`hermes auth add openai-codex --browser` (or `auth.codex_login_flow: browser`)
signs in through OpenAI's authorize endpoint with PKCE and receives the code on
the loopback listener `http://localhost:1455/auth/callback` — the redirect URI
fixed by the public Codex client registration. Organizations that disable the
device-code grant could not log in at all before (#95743).
Device code stays the default and is never auto-replaced: the browser flow runs
only when the user asks for it, and when :1455 is already taken (a Codex CLI
sign-in in progress) Hermes prints why and falls back to device code instead of
failing. State is a 32-byte nonce compared in constant time; the code, verifier
and tokens are never logged or printed. Credentials land in the existing pool
add path with source `manual:loopback_pkce`, so refresh/rotation treat them like
any other independently added Codex account.
Derived from #97058 by @astraltrekkin (re-homed after the auth_codex.py split;
the fixed registered port replaces the free-port scan, and the flow is opt-in
instead of auto-selected per the maintainer's ruling).
Fixes#95743