npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

how-much-codex

v1.0.0

Published

Secure local OAuth pairing helper for How Much Codex

Downloads

37

Readme

How Much Codex connection helper

This small MIT-licensed helper connects a ChatGPT/Codex subscription to How Much Codex without printing or pasting OAuth credentials.

The dashboard gives you a single-use command such as:

npx [email protected] connect ABCD-EFGH-JKLM --provider openai --url="https://howmuchcodex.com"

This package is provider-locked to OpenAI. It rejects an Anthropic provider flag before reading any credential, and its destination defaults to https://howmuchcodex.com. --url <origin> (or --url=<origin>) takes precedence over HMC_URL and that default, which makes a generated command portable across shells. The value is parsed directly as data: it must be an HTTPS origin with no credentials, path, query, or fragment. Plain HTTP is accepted only for loopback development.

The helper:

  1. asks for confirmation and shows the exact HTTPS destination;
  2. runs the installed official codex login command with a helper-owned temporary CODEX_HOME;
  3. lets Codex open its normal OpenAI browser sign-in;
  4. sends the resulting renewable credential only to the displayed How Much Codex origin; and
  5. stops the child login and removes the exact helper-created temporary directory when finished or interrupted with SIGINT/SIGTERM.

It does not read or rotate your normal ~/.codex/auth.json unless you explicitly add --use-existing-login. That fallback shares a rotating login, so prefer the default isolated browser login. Pairing codes expire after ten minutes and work once.

Requirements: Node.js 22.18 or newer and the Codex CLI available as codex on your PATH.

Security

Treat any Codex OAuth credential like a password. Do not paste auth.json into chat, support tickets, or issue trackers. The helper never prints a token, validates the destination as HTTPS (except explicit loopback development), refuses HTTP redirects instead of forwarding a credential to another origin, and sends only to the origin displayed before confirmation. If cleanup of its temporary login fails, the helper stops before upload and prints the exact helper-created directory that you should delete.

SIGKILL, a power loss, or a process crash cannot run cleanup handlers. On its next start, the helper removes only its exact-name temporary directories that are at least 24 hours old, contain the helper's owner marker, and belong to a process that is no longer running. Newer or active directories are left alone. Until then, a residual login may remain under your operating system's temporary directory with the how-much-codex-login- prefix. Remove only the specific directory after confirming no connection helper is still using it.

Source code is included in the npm package under the MIT License.