Two large Codex phone-verification threads were recently closed after individual cases were reviewed. That case-by-case work is useful, but the product-level account-recovery gap remains: OpenAI’s Help Center still states that an existing account phone number cannot be changed.
This is not a request to expose account-specific details or allow unrestricted phone-number edits. It is a request for a secure, self-service replacement and recovery path.
Phone numbers expire, are reassigned, and change when users move countries or companies. If ChatGPT can still be accessed through MFA or passkeys but Codex accepts only SMS/WhatsApp to a legacy number, the old number becomes both a permanent lockout risk and a security liability.
A risk-based implementation could:
- Add “I no longer have access to this number” to Codex verification.
- Allow step-up verification with an existing passkey/MFA method, recovery code, verified email, or trusted signed-in device.
- Verify the new number, notify all existing channels, and apply a 24-72 hour hold for high-risk changes.
- Revoke sensitive sessions and recovery tokens after the change, and provide a freeze/reversal link.
- Route exceptional cases to a private Account Recovery/Auth review.
Relevant closed discussions:
- Locked out of Codex because of an old phone number?
- Codex sign-in asks for phone verification on paid account
Current Help Center policy:
Could @OpenAI_Support confirm whether a self-service phone replacement or documented alternative recovery flow is planned?
This topic is intentionally about product design, not an individual account case. Please do not post phone numbers, email addresses, payment details, IDs, OTPs, or unredacted screenshots.