The outage named the boundary.
OpenAI marked a Codex outage at 22:58 UTC on September 25. Twenty minutes later, its status page said API-key login would unblock access. OpenAI marked all affected services recovered at 23:54 UTC.[1] The incident lasted 55 minutes and 53 seconds. It was an identity-route failure with a documented alternate path, not proof that every Codex surface or every model provider failed.
The Hacker News item preserved the incident URL and discussion ID while the event was active.[2] That trail matters because status headlines age fast. The final incident record now says resolved.
An API key changes the bill and the rules.
OpenAI's Codex authentication docs describe two local sign-in methods: ChatGPT and API key. The docs say API-key use follows the API organization's data settings and standard API pricing. Some workspace and cloud-dependent capabilities are limited or unavailable.[3]
A bypass that changes billing, policy, and available capabilities needs its own test card.
Do not discover that difference during an outage. Confirm the account, spend cap, allowed models, credential storage, and minimum task while the main route still works. Never paste the key into a repository, issue, or handoff note.
Local compatibility is a limp-home lane.
Ollama documents a local server that accepts a subset of the OpenAI API at http://localhost:11434/v1/. Its page includes chat-completions and Responses examples, and it lists unsupported cloud features.[4] A compatible endpoint can reduce adapter work. It does not make a small local model equivalent to a hosted coding agent.
Choose one bounded fallback job. Good candidates include summarizing a local diff, drafting a commit message, explaining a test failure, or extracting a checklist. Record the model, memory fit, latency, missing tools, and output limits. That is a continuity route. Pretending feature parity is not.
Run the drill while everything is green.
- Freeze or stash the work so the repository remains the durable state.
- Write a handoff with the goal, changed files, last command, result, and next safe action.
- Test API-key login on a low-risk task and record the separate billing route.
- Test one local model on the same bounded task, then record where it falls short.
The drill is complete only after somebody runs both alternate routes and records the result. The switch below prepares that drill card. It does not test credentials, models, or recovery.