Codex was working, you changed nothing, and suddenly every message comes back with unexpected status 401 Unauthorized: Incorrect API key provided. Worse: you don't even use an API key, you signed in with your ChatGPT account. This error has three very different causes, and only one of them can be fixed on your machine. The fastest way to tell them apart is the masked piece of the key printed in the error itself.
What does the 401 "Incorrect API key provided" in Codex mean?
It means OpenAI's server rejected the credential sent with the request. The full message usually looks like this:
unexpected status 401 Unauthorized: Incorrect API key provided: sk-svcac***...fvMA.
You can find your API key at https://platform.openai.com/account/api-keys.,
url: https://chatgpt.com/backend-api/codex/responses
The detail that decides everything is the masked key after provided:. It tells you which credential was rejected. If it is not one of your keys, the problem is not on your computer, and resetting passwords, logging out or wiping config will not help.
How can you tell in 30 seconds whether it is you or OpenAI?
Compare the suffix of the masked key with what Codex thinks it is using. Two commands are enough:
codex login status
env | grep -E '^(CODEX|OPENAI)_'
The first prints Logged in using ChatGPT or Logged in using an API key - sk-proj-***abcde (the first 8 and last 5 characters of the stored key). The second shows whether any key is exported in your shell. With that in hand, the table below points to your case:
| What you see | Cause | What to do |
|---|---|---|
Key starts with sk-svcac and status says Logged in using ChatGPT | Failure on OpenAI's side | Check status.openai.com and wait |
Only codex exec fails, interactive codex works | CODEX_API_KEY exported in your shell | unset CODEX_API_KEY |
| The rejected key suffix matches your stored key | Key revoked or deleted in the dashboard | codex logout and log in again |
The rejected key starts with sk-svcac: what happened?
It is a service key belonging to OpenAI, not to you. That is what happened on 09/25/2026: from about 22:40 to 23:54 UTC, every Codex call from ChatGPT-authenticated users came back with the same sk-svcac…fvMA, on Mac, Windows and Linux. OpenAI logged the incident as "Issues with Codex" on its official status page, affecting Codex Web, CLI, the VS Code extension and the API, and declared full recovery at 23:54.
In issue #48237, with more than 90 comments, dozens of people confirmed that nothing local fixed it: codex logout followed by login, a clean CODEX_HOME, reinstalling the app, rotating the key. One user showed that the OAuth token itself worked on GET /backend-api/codex/models and only failed on POST /backend-api/codex/responses. The rejected credential was being swapped on the server.
What to do in this case:
- Open
status.openai.com. If there is an open Codex incident, that is it. - Do not rotate or delete your key: it is not the key in the message.
- If you cannot wait, the workaround OpenAI itself posted during the incident was signing in with an API key, which bills per token on your platform account, outside your ChatGPT plan:
printenv OPENAI_API_KEY | codex login --with-api-key
Once the incident closes, go back to the normal login with codex logout and codex login, or you will keep paying per token without noticing.
Only codex exec returns 401 and interactive codex works: why?
Because there is a CODEX_API_KEY in your environment, and codex exec gives it priority over your ChatGPT login. This is in the Codex source code (codex-rs/login/src/auth/manager.rs), with the literal comment "API key via env var takes precedence over any other auth method". codex exec turns that lookup on; interactive codex and codex login status do not.
The practical effect is sneaky: codex login status answers Logged in using ChatGPT, the interactive terminal works, and your CI script or alias using codex exec breaks with a 401 using an old key left in a .bashrc, a .env or a pipeline secret.
# check whether the variable is set
env | grep -E '^(CODEX|OPENAI)_'
# remove it from the current session
unset CODEX_API_KEY
# test again
codex exec "Reply only: OK"
If the test passes, find where the variable is exported (grep -rn CODEX_API_KEY ~/.bashrc ~/.zshrc ~/.profile) and remove it or replace it with your current key.
The suffix is your own key: how do you fix it?
Then the key stored in Codex was revoked, deleted, or belongs to a project without access. It happens to people who ran codex login --with-api-key months ago and later cleaned up keys in the platform dashboard. codex login status shows the end of the stored key, so you can compare it directly with the suffix in the error.
codex logout
codex login # back to ChatGPT login
# or, to keep using an API key:
printenv OPENAI_API_KEY | codex login --with-api-key
--with-api-key reads the key from standard input, not as an argument. If you type codex login --with-api-key alone in the terminal, it tells you it expects the key through a pipe.
What if none of the three cases match?
Run the local diagnostic and keep the output:
codex doctor --json
It shows the stored auth mode (stored auth mode), whether a key or ChatGPT token is stored (stored API key, stored ChatGPT tokens) and whether OPENAI_API_KEY or CODEX_API_KEY are present in the environment, without leaking the value. That lets you open an issue without exposing secrets.
Worth knowing: even after OpenAI declared the 09/25 incident resolved, isolated reports of the same sk-svcac showed up in issue #48237, one on 09/26 in the VS Code extension after hitting the usage limit and another on 09/28 on a Raspberry Pi with CLI 0.158.0. As of 09/29/2026 no maintainer had replied to either. If that is your case, attach the codex doctor --json output to the open issue instead of creating a new one.
When the 401 comes from the server, nothing on your machine fixes it, and the downtime is the same for everyone. What changes the damage is having a second coding agent ready in the terminal. Verboo Code runs in the terminal with unlimited tokens and keeps the work going while your main provider comes back.



