AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Login_chatgpt_device Fails Due To Incorrect Request Encoding And Mismatched OAuth Contract

The ChatGPT device login helper in langchain-openai sends form-encoded data to an endpoint that expects JSON, causing HTTP 400. Additionally, the polling and token exchange steps do not match OpenAI's current device authorization flow, making the feature completely inoperative.

highConfidence 82%LangchainAffected V1.6.0

Origin Analysis

The implementation uses an outdated device authorization API contract: the initial POST to /deviceauth/usercode sends form-encoded data instead of JSON, and subsequent steps (polling, token exchange) use incorrect request formats and status code handling, mismatching OpenAI's Codex device-login implementation.
Run the following Python code with langchain-openai 1.6.0: ```python from pathlib import Path from tempfile import TemporaryDirectory from langchain_openai.chatgpt_oauth import login_chatgpt_device with TemporaryDirectory() as directory: login_chatgpt_device(store_path=Path(directory) / "auth.json") ``` Observe the HTTP 400 error from https://auth.openai.com/api/accounts/deviceauth/usercode.

Fixing Code Block

Edge Case Audit

The endpoint URLs (poll and token) are guessed from the description and may need adjustment to match the actual OpenAI API. Test thoroughly before merging. The function uses a new httpx.Client per call, which is safe but not optimal for high concurrency; consider reusing a client. Rollback: if this fix causes issues, revert to the previous version (though it is already broken), or consult the official OpenAI Codex implementation for the exact endpoints and payloads.

Ecosystem Topology