mirror of
https://github.com/openai/codex.git
synced 2026-08-30 14:19:08 +00:00
## Why App-server clients can report whether Amazon Bedrock is using AWS-managed credentials or a Codex-managed API key, but they do not have a matching API for creating the managed login. This PR defines that experimental wire contract independently from its implementation. Managed Bedrock API keys are already a primary `CodexAuth` mode. The API therefore describes a normal Codex login that replaces the current stored auth rather than introducing provider-scoped credential storage. ## What changed - Add the experimental `amazonBedrock` variant to `account/login/start`. - Accept an API key and AWS region and return a matching discriminated response. - Gate the request behind the app-server `experimentalApi` capability. - Regenerate the JSON and TypeScript protocol schemas. - Document the login contract, notifications, primary-auth replacement semantics, restart boundary, and non-transactional durable writes. ## Impact This PR defines the API shape but does not implement login behavior. The next PR adds validation, persistence through the existing Codex auth lifecycle, provider selection, and notifications. ## Validation - `just test -p codex-app-server-protocol` ## Stack 1. **#31327 Managed Bedrock experimental API** — base: `main` 2. #31326 Managed Bedrock login — base: `codex/managed-bedrock-api` 3. #31325 Managed Bedrock logout — base: `codex/managed-bedrock-login-v2`