Codex Account Switch
An Omarchy Quattro bar widget for switching between locally saved Codex desktop accounts. It preserves refreshed credentials, closes Codex cleanly, changes the active account, and reopens the app.
Install
omarchy plugin add https://github.com/brandonwhitfield/codex-account-switch.git --enable
The widget is placed in the right section of the bar by default. Move it with:
omarchy bar move io.github.brandonwhitfield.codex-account-switch --section right
Requirements
- Omarchy with the Quattro shell plugin system
- The Codex desktop app (
/usr/bin/chatgpton the current Omarchy package) - Python 3.10 or newer
wofifor naming the currently active accountomarchy-launch-floating-terminal-with-presentationfor isolated account login
The helper first checks the current Omarchy Codex desktop paths, then falls
back to codex, chatgpt, or codex-desktop on PATH. Custom installations
can set CODEX_ACCOUNT_SWITCHER_CODEX_BIN and
CODEX_ACCOUNT_SWITCHER_APP_BIN.
Usage
- Click the account icon and choose Update active account to save the account currently open in Codex.
- Choose Add another account, name it, and complete the isolated browser login in the terminal that opens.
- Do not log out of Codex to add another account. Logging out can revoke the refresh token in a previously saved snapshot.
- Select a saved account and confirm Switch & reopen.
Right-clicking the bar icon updates the active account snapshot. Keyboard
shortcuts inside the panel are A to add an account, U to update the active
account, and R to refresh.
Credential storage and security
This plugin handles Codex OAuth credentials. It stores account snapshots in:
~/.local/share/codex-account-switcher/
Directories use mode 0700; the index, lock, and credential files use mode
0600. Tokens are not printed, placed in plugin configuration, or passed as
command-line arguments. Storage operations reject symlinks, non-regular files,
unexpected owners, and hard-linked files. Writes use descriptor-relative,
atomic replacement, and the lock is opened with no-follow and exclusive-create
semantics.
The files are protected by Unix permissions but are not additionally encrypted. Any process running as your user can potentially read them. Review the source before installing; Omarchy plugins execute unsandboxed.
Account switching targets only the current user's Codex desktop executable;
Codex CLI and agent sessions are excluded. The helper captures the desktop
process UID, executable, and /proc start time, opens a Linux pidfd, revalidates
the identity, and only then sends SIGTERM. It never uses SIGKILL. If the
desktop process is replaced or does not close within eight seconds, credentials
are left unchanged.
Account labels reject markup delimiters, and every account-derived QML display
uses Text.PlainText so labels cannot trigger rich-text resource loading in the
shared shell process.
Remove
Remove the plugin code and bar entry:
omarchy plugin remove io.github.brandonwhitfield.codex-account-switch
Saved account credentials are deliberately retained so an uninstall cannot silently destroy user data. To permanently delete them too, close Codex and remove this exact directory:
rm -rf -- "$HOME/.local/share/codex-account-switcher"
Development
python3 test_helper.py
python3 -m py_compile bin/codex-account-switcher
omarchy plugin validate .
qmllint -I /usr/share/omarchy/shell Panel.qml