Diagnose why OpenAI or Codex feels slow, reconnects repeatedly, or fails behind a proxy.
codex-netcheck tests DNS, TCP, TLS, HTTPS, WebSocket handshakes, proxy settings, and the active route from one command. Add --claude to check Anthropic and Claude alongside OpenAI. It runs locally and redacts credentials from reports by default.
macOS and Linux · Node.js 20+ · No OpenAI or Anthropic API key required
npx codex-netcheckCheck OpenAI/Codex and Claude together:
npx codex-netcheck --claudeExample:
codex-netcheck · OpenAI/Codex network diagnostics
✓ DNS api.openai.com: resolved 2 IPv4 addresses 34 ms
✓ TCP connection (api.openai.com:443): connected 76 ms
✓ TLS handshake (api.openai.com:443): TLSv1.3 114 ms
✓ OpenAI API HTTPS: HTTP 401, service reachable 225 ms
✓ OpenAI Realtime WebSocket: handshake reached service 302 ms
Conclusion
The OpenAI network path is healthy. Slow Codex responses are more likely caused by model reasoning, service load, or a long context.
Codex uses more than basic ICMP connectivity. A healthy ping can coexist with broken DNS, TLS interception, blocked WebSocket upgrades, or an unexpected VPN route. This tool checks each layer and turns failures into concrete remediation steps.
# Human-readable diagnostics
npx codex-netcheck
# Machine-readable output
npx codex-netcheck --json
# Save a redacted Markdown report
npx codex-netcheck --report report.md
# Save JSON
npx codex-netcheck --report report.json
# Repeat every 30 seconds
npx codex-netcheck --watch 30
# Change the timeout per check
npx codex-netcheck --timeout 15
# Include Claude API and claude.ai checks
npx codex-netcheck --claude| Layer | What it detects |
|---|---|
| Environment | OS, architecture, and Node.js runtime |
| Proxy | Proxy environment variables and macOS system proxy |
| DNS | IPv4 resolution for OpenAI hosts and, with --claude, Anthropic hosts |
| Route | Direct interface versus VPN/TUN route |
| TCP | Reachability of api.openai.com:443 |
| TLS | Certificate validation, protocol, cipher, and handshake time |
| HTTPS | Reachability and time to response for OpenAI and ChatGPT |
| WebSocket | Whether an OpenAI WSS handshake reaches the service |
Claude mode checks api.anthropic.com and claude.ai across DNS, route, TCP, TLS, and HTTPS. It does not add a Claude WebSocket probe because Anthropic does not publish a stable client WSS endpoint for this purpose.
- No OpenAI or Anthropic API key is required or sent.
- Probes use unauthenticated requests only.
- API keys, bearer tokens, proxy credentials, cookies, and home-directory paths are redacted.
- Reports are created with owner-only file permissions where supported.
- The hidden
--include-sensitiveflag exists only for local debugging and should not be used for shared reports.
npm install --global codex-netcheck
codex-netcheckgit clone https://github.com/cntopcode/codex-netcheck.git
cd codex-netcheck
npm install
npm test
npm run build
npm run dev- OpenAI endpoint latency history and percentile summaries
- Proxy-on versus proxy-off comparison mode
- Optional traceroute/MTR integration
- Sanitized HTML report
- Windows support
Bug reports and reproducible network cases are welcome. See CONTRIBUTING.md. Please never include API keys, cookies, proxy credentials, or unredacted configuration in an issue.
MIT