Naming map
Implicit agent runtime
When provider/modelagentRuntime policy is unset or auto, OpenAI’s
provider-owned route policy chooses the implicit runtime from the effective
endpoint and adapter:
Valid model-scoped
params.fastMode / params.fast_mode, cutoff, and thinking
values are typed agent-runtime controls, not authored provider request params.
Affirmative reasoning support and native reasoning-effort metadata also preserve
Codex selection. See Runtime selection
for the supported capability values and the request overrides that remain protected.
An explicit agentRuntime.id: "openclaw" keeps a Codex-eligible route on
OpenClaw. Explicit agentRuntime.id: "codex" requires a registered Codex harness;
unsupported routes/auth fail closed, except that authored request overrides may
use Codex’s declared exact-request OpenClaw fallback before execution. Inspect
the completed result’s actual harness when a recipe depends on native execution.
Runtime selection does not change credential type or billing: Platform API-key
auth and ChatGPT/Codex subscription auth remain distinct.
openclaw doctor --fix migrates legacy codex/* and openai-codex/* model
refs, legacy Codex auth profile ids, and legacy Codex auth-order entries to the
canonical openai route. Migrated model refs receive model-scoped
agentRuntime.id: "codex"; use auth.order.openai for new auth-order config.
Fresh OpenAI setup applies a GPT-5.6 primary only when no primary model is
configured. Adding or refreshing OpenAI auth preserves an existing explicit
selection, including
openai/gpt-5.5, unless you explicitly use
models auth login --set-default or models set. Use an API-key auth profile
only when you want API-key auth for an agent model.Native Codex app-server auth
The native Codex app-server harness usesopenai/* model refs when an eligible
exact official HTTPS route selects it implicitly, or when provider/model
agentRuntime.id: "codex" selects it explicitly. Its auth is still
account-based. OpenClaw selects auth in this order:
- Ordered OpenAI auth profiles for the agent, preferably under
auth.order.openai. Runopenclaw doctor --fixto migrate older legacy Codex auth profile ids and auth order. - The app-server’s existing account, such as a local Codex CLI ChatGPT sign-in. For the default isolated agent home, OpenClaw bridges that native CLI account into the app-server through its login RPC; it does not share the CLI’s config, plugins, or thread store.
- For local stdio app-server launches only, and only when the app-server
reports no account:
CODEX_API_KEY, thenOPENAI_API_KEY.
codex-home/auth.json is not a runtime auth store. If
you copied or mounted Codex CLI credentials there, import them into the agent’s
OpenClaw auth store before starting a native Codex turn. Replace <agent-id>
with the configured agent that owns this Codex home:
OPENAI_API_KEY for direct OpenAI models or
embeddings. The env API-key fallback applies only to the local stdio no-account
path; it is never sent over WebSocket app-server connections. When a
subscription-style Codex profile is selected, OpenClaw also keeps
CODEX_API_KEY and OPENAI_API_KEY out of the spawned stdio app-server child
and sends the selected credentials through the app-server login RPC instead.
When that subscription profile is blocked by a Codex usage limit, OpenClaw
marks the profile blocked until Codex’s advertised reset time and lets auth
ordering rotate to the next openai:* profile, without changing the selected
model or dropping out of the Codex harness. Once the reset time passes, the
subscription profile is eligible again.