Input and method
No API key, account, model, billing, upload, or arbitrary endpoint input.
Inspect narrow browser and probe-region observations for one server-selected public service fixture.
No API key or billable call is used; model access, quota, and real SSE remain outside this check.
API DNS
Not observed
openai_unauthenticated_gateway
API TLS
Not observed
openai_unauthenticated_gateway
Credential-free HTTP
Not observed
openai_unauthenticated_gateway
Codex sign-in
Not observed
codex_login_entry
Codex service entry
Not observed
codex_login_entry
WebSocket
Not observed
codex_websocket_observation
openai_api_codexThere are no target or credential fields. The server selects business-targets-v1.
Ready
No assessment has been created.
No aggregate conclusion (unknown)
The service and target IDs are closed. No URL, account, Cookie, API key, subscription, model, title or private risk input is accepted. Evidence does not establish availability.
Check the public API gateway, Codex sign-in, and realtime network paths without an API key.
No API key, account, model, billing, upload, or arbitrary endpoint input.
API DNS, TLS, and unauthenticated HTTP authentication response remain separate from Codex sign-in and WebSocket observations.
A 401 can prove only that an authentication layer answered; it does not validate a key, quota, model, billing, SSE, or task execution.
Check the public API gateway, Codex sign-in, and realtime network paths without an API key.
No API key, account, model, billing, upload, or arbitrary endpoint input.
API DNS, TLS, and unauthenticated HTTP authentication response remain separate from Codex sign-in and WebSocket observations.
A 401 can prove only that an authentication layer answered; it does not validate a key, quota, model, billing, SSE, or task execution.
Input is used only for this explicit check. A 401 can prove only that an authentication layer answered; it does not validate a key, quota, model, billing, SSE, or task execution.
Run it again after the relevant network, address, browser environment, or target changes. API DNS, TLS, and unauthenticated HTTP authentication response remain separate from Codex sign-in and WebSocket observations.