The Codex models manifest path returned upstream 401s straight to the
client without feeding them into the account state machinery. A revoked
or invalidated OAuth account therefore stayed active and schedulable,
kept being selected for subsequent /models requests, and produced
repeated 502s until an admin ran a manual connection test (#4544).
- Route ChatGPT-backend manifest 401s through the shared upstream-error
handling: token cache invalidation, temp-unschedulable cooldown for
refreshable OAuth accounts, permanent disable for
token_revoked/token_invalidated, plus the runtime scheduling block.
- Treat ChatGPT-backend manifest 401s as failover-eligible so the
current /models request can switch to a healthy account instead of
returning 502. Custom API key upstream 401s keep the existing
no-failover, no-disable behavior since their /models auth is not
authoritative for the account.
- Skip Agent Identity accounts: their 401s can be task-scoped and have
a dedicated recovery flow.
- Attach the selected account to the ops error-log context so /models
failures record the account_id.
Fixes#4544
Co-authored-by: Cursor <cursoragent@cursor.com>