This hotfix restores the documented Codex approval path when the Spend Guard holds a request before provider send.
Fixed
- Codex Spend Guard approvals now resolve safely. TokenPak recognizes Codex
session-idandthread-idheaders, reads strict yes/no intent and leading[TIP: allow=once]directives from OpenAI Responses input, and keeps pending requests and anti-loop state isolated per session. Requests without a stable identity remain blocked without creating a global approval row.