openai/codex · error · WorkloadIdentityError
could not read workload identity assertion file {path}
Error message
could not read workload identity assertion file {path} What it means
Error "could not read workload identity assertion file {path}" thrown in openai/codex.
Source
Thrown at codex-rs/workload-identity/src/lib.rs:50
Ok(Self {
assertion_file,
federation_rule_id: federation_rule_id.to_string(),
workload_identity_context,
})
}
}
#[derive(Clone, Debug, Error)]
pub enum WorkloadIdentityError {
#[error("the workload identity federation rule ID must not be empty")]
InvalidFederationRuleId,
#[error("the workload identity assertion file path must be absolute")]
AssertionFileMustBeAbsolute,
#[error("the workload identity assertion is invalid")]
InvalidAssertion,
#[error("the workload identity assertion exceeds 16 KiB")]
AssertionTooLarge,
#[error("could not read workload identity assertion file {path}")]
AssertionFile {
path: PathBuf,
#[source]
source: Arc<std::io::Error>,
},
#[error("could not configure the workload identity HTTP client")]
HttpClientConfiguration,
#[error("the workload identity token URL must use HTTPS or loopback HTTP")]
InvalidTokenUrl,
#[error("the workload identity token exchange is unavailable")]
ExchangeUnavailable,
#[error("the workload identity token exchange was rejected with HTTP {0}")]
ExchangeRejected(u16),
#[error("the workload identity token exchange returned an invalid response")]
InvalidExchangeResponse,
}
impl WorkloadIdentityError {View on GitHub (pinned to 339751715c)
Solutions
- Verify the assertion file path exists and is readable by the process; fix permissions or the configured path.
When it happens
Trigger: Thrown at codex-rs/workload-identity/src/lib.rs:50 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of openai/codex@339751715c (2026-08-25).
Data as JSON: /api/errors/1fa0975b9b74f336.
Report an issue: GitHub.