codex-auto-register
Automate ChatGPT/Codex account registration and OAuth token generation using DuckMail temporary email service
How do I install this agent skill?
npx skills add https://github.com/reason-machines/codex-skills --skill codex-auto-registerIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The codex-auto-register skill automates the bulk creation of ChatGPT and Codex accounts using temporary email services and proxies. The tool's design involves generating and storing sensitive credentials and OAuth tokens in local plain-text files. It also includes a configurable feature to upload these credentials to a remote API endpoint, which presents a risk of data exfiltration or exposure if directed to an untrusted or insecure server.
- Socketwarn
1 alert: gptSecurity
- Snykwarn
Risk: MEDIUM · 1 issue
What does this agent skill do?
Codex Auto Register
Skill by ara.so — Codex Skills collection.
Overview
codex_auto_register is a Python tool for automated ChatGPT/Codex account registration and OAuth token generation using the DuckMail temporary email API. It supports two workflows:
- Root script (
chatgpt_register.py): Register ChatGPT accounts with optional OAuth - Codex protocol script (
codex/protocol_keygen.py): Full Codex OAuth flow with CLIProxyAPI v6 compatible token output
Installation
Dependencies
For root registration script:
pip install curl_cffi
For Codex protocol script:
pip install requests urllib3
Configuration Setup
- Copy example configs to active configs:
cp config.example.json config.json
cp codex/config.example.json codex/config.json
- Edit
config.jsonandcodex/config.jsonwith your credentials (see Configuration section)
Root Script: ChatGPT Registration
Configuration (config.json)
{
"total_accounts": 5,
"duckmail_api_base": "https://duckmail.example.com",
"duckmail_bearer": "${DUCKMAIL_TOKEN}",
"proxy": "http://username:password@proxy.example.com:8080",
"output_file": "registered_accounts.txt",
"enable_oauth": true,
"oauth_required": false,
"upload_api_url": "https://cpa.example.com/api/accounts",
"upload_api_token": "${CPA_API_TOKEN}"
}
Key Fields:
total_accounts: Number of accounts to registerduckmail_api_base: DuckMail API endpointduckmail_bearer: DuckMail authentication token (use env var)proxy: HTTP/HTTPS proxy (required for registration)enable_oauth: Whether to perform OAuth flowoauth_required: Fail if OAuth failsupload_api_url/upload_api_token: Optional CPA upload
Usage
python chatgpt_register.py
The script will:
- Create temporary email via DuckMail
- Register ChatGPT account
- Optionally perform OAuth
- Save results to
registered_accounts.txt - Optionally upload to CPA
Output Format
registered_accounts.txt contains:
email@example.com:password123:access_token:refresh_token
email2@example.com:password456:access_token2:refresh_token2
Codex Protocol Script
Configuration (codex/config.json)
{
"total_accounts": 10,
"duckmail_api_base": "https://duckmail.example.com",
"duckmail_bearer": "${DUCKMAIL_TOKEN}",
"proxy": "http://user:pass@proxy.example.com:8080",
"output_dir": "codex_tokens",
"accounts_file": "accounts.txt",
"csv_file": "registered_accounts.csv",
"upload_api_url": "https://cpa.example.com/api/codex",
"upload_api_token": "${CPA_API_TOKEN}",
"save_access_token": true,
"save_refresh_token": true,
"ak_file": "ak.txt",
"rk_file": "rk.txt"
}
Usage
python codex/protocol_keygen.py
The script performs:
- DuckMail temporary email creation
- ChatGPT account registration
- Codex OAuth login flow
- Token extraction and storage
- CLIProxyAPI v6 compatible file generation
Output Files
Token JSON files (CLIProxyAPI v6 format):
codex_tokens/
├── fk-xxxxxx.json
├── fk-yyyyyy.json
└── ...
Each JSON contains:
{
"access_token": "ey...",
"refresh_token": "ey...",
"expires_at": 1234567890
}
Account files:
accounts.txt: email:password:access_token:refresh_tokenak.txt: Access tokens (one per line)rk.txt: Refresh tokens (one per line)registered_accounts.csv: CSV format with all fields
Common Patterns
Environment Variables for Secrets
Never hardcode credentials. Use environment variables:
export DUCKMAIL_TOKEN="your_duckmail_token"
export CPA_API_TOKEN="your_cpa_token"
Reference in config:
{
"duckmail_bearer": "${DUCKMAIL_TOKEN}",
"upload_api_token": "${CPA_API_TOKEN}"
}
Proxy Configuration
Both scripts require proxies to bypass rate limits:
{
"proxy": "http://username:password@proxy-host:port"
}
For SOCKS5:
{
"proxy": "socks5://username:password@proxy-host:port"
}
Batch Registration
Register multiple accounts in sequence:
# In your automation script
import subprocess
import json
config = {
"total_accounts": 50,
"duckmail_api_base": "...",
# ... other config
}
with open("codex/config.json", "w") as f:
json.dump(config, f)
subprocess.run(["python", "codex/protocol_keygen.py"])
Token File Naming Convention
Codex tokens follow CLIProxyAPI v6 naming:
- Format:
fk-{unique_id}.json - Compatible with CLIProxyAPI token directory structure
- Can be directly placed in CPA token folders
DuckMail API Integration
The project uses DuckMail for temporary email:
Create email:
POST {duckmail_api_base}/api/email/create
Authorization: Bearer {duckmail_bearer}
Check inbox:
GET {duckmail_api_base}/api/email/{email_id}/messages
Authorization: Bearer {duckmail_bearer}
See duckmaildoc.md for full API reference.
Troubleshooting
Registration Fails
Problem: ChatGPT registration returns errors
Solutions:
- Verify proxy is working and not banned
- Check DuckMail API is accessible
- Ensure
duckmail_bearertoken is valid - Try different proxy IP range
OAuth Token Not Generated
Problem: enable_oauth: true but no tokens
Solutions:
- Set
oauth_required: falseto continue without OAuth - Verify proxy supports OAuth endpoints
- Check account was successfully verified
- Inspect network logs for OAuth failures
DuckMail Email Not Received
Problem: Verification email not arriving
Solutions:
- Wait 30-60 seconds (DuckMail polling interval)
- Check DuckMail API rate limits
- Verify email was successfully created
- Try different email domain if available
CPA Upload Fails
Problem: upload_api_url returns errors
Solutions:
- Verify
upload_api_tokenis correct - Check CPA endpoint is accessible through proxy
- Ensure token format matches CPA expectations
- Review CPA API documentation for required fields
Token Files Not Compatible
Problem: CLIProxyAPI doesn't recognize tokens
Solutions:
- Verify filename format:
fk-*.json - Check JSON structure matches expected schema
- Ensure
expires_atis Unix timestamp - Validate tokens are not expired
Proxy Authentication Errors
Problem: 407 Proxy Authentication Required
Solutions:
- Verify proxy username/password are correct
- Use URL-encoded credentials in proxy string
- Test proxy with curl:
curl -x proxy http://api.openai.com - Check proxy supports CONNECT method for HTTPS
File Structure
Generated files (all in .gitignore):
project_root/
├── config.json # Root script config
├── registered_accounts.txt # Root script output
└── codex/
├── config.json # Codex script config
├── accounts.txt # email:password:tokens
├── ak.txt # Access tokens only
├── rk.txt # Refresh tokens only
├── registered_accounts.csv # CSV format
└── codex_tokens/ # CLIProxyAPI compatible
├── fk-xxxxx.json
└── fk-yyyyy.json
Security Notes
- Never commit
config.jsonfiles (use.example.jsontemplates) - Store tokens securely (files are gitignored by default)
- Use environment variables for all secrets
- Rotate DuckMail tokens regularly
- Keep proxy credentials separate from code
- Review
registered_accounts.txtfor sensitive data before sharing logs
Integration with CLIProxyAPI
Place generated token files directly in CPA token directory:
cp codex/codex_tokens/*.json /path/to/CLIProxyAPI/tokens/codex/
CPA will automatically detect and use tokens with fk-*.json naming pattern.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/reason-machines/codex-skills/codex-auto-register">View codex-auto-register on skillZs</a>