabilities/read alone is insufficient.

Use the supported path without changing provider identity:

  1. Logged-in loopback: retain built-in openai and root openai_base_url. Ordinary /models?client_version=… reaches that base with ChatGPT auth in inspected stable/main. Make OpenCodex's existing native envelope dynamic; remove only its owned model_catalog_json after installed-runtime qualification.
  2. Existing supported custom provider: offer authenticated local model_catalog_url. Built-in provider merge rules do not universally allow model_providers.openai to retrofit this field; verify the actual configuration contract.
  3. Older/API-key/authless combinations: retain owned file publication unless live behavior is qualified. Upstream API-key discovery gates and overridden-base restrictions mean a URL alone is insufficient.

A conflicting static assignment selects static behavior. Preserve ownership, atomic writes, backup/restore, history, compaction and login; do not retag sessions merely to obtain discovery. Static managers may require normal reload even after file updates. Stable rust-v0.157.1 has URL configuration, but inspected main has additional explicit-catalog semantics: failures can clear its catalog with no bundled fallback. Do not generalize that behavior to every installed release or guess a universal minimum version.

Serve live projections cache-first from immutable inventory, applying current scope/policy/profile and refreshing asynchronously. The current handler gathers all-provider/native network data, whose eight-second timeout can exceed the inspected explicit URL client's five-second deadline. Remove that gather from response latency. Before static-to-live activation, prefetch/validate a compatible manifest; after restart restore matching snapshots. With no valid snapshot, retain the working file/config path during activation and report bounded unavailability rather than publish a fabricated empty success or wait unboundedly.

Respect the consuming client's limits: inspected main explicit URL is five seconds/one MiB, smaller than upstream fetch allowance. Oversize projections need visible compatibility failure, not silent row loss. Reusable materialized bytes require matching source, credential, policy and client-profile revisions. Keep /v1/catalog shared-byte semantics; negotiate new projections through a separate versioned contract or verified headers. Its importer rejects query parameters, while native /models already has client-version semantics.

Inspected main accepts custom effort strings and string tiers; older clients may have closed effort vocabularies, and modality/program enums remain constrained. Retain all values raw, but disable/omit unsupported controls with explanations in that projection. A row lacking a compatible effort/default or required operational fields stays diagnosable as incompatible rather than borrowing defaults. Unaffected models publish; retain the previous valid catalog only if the whole projection is unsafe. Never substitute an effort without a verified translation. Synthetic selectors need explicit bindings and collision checks against real IDs. Discovery does not change saved models, promote paid tiers, enable programs, or override allowlists, disabled models, caps, newModelPolicy, or tier opt-ins.

Responses to maintainer concerns

Prior discussion concerns narrower scheduler, fallback and client changes; it does not approve or reject this whole proposal. These decisions become design constraints and release checks.

Recorded concern Required response and verification
Unconfirmed rosters should not hide working flagships. Current rationale, September 4 decision Preserve ordinary-model fallback; distinguish uncertainty, withdrawal and explicit refusal. Bootstrap cannot grant new restricted controls. Failed/old/partial rosters must not erase working pools.
Do not advertise invented Ultrafast or claim forwarding proves fulfillment. #2993, #3429 Require authentic scoped descriptors and understood bindings. Keep intent/support/fulfillment separate; no guessed multiplier or silent downgrade. Historical absence is not a ban on genuinely advertised later tiers.
Bound polling and convergence cost. Roadmap, #4584 decision Keep broad refresh opt-in; native single flights/jitter/backoff and unchanged-content detection prevent full sync/churn. Slow unrelated providers cannot block delivery; discovery does not spend inference budgets.
OpenCodex does not own Codex composer widgets. #3255 Put generic controls/coverage in OpenCodex; publish stock-compatible descriptors/files. Unsupported rendering is explicit; preserve existing history/login/compaction without client changes.
Watcher account detection, invalidation races, failure and recovery. #6143 review Scoped observations only, narrow invalidation, self-loop suppression, generation checks and visible recovery. The owner-account post expressly attributes this review to grok-bot; it is review evidence, not a personal maintainer statement.
Visibility is not permission; account/config ownership must survive. #2097, architecture One evaluator governs badges and every attempt. Preserve fixed/upload constraints, admission, credentials and restore; newer negatives override old grants and donor labels never pin pooled choices.

Acceptance and unresolved verification

Case Required observable result
Future non-GPT ID with unique instructions/context/defaults All applicable views and dispatch update after refresh without constants, pins, family rules or Sol inheritance.
New effort/tier label; later display rename Literal labels need no i18n key; ID/history/selection remains stable. Operator presentation override wins with raw label retained.
New nested JSON, literal effort ultra or tier fast Unknown JSON survives bounded internal cache/restart and authorized inventory-compatible export, not unrestricted client projection. A qualified profile preserves exact-wire intent while legacy selections retain their mappings. Ambiguous representation becomes incompatible/metadata-only, not silently remapped.
Closed client enum, missing required field or oversize projection Affected control/row explains incompatibility; unrelated valid additions survive and client budgets remain respected.
Partial pool support or pool-only option Exact combination coverage remains selectable; strategy uses supporting subset without donor pinning. Active rotation does not change primary presentation.
Omitted external controls or differing pooled defaults/limits Existing omissions remain intact; explicit UI intent is stable. Conservative limits or eligible subset avoid accidental default/capability changes.
New model versus legacy ordinary fallback New baseline and controls require matching account support; unconfirmed accounts are not eligible or falsely denied. Bounded legacy fallback survives; older omissions cannot deny another context.
Quota, cooldown, pause or failed discovery Readiness/unknown differs from support and persistent membership denominator. Strategies and quota accounting remain correct within eligible subset.
Retry, token refresh or newer refusal/policy/identity Same intent and budgets; current eligibility wins, with no stale grant, unsupported route or silent downgrade.
Fixed account, upload, committed stream or unsafe replay Existing account/replay guards prevent migration and duplicate execution; continuation cleanup remains correct on allowed moves.
Reserve row and main-drain exceptions Existing authorization/lifecycle behavior survives independently of discovered membership; future-ID drain policy is explicit.
Empty/partial/malformed refresh, withdrawal, credential switch or regain Correctly scoped stale data survives failure; no cross-account deletion/late publication/stale resurrection. Fresh scoped reappearance may restore availability under current policy.
Watcher/manual/background publication races or oversized raw payload No self-loop, broad invalidation or unrelated config churn; failures recover visibly. Depth/string/count and aggregate memory/durable budgets remain bounded.
Live catalog outage/cold start/slow unrelated provider Prompt cached compatible response and current policy; qualified activation never discards a usable static setup for an unbounded fetch.
Older stock client, live integration or two caller-owned accounts Parseable delivery preserves provider/history/login/compaction/restore; reload limits are stated. Ephemeral catalogs stay isolated even without globally admitted main credentials; no required Codex changes.
API-project model or operator restriction No borrowed ChatGPT grant/unsupported Responses claim; raw discovery never overrides user policy.

Most validation should use bounded recorded roster fixtures, followed by authorized end-to-end checks with real accounts and selected stock runtimes. Measure discovery-to-picker latency, projection omissions, refresh cost/failures, revision churn and prevented stale publications. No runtime/account validation was performed for this proposal; pooling compatibility is an architectural conclusion pending these release checks.

Settle during implementation: installed runtime live/file/auth qualification; roster completeness, pagination/ETag/empty semantics and authoritative versus experimental fields; necessity of each legacy transport rewrite; freshness/offline policy for restricted versus existing ordinary routes; explicit future-model main-drain policy; and compatible live negotiation without changing shared-byte contracts. None requires recurring model registration. A separate central metadata service, documentation scraping, automatic custom-ID templating or blind roster passthrough would respectively add dependency, lack account authority, invent traits or bypass existing policy.

Primary references

Repository links above identify source evidence pinned to the analyzed commit. Additional boundaries: observation provenance, unknown main-selector rows, credential lease admission, snapshot currency, commit checks, effort compatibility, strict modality parsing, remote URL validation, injection, built-in/static injection, new-model policy.

Official sources checked September 29, 2026: API model list, app-server discovery, speed modes, Daybreak contract, and model/Ultra controls.

Upstream source was inspected at main 26dd19ef478cfa294406413bafedb84b49f93ea4 and stable rust-v0.157.1, peeled 36650394c5b38c2990ccf2a3457165ca3e9d9726 (September 25). These establish source contracts, not the user's installed behavior:

Contract Pinned source
Native descriptors, instructions and response envelope ModelInfo, validation at line 901.
Ordinary models requests and provider/base merge Endpoint, provider config, root override 651/built-in merge 687.
Stable discovery, static precedence and explicit URL failure Stable endpoint, main provider, main manager, failure clearing 579; stable provider behavior differs at 546.
Explicit URL auth/budgets and API-key gates Main endpoint, auth 121/API-key restriction 213; manager gate.
Open efforts, string tiers and client DTO ReasoningEffort, tiers 227; app-server DTO, output 119; tier menu.

Inspected app-server model/list uses OnlineIfUncached, not force refresh; a separate worker runs every 270 seconds and the manager has a five-minute TTL. Its ETag handling does not establish conditional-request support for every source. OpenCodex's inventory lifecycle must remain explicit.

Checks

  • I searched existing issues and documentation.
  • This request describes a concrete OpenCodex workflow rather than merely naming a desired technology.
  • I removed secrets and personal data.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    account-poolOAuth, credentials, Codex pool, quota, failover, planscatalogModel catalog, slugs, visibility, routed entriesenhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions