Repository navigation
Multi Codex v2.4.5
Multi Codex v2.4.5
Open each account in VS Code, the standalone Codex app, or both. Each target uses that account's existing isolated Codex home; standalone cookies and app state use a separate desktop-data directory. Existing accounts, profile paths and the global Codex login remain in place.
A simple first-run welcome detects the platform and installed apps. When both launch targets are usable, Launch settings offers VS Code only, Codex app only and Both; Both shows two launch buttons per account. With one usable app, the choice is hidden and that app is selected automatically. Existing installations initially keep their VS Code launch preference. New installations with both verified apps start with Both. Detection runs again at startup, in settings and before launch.
Preferred folder + Browse uses the built-in folder picker. Executable paths and global Codex home stay under Advanced. Linux users can turn off the desktop picker; Mac users never see the desktop toggle or desktop picker, and launch on the current desktop. A repeated VS Code launch opens another window. A repeated standalone launch uses that account's own desktop instance.
Two different disposable accounts passed native standalone credential reuse, refresh, logout, peer isolation and signed-out restart checks on Linux and a Mac GitHub runner. The standalone launch option is enabled only for Codex desktop version 26.930.51102 on Linux x86_64 and Apple Silicon macOS; unknown versions stay disabled until tested. The sanitized isolation evidence records the completed checks without credentials.
The launch path preserves the browser's normal HOME, uses private short aliases for long Mac profile paths, and discovers the CLI bundled with the standalone app when needed. Editing, deletion and cache cleanup are guarded while either app uses an account. A deliberate standalone sign-out remains signed out; a later usage check cannot silently restore stale keyring credentials. These changes protect existing account data during launch and refresh.
On Linux, window detection recognizes the exact database lock held by Codex desktop after Electron rewrites its process arguments. This fixes the false “window could not be identified” error after a successful launch; placement retries still reuse the already opened window.
Launches preserve existing per-account Codex settings. Credential and sign-out writes are atomic, and cache cleanup refuses linked paths into another account.
Local frontend and Rust suites, production frontend build, formatting, packaging and installer checks passed. Mac native CI also passed Keychain and VS Code checks, launched the official standalone app twice with private paths containing spaces and Unicode, observed an on-screen native window, and built and inspected the Apple Silicon app/DMG. These CI fixtures are separate from the authenticated isolation run.
The release build completed all four packages and checksums. The downloaded AppImage passed real native button clicks, folder selection, all three launch choices, restart, live limits, desktop placement and repeat-window behavior on Arch/Hyprland. A running-profile delete was refused after restarting the launcher. The local upgrade preserved all six saved account records and credential files; a full backup and consistent SQLite snapshots were retained. Sanitized local package and upgrade evidence
VS Code needs the official Codex extension installed inside each isolated VS Code profile. The standalone version allowlist remains 26.930.51102; the newer 26.930.61225 has not completed authenticated isolation verification. Mac CI uses the pinned official archived build.
Published at the repository owner's request using the exact tested packages. The Mac DMG has no Apple Developer ID signature and is not notarized. The README Mac commands explicitly opt into the checksum-verified unsigned package; the installer applies a local ad-hoc signature if needed, and macOS still controls first-open approval. Apple's Open Anyway instructions
The actual DMG install and update passed on a Mac runner, including unsigned-install rejection, explicit opt-in, signature integrity, installed app startup/restart, staging cleanup and unchanged account/chat sentinels. Installer evidence
The same run passed AppImage install/update on Ubuntu, verifying the exact installed asset and preserved account/chat and default-login sentinels. These installer tests use the original release-build packages and substitute draft release URL resolution before publication. Native Linux launch and authenticated isolation checks are separate. Linux installer evidence
Install and update scripts are included in the release and its checksums. README commands follow the latest release automatically. Publication requires successful Linux/Mac builds, installer verification, authenticated isolation and all six asset hashes. Developer ID signing and notarization are optional and were not performed. Broader installed-package checks remain pending in the validation manifest. Platform support and validation details
The publication workflow passed and published v2.4.5 as the latest stable release. GitHub's latest-release API and redirect were verified, and both live public Linux README scripts preserved six disposable account/chat fixtures during install/update. Publication evidence. End-user macOS first-open approval was not automated.