mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-03 16:11:17 +08:00
* feat(sandbox): expose services during creation Signed-off-by: Drew Newberry <anewberry@nvidia.com> * feat(providers): refresh Codex credentials in gateway Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(cli): normalize create-time service URLs Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(server): roll back failed service exposure Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(example): simplify Codex provider setup Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(example): separate provider setup commands Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(sandbox): harden create-time service exposure Signed-off-by: Drew Newberry <anewberry@nvidia.com> * docs(example): bundle Codex provider profile Signed-off-by: Drew Newberry <anewberry@nvidia.com> * fix(example): allow npm-installed Codex binary Signed-off-by: Drew Newberry <anewberry@nvidia.com> --------- Signed-off-by: Drew Newberry <anewberry@nvidia.com>
70 lines
2.0 KiB
YAML
70 lines
2.0 KiB
YAML
# SPDX-FileCopyrightText: Copyright (c) 2025-2026 NVIDIA CORPORATION & AFFILIATES. All rights reserved.
|
|
# SPDX-License-Identifier: Apache-2.0
|
|
|
|
# Provider profile for the Codex app-server example. The gateway owns refresh
|
|
# material and injects opaque handles for the access token and account ID.
|
|
|
|
id: codex
|
|
display_name: Codex
|
|
description: OpenAI Codex CLI with gateway-managed token refresh
|
|
category: agent
|
|
inference_capable: true
|
|
credentials:
|
|
- name: access_token
|
|
description: Codex OAuth access token refreshed by the gateway
|
|
env_vars: [CODEX_AUTH_ACCESS_TOKEN]
|
|
required: true
|
|
auth_style: bearer
|
|
header_name: authorization
|
|
refresh:
|
|
strategy: oauth2_refresh_token
|
|
token_url: https://auth.openai.com/oauth/token
|
|
refresh_before_seconds: 300
|
|
max_lifetime_seconds: 3600
|
|
material:
|
|
- name: client_id
|
|
description: Codex OAuth client ID
|
|
required: true
|
|
- name: refresh_token
|
|
description: Codex OAuth refresh token
|
|
required: true
|
|
secret: true
|
|
- name: refresh_token
|
|
description: Codex OAuth refresh token for clients that manage their own refresh
|
|
env_vars: [CODEX_AUTH_REFRESH_TOKEN]
|
|
- name: account_id
|
|
description: Codex account identifier
|
|
env_vars: [CODEX_AUTH_ACCOUNT_ID]
|
|
required: true
|
|
- name: id_token
|
|
description: Codex OAuth ID token
|
|
env_vars: [CODEX_AUTH_ID_TOKEN]
|
|
discovery:
|
|
credentials: [access_token, refresh_token, account_id, id_token]
|
|
endpoints:
|
|
- host: api.openai.com
|
|
port: 443
|
|
protocol: rest
|
|
access: read-write
|
|
enforcement: enforce
|
|
- host: auth.openai.com
|
|
port: 443
|
|
protocol: rest
|
|
access: read-write
|
|
enforcement: enforce
|
|
- host: chatgpt.com
|
|
port: 443
|
|
protocol: rest
|
|
access: read-write
|
|
enforcement: enforce
|
|
- host: ab.chatgpt.com
|
|
port: 443
|
|
protocol: rest
|
|
access: read-write
|
|
enforcement: enforce
|
|
binaries:
|
|
- /usr/bin/codex
|
|
- /usr/local/bin/codex
|
|
- /usr/lib/node_modules/@openai/**
|
|
- /usr/local/lib/node_modules/@openai/**
|