App proxy

Fix Codex in VS Code and ChatGPT Behind Clash Verge: Web, Extension, CLI

OpenAI spread Codex across a product page CLI, Codex inside chatgpt.com, and a VS Code extension. Failures look like "cannot connect" and hide three paths. The CLI article already covers shell timeouts and unsupported_country. This page covers Codex inside ChatGPT and the VS Code extension. A green CLI is the most common false all-clear.

Clash Verge Rev only ships the packets. The website uses system proxy; the extension usually needs Tun or an editor-level proxy. Claude site/desktop: Claude.ai / Desktop. CLI: Codex CLI. ChatGPT site: ChatGPT proxy.

Do not debug three Codex doors as one

Entry Traffic looks like Default Clash move
Codex on chatgpt.com Browser System proxy + Rule; treat it as ChatGPT web
VS Code Codex extension Editor process Tun, or VS Code http.proxy to mixed port
Codex CLI Terminal Tun or HTTPS_PROXY; see the CLI article

You can install all three. Test one door at a time. Web Codex failing is not a reason to edit VS Code proxy. Extension spinner is not a reason to reinstall the CLI. A second Clash/CFW stealing the mixed port will make all three look cursed: port conflicts.

ChatGPT web Codex rides the browser path

ChatGPT chat works, Codex panel does not: decide whether the product entry moved, the account lacks the feature, or the network failed. No new connections when you click Codex looks like the UI never issued a call. Rows for openai/chatgpt with 403 or timeout are node/region. System proxy LED lying: system proxy. Half-rendered login plus a white Codex pane often DNS: DNS.

Do not turn Tun on to "strengthen" a website test. Tun widens the blast radius. Goal for web Codex: Rule, system proxy on, one ChatGPT reply on the same node, then one short Codex task. Fail there, stay on the web layer—change nodes or the account, do not install the VS Code extension as a lucky charm.

VS Code extension: system proxy is often not enough

The extension host does not promise to follow OS proxy. ChatGPT in the browser looks fine; the status bar spins; completions never arrive. Trigger one completion and watch Clash connections. Empty list: still direct. Rows that fail: then talk about region.

  1. Prefer Tun. Windows: Service Mode first. Fully quit VS Code after Tun is up so the old window does not keep the old route.
  2. If Tun is blocked, set VS Code http.proxy to http://127.0.0.1:mixed-port using http, not a socks port. Read the port from Clash Settings.
  3. If someone flipped http.proxyStrictSSL, return it to default while testing so a custom CA does not kill the OpenAI handshake.
  4. Corporate PAC can bypass 127.0.0.1. Tun if allowed; otherwise live with office egress.

A quick way to confirm the extension path: with Tun on, trigger one completion and filter the connections list by openai.com. If you see a 2xx row, the proxy works and the issue is account or quota, not Clash. Cursor users should not treat Cursor model settings as the VS Code Codex switch. Cursor: Cursor article. With Copilot installed, both extensions share an outbound path. Disable Copilot for one Codex test so the connections list is readable. Copilot: Copilot proxy.

Timeout vs region vs rate limit

Timeout with an empty connections list: the extension never entered Clash. Fix Tun, http.proxy, or the port. Timeout with rows: node or path quality (latency tests, slow speed). unsupported_country: egress region, not a reinstall. 429: quota or rate, not a reason to hammer Tun.

Auth errors often sit on a successful TLS row. Fix proxy first, then the account. ChatGPT website signed in while the extension will not is still "extension not tunneled," not a password drill.

Running Claude and Codex together

Claude uses anthropic.com / claude.ai; Codex uses openai.com / chatgpt.com-class hosts. A coarse "foreign PROXY, domestic DIRECT" split usually carries both. Failures come from handwritten DOMAIN-SUFFIX lists that omit one vendor, or DIRECT on api.openai.com. After edits, send one short Claude Desktop message and one VS Code Codex completion. The connections list should show both vendors.

Fake-IP breaking one side: Fake-IP. Do not flip Global twenty times a day for Codex versus a domestic disk. Stay on Rule plus an explicit DIRECT list: bypass rules, routing.

Acceptance and stop-loss

Web Codex: under system proxy, one short Codex task on chatgpt.com. VS Code: Tun or http.proxy live, a completion or chat returns, connections logged. CLI success does not sign those two. Three nodes still region-blocked: stop, inspect egress and account, do not reinstall VS Code. Builds: download center. Tun dead: start failed. PowerShell variables help shells only: terminal proxy.

One-line triage table

Symptom Likely layer Move
Web Codex blank, chat works Account / feature flag Try a short task on the same node; check plan
Extension spinner forever Tunnel Tun or http.proxy to mixed port; restart VS Code
Rows in connections but 403/429 Egress / quota Change node region; wait out rate limit

Extension and web each need a live client

Codex still depends on an OpenAI network path. Grab Clash Verge Rev from the download center, then accept web, VS Code, and CLI separately.