Skip to content

feat: reuse Codex and Claude subscriptions for LLM roles - #6

Merged
ASRagab merged 2 commits into
mainfrom
feat/codex-claude-subscription
Sep 23, 2026
Merged

ASRagab merged 2 commits into
mainfrom
feat/codex-claude-subscription

Conversation

@ASRagab

@ASRagab ASRagab commented Sep 23, 2026

Copy link
Copy Markdown
Owner

Summary

Codex and Claude Code users can now run proposal, judging, analysis, scoring, validation, and generated-evaluator roles through their existing local subscriptions instead of configuring provider API keys. API-backed LiteLLM behavior remains the default, so existing commands and standalone generated API evaluators keep working unchanged.

Design decisions

  • Backend selection is explicit through role-specific CLI flags or TOML role tables; the runtime never guesses from the host process.
  • Codex runs in an empty read-only workspace with denied approvals and a private temporary home linked only to the saved login. Claude runs without tools, MCP servers, session persistence, or paid API/cloud environment overrides.
  • Subscription calls share per-provider concurrency limits and sticky per-role fallback circuits. Same-vendor API fallback requires both a matching fallback model and credential, and prints a billing warning before use.
  • Results record requested and actual backend, model, authentication class, role, timing, usage, and fallback provenance without storing prompts or credential values.
  • Default API-generated evaluators remain self-contained; subscription-generated evaluators use the installed versioned runtime so they share the same isolation and coordination policy.

Example

optimize-anything optimize seed.txt \
  --proposer-backend codex \
  --judge-backend codex \
  --objective "Improve clarity" \
  --no-api-fallback

optimize-anything optimize seed.txt \
  --proposer-backend claude \
  --judge-backend claude \
  --objective "Improve clarity" \
  --no-api-fallback

Security considerations

  • Subscription credentials stay provider-owned; configuration accepts no token values.
  • External JSON Schema references, including $dynamicRef, are rejected before validation to prevent outbound schema resolution.
  • Provider subprocess output, runtime, workspaces, and cleanup are bounded; provider errors are normalized without echoing model output or credentials.

Test plan

  • uv run python scripts/check.py — 443 passed, 14 skipped; smoke harness and score regression gate passed.
  • uv run mypy src/optimize_anything — passed.
  • git diff --check origin/main...HEAD — passed.
  • OPTIMIZE_ANYTHING_RUN_SUBSCRIPTION_LIVE=1 uv run pytest -q tests/test_subscription_live.py — 6 passed against authenticated Codex and Claude subscriptions.
  • Browser tests: skipped; this change has no browser routes or rendered UI.

Agent-assisted implementation: Codex CLI · GPT-5.

@ASRagab
ASRagab merged commit 70e1fdf into main Sep 23, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant