openai/codex · error · WorkloadIdentityError
the workload identity token exchange was rejected with HTTP
Error message
the workload identity token exchange was rejected with HTTP {0} What it means
Error "the workload identity token exchange was rejected with HTTP {0}" thrown in openai/codex.
Source
Thrown at codex-rs/workload-identity/src/lib.rs:62
#[error("the workload identity assertion file path must be absolute")]
AssertionFileMustBeAbsolute,
#[error("the workload identity assertion is invalid")]
InvalidAssertion,
#[error("the workload identity assertion exceeds 16 KiB")]
AssertionTooLarge,
#[error("could not read workload identity assertion file {path}")]
AssertionFile {
path: PathBuf,
#[source]
source: Arc<std::io::Error>,
},
#[error("could not configure the workload identity HTTP client")]
HttpClientConfiguration,
#[error("the workload identity token URL must use HTTPS or loopback HTTP")]
InvalidTokenUrl,
#[error("the workload identity token exchange is unavailable")]
ExchangeUnavailable,
#[error("the workload identity token exchange was rejected with HTTP {0}")]
ExchangeRejected(u16),
#[error("the workload identity token exchange returned an invalid response")]
InvalidExchangeResponse,
}
impl WorkloadIdentityError {
/// Whether retrying the operation may succeed without changing configuration.
pub fn is_transient(&self) -> bool {
match self {
Self::AssertionFile { source, .. } => matches!(
source.kind(),
std::io::ErrorKind::Interrupted
| std::io::ErrorKind::NotFound
| std::io::ErrorKind::TimedOut
| std::io::ErrorKind::WouldBlock
),
Self::ExchangeUnavailable | Self::ExchangeRejected(408 | 429 | 500..=599) => true,
Self::InvalidFederationRuleIdView on GitHub (pinned to 339751715c)
Solutions
- Inspect the HTTP status and response body from the token endpoint; verify the federation rule and assertion are accepted by the provider.
When it happens
Trigger: Thrown at codex-rs/workload-identity/src/lib.rs:62 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of openai/codex@339751715c (2026-08-25).
Data as JSON: /api/errors/74970dd1a662ccf6.
Report an issue: GitHub.