AI
Connect AI access
Connect ChatGPT or OpenAI API access for Codex and project code.
What AI credentials are for
CoCalc-ai uses OpenAI access for integrated Codex chat. A user can connect a ChatGPT subscription or configure an OpenAI API key, depending on what access the deployment and account support.
Connect access for Codex
- Open Codex or the AI settings area.
- Choose Sign in with ChatGPT or configure an OpenAI API key.
- Complete the device authorization or key setup flow.
- Return to the Codex thread and start a concrete task.
If device authorization is running, keep the authorization panel visible until the browser confirms that the account is connected.
Choose the payment source for a thread
Connecting credentials makes them available. On hosted CoCalc, each thread can choose how its future turns are funded.
- Open Codex settings using the Codex control. On phones, tap the button showing the model and reasoning level in the chat header.
- Choose a payment source and click Save. ChatGPT Plan, Project OpenAI API key, and Account OpenAI API key appear when configured. CoCalc Membership is available only when the site and account provide an included allowance.
- Check Payment source in Codex settings before submitting work.
Automatic prefers your ChatGPT plan, then the project API key, account API key, and membership allowance. You can continue an established session using ChatGPT or a personal API key without losing its context. Switching an established personal session to membership funding is disabled: start a new chat for the membership's constrained model profile. Returning from an explicit source to Automatic is also disabled after a session starts.
In Lite, configure a ChatGPT plan or an OpenAI API key in account AI settings; if both are configured, Lite uses the ChatGPT plan.
Check usage and recover a failed sign-in
Open account AI settings to inspect the connection. ChatGPT Codex usage appears when ChatGPT Plan is the resolved payment source. Click Refresh usage to request a live check. Meters show the percentage remaining and reset timing for each reported usage window; they are not a per-thread spending total. Missing or unchecked usage data does not mean the allowance is zero. The displayed account and plan help identify the connection. Hosted usage checks and device sign-in need an available project; open one when prompted and retry.
Connection not verified means a stored credential was found but the live check did not confirm access. Sign-in needs refresh means that connection needs attention before Codex can use it.
- For an expired-authentication error, choose Sign in again, or update the OpenAI API key used by the thread.
- Refresh usage or check the connection status again.
- Return to the failed message and use Submit again when offered.
An allowance error is different from an expired sign-in. Follow its Open AI Settings or usage link and check the thread's selected payment source. Membership-funded access depends on the deployment and account; connecting a personal plan does not increase the membership allowance itself.
For unavailable-model messages, see Configure Codex chats.
Use project secrets for keys
For code that calls OpenAI directly from a notebook, script, or terminal, store
the API key as a project secret such as OPENAI_API_KEY. Do not paste keys
into notebooks, chat messages, shell history, or committed files.
Complete a Codex authorization request
On sites that enable this workflow, a sensitive CoCalc CLI action can show Codex needs fresh account authorization in the chat, with the status Waiting for authorization.
- Keep the originating CoCalc browser tab open and choose Approve in CoCalc on the card.
- In the authorization page, check the account shown. Follow any instruction to sign in with that account.
- Use an available verification method and choose Approve CLI Elevation. Complete password or second-factor verification on that page.
- Return to the chat and inspect the result. The waiting integrated CLI command retries automatically after approval, so check its state before requesting another attempt.
Acknowledge and Snooze 5 minutes manage the notification; they do not authorize the action. An ordinary chat reply or question response also does not complete this verification. Keep passwords and verification codes out of chat.
If the request is canceled or expired, inspect the command's reported state before asking Codex to try again. This card is conditional on site support; it is not available for every command or deployment.
Why this matters in CoCalc
AI access is both account-level and project-contextual. The account connection lets Codex work in the UI; project secrets let ordinary code and terminal-native agents use credentials without turning private tokens into shared content.