Add an OAuth-based path to run Strix on a user's ChatGPT Plus/Pro
subscription instead of a metered API key, modeled on OpenAI's Codex CLI.
Auth:
- strix/auth: Codex OAuth login (authorization-code + PKCE), a 0600 token
store, refresh-on-expiry, and an AsyncOpenAI client that routes inference
through the ChatGPT backend (chatgpt.com/backend-api/codex) with a
per-request auth hook so long scans survive token expiry.
- `strix auth login|logout|status` CLI (browser loopback on :1455 with a
manual-paste fallback); STRIX_AUTH_MODE=subscription persisted to config.
Inference wiring:
- Subscription branch in configure_sdk_model_defaults installs the Codex
client and the Responses API.
- _CodexResponsesModel always streams (the backend rejects non-streamed
requests) and aggregates back for the non-streaming get_response path.
- store=false + encrypted reasoning for the stateless backend; models
coerced to plan-available names (default gpt-5.4 — 5.5+ apply stricter
content moderation that interferes with security testing).
UX / reporting:
- Track tokens but report $0.00 in the TUI, completion panel, and web
viewer run details; record auth_mode in run.json and PostHog/Scarf.
- Graceful, actionable errors for unavailable models and expired sign-in.
- Restyled OAuth callback page (Strix branding + link to strix.ai).
Tests: PKCE/URL/redirect parsing, token refresh + account-id, streaming
aggregation, cost zeroing, CLI routing/provider aliasing.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>