GPTsAppCodex Reset
Menu

Codex capability diagnosis

Why does Codex keep asking for permission?

Include the exact action, approval/policy message, surface, and whether the prompt returns in a new session.

Local redaction. Save only by choice.

Paste the first useful error/status or describe the last thing that worked and the first thing that failed.

Import local evidence
0 / 32,768
Which capability?
Collect private diagnostics locally

Raw text stays in this browser. Only the sanitized preview is submitted. The diagnosis is not stored unless you explicitly save a private report.

Optional context Improves surface and version boundaries

Diagnosis workspace

Not checked

Evidence in.
One useful next step.

Your result appears here after you review and submit the sanitized evidence.

First supported boundary
Waiting for evidence
Next check
Not selected yet
Private report
Not created
Worked example — not your diagnosis Authorization A compact output computed by the current deterministic ruleset. AUTHORIZED

Example evidence

The capability action works after approval, but Codex asks for the same permission every time I open a new session. The approval does not persist across reopen.
Result Authorization · AUTHORIZED

The earliest supported failure is authorization: the capability is reachable or activated, but the requested action is not allowed by the current provider scope, workspace policy, approval, or sandbox boundary.

Why this boundary

The supplied evidence explicitly names forbidden/denied access, a missing scope/role, or approval that does not persist.

Next safe check Record the exact denied action and retry only that safe action

Separate authentication from workspace policy, approval lifetime, sandbox, or command-rule authorization.

Method and limits

A capability chain, not an AI guess

Deterministic rules over your redacted evidence. What the tool cannot support, it declines to claim.

Earliest supported layer

Rules distinguish availability, discovery, parsing, configuration, dependency, connection, authentication, registration, exposure, activation, authorization, execution, and persistence.

Evidence before verdict

A rule must meet a deterministic threshold. Conflicting or incomplete evidence becomes partial or unknown; it is not converted into a confident root cause.

No unknown execution

The site does not install capabilities, execute packages, contact private endpoints, edit configuration, or ask for credentials.

Private by explicit choice

A diagnosis is stateless by default. Saved reports use random URLs, expire after seven days, can be deleted immediately, and are excluded from indexing.