App Proxy

Run OpenAI Codex Behind Clash Verge: Timeout Means Not Proxied, Country Error Means Wrong Region

Codex CLI or scripts calling OpenAI: timeouts mean “not proxied”; unsupported_country means “wrong region.” Treat them separately.

Prefer Tun; else shell proxy env + a fitting region. VS Code extension and ChatGPT-web Codex are not this article: VS Code / ChatGPT Codex. Web ChatGPT: ChatGPT; overview: Tun & AI.

Tun, env, region

Open a new shell after Tun. Don’t hardcode unstable ports in rc files (ports). Confirm which binary you run if multiple installs exist. Providers/regions: provider, latency.

export HTTPS_PROXY=http://127.0.0.1:MIXED_PORT
export HTTP_PROXY=http://127.0.0.1:MIXED_PORT
codex   # one API call should land in Connections

Minimal repro

One API command + the Connections page. No hits → path broken (system proxy). Hits but rejected → region. Use the same node pool as Claude/Cursor/Aider so behavior is comparable.

Failure split

ErrorMeaningFix
timeout / connection refusedNot proxiedTun, env vars, or node reachability
unsupported_countryWrong regionSwap to an in-region node; not a reinstall
auth errorsKeys/loginVerify after the proxy path is proven

Stop

Tun issues: Tun start failed. Siblings: Claude Code, Cursor, Aider. Builds: download center.

Prepare a working proxy and the right node

Codex needs a proxy to reach OpenAI and is sensitive to node region. Get Clash Verge Rev from the download center, then configure the terminal proxy and node below.