Omahub
← All plugins
B

Codex Account Switch

by Brandon Whitfield

Switch between locally saved Codex accounts from the Omarchy bar.

Security review

No obvious issues detected

Deterministic scan — not a security guarantee

None
Risk level
None
Analyzed commit
21023f9
Scanned
1 month ago

No potentially dangerous behavior detected in the analyzed commit.

Automated analysis only — not a security guarantee.

AI advisory review

No obvious issues detected

Language-model assessment · ~deepseek/deepseek-v4-flash-latest — advisory only

Low
AI risk level
Low
Recommendation
install
Model
~deepseek/deepseek-v4-flash-latest
Analyzed commit
21023f9
Reviewed
1 month ago

The plugin is well-engineered with strong security practices: it uses O_NOFOLLOW, dir_fd, atomic writes, strict permission checks, and process identity validation via pidfd before terminating processes. It also sanitizes labels to prevent QML injection. The only notable risk is that stored OAuth tokens are not encrypted, but this is explicitly documented and is a user-environment limitation rather than a plugin vulnerability.

  • Credentials are stored unencrypted (though with 0600 permissions) and any process running as the user could potentially read them.
  • The helper relies on environment variables (CODEX_ACCOUNT_SWITCHER_CODEX_BIN) which could be overridden by a malicious user, but this is not a plugin-specific risk.
How this check works

This review combines the deterministic scan (the rule-based results above) with an independent look at the plugin's code by a language model. The model reads a trimmed sample of the repository's files, the manifest, and the README, then gives a plain-language risk level and a recommendation: install (no notable danger), review (look closer first), or avoid (clearly dangerous).

It runs on the same analyzed commit as the deterministic scan and is strictly advisory — it is not a security guarantee and never blocks a plugin by itself. A human moderator still reviews plugins before they are listed.

AI advisory only — automated analysis, not a security guarantee.

Install
$ omarchy plugin add https://github.com/brandonwhitfield/codex-account-switch --enable
Widgets #bar #quickshell #ai

Codex Account Switch

An Omarchy Quattro bar widget for switching between locally saved Codex desktop accounts. It preserves refreshed credentials, closes Codex cleanly, changes the active account, and reopens the app.

Install

omarchy plugin add https://github.com/brandonwhitfield/codex-account-switch.git --enable

The widget is placed in the right section of the bar by default. Move it with:

omarchy bar move io.github.brandonwhitfield.codex-account-switch --section right

Requirements

  • Omarchy with the Quattro shell plugin system
  • The Codex desktop app (/usr/bin/chatgpt on the current Omarchy package)
  • Python 3.10 or newer
  • wofi for naming the currently active account
  • omarchy-launch-floating-terminal-with-presentation for isolated account login

The helper first checks the current Omarchy Codex desktop paths, then falls back to codex, chatgpt, or codex-desktop on PATH. Custom installations can set CODEX_ACCOUNT_SWITCHER_CODEX_BIN and CODEX_ACCOUNT_SWITCHER_APP_BIN.

Usage

  1. Click the account icon and choose Update active account to save the account currently open in Codex.
  2. Choose Add another account, name it, and complete the isolated browser login in the terminal that opens.
  3. Do not log out of Codex to add another account. Logging out can revoke the refresh token in a previously saved snapshot.
  4. Select a saved account and confirm Switch & reopen.

Right-clicking the bar icon updates the active account snapshot. Keyboard shortcuts inside the panel are A to add an account, U to update the active account, and R to refresh.

Credential storage and security

This plugin handles Codex OAuth credentials. It stores account snapshots in:

~/.local/share/codex-account-switcher/

Directories use mode 0700; the index, lock, and credential files use mode 0600. Tokens are not printed, placed in plugin configuration, or passed as command-line arguments. Storage operations reject symlinks, non-regular files, unexpected owners, and hard-linked files. Writes use descriptor-relative, atomic replacement, and the lock is opened with no-follow and exclusive-create semantics.

The files are protected by Unix permissions but are not additionally encrypted. Any process running as your user can potentially read them. Review the source before installing; Omarchy plugins execute unsandboxed.

Account switching targets only the current user's Codex desktop executable; Codex CLI and agent sessions are excluded. The helper captures the desktop process UID, executable, and /proc start time, opens a Linux pidfd, revalidates the identity, and only then sends SIGTERM. It never uses SIGKILL. If the desktop process is replaced or does not close within eight seconds, credentials are left unchanged.

Account labels reject markup delimiters, and every account-derived QML display uses Text.PlainText so labels cannot trigger rich-text resource loading in the shared shell process.

Remove

Remove the plugin code and bar entry:

omarchy plugin remove io.github.brandonwhitfield.codex-account-switch

Saved account credentials are deliberately retained so an uninstall cannot silently destroy user data. To permanently delete them too, close Codex and remove this exact directory:

rm -rf -- "$HOME/.local/share/codex-account-switcher"

Development

python3 test_helper.py
python3 -m py_compile bin/codex-account-switcher
omarchy plugin validate .
qmllint -I /usr/share/omarchy/shell Panel.qml

License

MIT