You open the Codex client ready to work, but are blocked by a "Verify your phone number" prompt; or ChatGPT was working fine, but upon refresh it asks for a phone number to receive a code—this is usually not a client bug, but an account-level security check triggered. There's no skip option; you have to complete it.
Bottom line first: If you have a real mobile carrier number that you can continue to hold in the future, just use it to verify. If the number you can think of is a VoIP number like Google Voice, a landline, or a one-time temporary number borrowed during registration, don't fill it in—filling in the wrong direction will not only fail to receive the code but also waste the few chances this account has.
When does it suddenly pop up?
OpenAI's Help Center describes phone verification as part of the security process. Common triggers include:
- First authorized login on the Codex client, or after the account enables higher-level security settings, client-side login may force phone verification;
- Login verification when switching to a new device, new browser, or when the exit IP and geolocation differ from before;
- First API key creation on the API platform;
- Modifying sensitive account settings (e.g., security-related options).
So many people feel "it was fine yesterday, suddenly it asks for verification today"—often something like changing device, network exit, or opening Codex for the first time happened in between. Paid accounts are also asked; paying doesn't exempt you. As for the exact threshold for risk control triggers, or whether a certain IP range is more likely targeted, the official details are not public and may change with policy—no need to guess a definite reason.
Three hard rules you must know before acting
These three rules determine which number you should fill in, not just whether you can receive this one SMS.
First, there are restrictions on number types. OpenAI explicitly does not support VoIP numbers like Google Voice, landlines, and high-cost special service numbers. Filling in such numbers often results in the page directly blocking, showing an invalid number, or clicking send but the SMS never arrives. For specific behaviors and how to distinguish Chinese numbers and VoIP rejections, refer to this error-categorized explanation.
Second, the same number has a reuse limit on OpenAI. According to official statements, a phone number can be used for verification binding on at most 3 accounts; after reaching the limit, the number cannot complete verification for new accounts. If the number you have has already been used by colleagues or your other two accounts, this time it will likely fail directly.
Third, self-service rebinding is not supported after binding. The Help Center states that currently, directly modifying or unbinding a phone number associated with an account is not supported. This is the most easily overlooked and also the most fatal: if you casually borrow a temporary number that disappears after use to pass verification, the next time Codex or the web triggers mandatory verification, the code will be sent to that number that no longer belongs to you, and the account will be locked out.

Handling order: from stopping to switching numbers
1. Stop, don't repeatedly click "Resend". SMS itself has delivery delays; continuous triggering may be flagged as abnormal. Wait one to two minutes, check if your phone is in airplane mode or blocking international SMS. For the complete delay troubleshooting order, see this article.
2. Check the number type. First ask yourself: Is this a physical SIM or eSIM issued by a carrier? Can it normally receive SMS from other platforms? If it's a number assigned by a VoIP service, change direction and don't waste time here.
3. Keep the environment consistent. If you just changed network exit or device, try to return to your usual environment for verification, reducing the combination of "new device + new region + new number" appearing simultaneously. Network exit is not managed by the number; if you work across environments long-term, exit and multi-account environments can be handled separately by NexIP and NexBrowser—not covered here.
4. Confirm how many binding slots this number has left. Think about whether it has already been used to verify other OpenAI accounts. If unsure, treat it as risky and prioritize switching to a clean number.
5. Switch numbers, and switch to one you can hold long-term.
What kind of number to choose when switching
Combining the three rules above, the criteria for choosing a number this time differ from "just receive one SMS":
- Must be a real mobile carrier number, not a virtual number from a network-based service, otherwise it will likely be blocked at the sending stage;
- Must be able to receive repeatedly within the validity period, because the next verification trigger is only a matter of time;
- Must be renewable, because once the number expires and is recycled, and the account cannot change its binding, the consequence is similar to losing the account;
- Country should be a region commonly supported by the platform; US numbers are a common choice. For differences between countries, refer to this compilation on which country's phone number to use for OpenAI registration.
By this standard, "buy a short-term number, receive, and discard" is the easiest and most dangerous approach for OpenAI; it suits platforms where you verify once and never return, but not a development tool you open daily.
If you really don't have an available overseas real number, you can choose on NexSMS by purpose: short-term numbers are pay-per-use, very short validity, one-time verification then done; long-term premium numbers are real carrier local numbers (physical SIM and eSIM), renewable, with unlimited SMS reception within the validity period. For binding accounts like ChatGPT/Codex that require long-term login, the latter is more reliable—first check the difference in short-term vs. long-term numbers and renewal conditions, then go to the US number page to see currently available numbers and regions. Note that whether verification passes is ultimately determined by OpenAI's risk control rules at the time; no number can guarantee 100% success; choosing the right number type only minimizes the probability of failure.
After verification passes, do three things
- Record the number, country, and expiration date, together with this OpenAI account. Rebinding is not possible, so the number becomes part of the account asset.
- Set a renewal reminder a few days before the expiration date. Long-term numbers need to be renewed before expiration to continue holding; after expiration, trying to recover the same number is often too late.
- Also enable another stronger two-factor authentication (e.g., authenticator app or passkey), and don't let SMS be the only recovery channel. For the security boundaries of SMS OTP itself, see this layered advice.
Final reminder: All the above applies only to verifying accounts you legally own. Receiving verification codes for others, bulk registration, and circumventing platform real-name requirements are outside the scope of discussion, and platform risk control will quickly identify such behavior.
NexSms官方博客
Comments(0)