Pick a CODEX_HOME source and manage an auth/account pool for tmux-workflow workers (balanced or team_cycle), with optional usage watching + rotation.
This skill exposes a tiny CLI (scripts/cap) that:
CODEX_HOME source directory for a worker (cap pick)cap pick-auth)It is designed to be called by tmux-workflow/scripts/twf when twf.account_pool.enabled: true.
Edit scripts/cap_config.yaml:
sources: comma-separated list of CODEX_HOME template directories (optional; default fallback is ~/.codex)auth_team_dir: required when using pick-auth (should contain multiple auth JSON files; names unrestricted)pick-auth selection algorithm:
balanced (default): pick the least-used auth file (counts persisted in state_file); if tied, pick randomlyteam_cycle: use one auth for the whole team, and keep it stable until you advance the pointerCAP_AUTH_STRATEGY=team_cycle (or config auth_strategy: team_cycle)twf):bash .codex/skills/codex-account-pool/scripts/cap pick --worker <full> --base <base>twf):bash .codex/skills/codex-account-pool/scripts/cap pick-auth --worker <full> --base <base>bash .codex/skills/codex-account-pool/scripts/cap auth-current --team-dir /abs/path/to/AUTH_TEAMbash .codex/skills/codex-account-pool/scripts/cap auth-advance --team-dir /abs/path/to/AUTH_TEAMbash .codex/skills/codex-account-pool/scripts/cap reset-state/status in tmux (requires tmux + codex):bash .codex/skills/codex-account-pool/scripts/cap status /abs/path/to/AUTH_TEAMbash .codex/skills/codex-account-pool/scripts/cap watch-team /abs/path/to/AUTH_TEAM --registry /abs/path/to/registry.jsonbash .codex/skills/codex-account-pool/scripts/cap listbash .codex/skills/codex-account-pool/scripts/cap whereEnable in tmux-workflow/scripts/twf_config.yaml:
twf.account_pool.enabled: trueOptional:
twf.account_pool.cmd: "/abs/path/to/.codex/skills/codex-account-pool/scripts/cap"TWF_ACCOUNT_POOL_CMD=/abs/path/to/capWhen enabled, twf will:
cap pick to choose TWF_CODEX_HOME_SRC (if you didn’t set TWF_CODEX_HOME_SRC explicitly)cap pick-auth and copy the chosen file into each worker home as auth.json (overriding the synced auth.json)