OpenVision 2.14.0 Lets Ray-Ban Meta Owners Sign In With ChatGPT or SuperGrok, Then Moves Eight Plain-Text Keys Into the Keychain

Visitors at the Ray-Ban and Meta smart glasses booth at the 2025 Bild Expo presented by B&H Photo
The Ray-Ban and Meta booth at the 2025 Bild Expo. Photo: Tzim78 via Wikimedia Commons, CC BY 4.0.

OpenVision, an OPEN-SOURCE iPhone app that connects Ray-Ban Meta glasses to the AI model of the owner’s choosing, shipped version 2.14.0 on October 2 at 20:29 UTC (4:29 p.m. ET). The HEADLINE change is that owners who ALREADY pay for ChatGPT Plus or Pro, or for SuperGrok, can now SIGN IN with that subscription instead of buying SEPARATE API credits. Two days LATER, on October 4, the project merged a fix that moves EIGHT API keys and tokens out of a PLAIN-TEXT settings file and into the iOS Keychain.

Neither change comes from META, OpenAI or xAI. OpenVision is a THIRD-PARTY project under the MIT licence, with about 155 stars on GitHub at the time of writing, and it has NO App Store listing. The documented route is STILL a SOURCE build in Xcode.

What the subscription sign-in actually does

According to the release notes, Settings now offers a “Connect With” choice for OpenAI: API key or ChatGPT subscription. The sign-in uses OAuth with PKCE, and the tokens are stored in the Keychain as this-device-only items. Text, photos from the glasses, web search and tools WORK on the subscription route. Live video does NOT; it still needs an OpenAI API key, or the app falls back to Gemini.

The project is CANDID about the RISK. The pull request that added the feature says the app SIGNS IN “the way the Codex CLI does,” using the Codex CLI’s public client ID, and sends requests to the SAME backend that OpenAI’s command-line coding tool uses. The release notes warn: “This uses the Codex CLI’s integration surface, not a documented API, so it can change or stop working without notice.” They also note that signing in on the phone APPEARS to end a Codex CLI session for the same account, and vice versa.

The same release adds xAI’s Grok as a SIXTH backend through xAI’s public Chat Completions API, reachable with an xAI API key or a SuperGrok sign-in. According to the Grok pull request, that sign-in reuses the Grok CLI’s public client ID, while the resulting token calls the PUBLIC API directly. Version 2.14.0 also adds two CLOUD voices, Grok with 28 voices and OpenAI’s gpt-4o-mini-tts with 13, and moves a dependency pin so the project BUILDS on Xcode 27. The notes flag one gap HONESTLY: the OpenAI voice had not been verified on a device, because no contributor had API credits.

Eight secrets were sitting in a JSON file

The SECURITY fix arrived SEPARATELY. Pull request 66, titled “Add: Store API keys in the Keychain,” was opened on October 3 and merged on October 4 at 19:19 UTC (3:19 p.m. ET). It states that the app’s eight keys and tokens “were saved in plain text in Documents/settings.json.” The fields it names are openClawAuthToken, geminiAPIKey, openAIAPIKey, grokAPIKey, hermesAPIKey, tavilyAPIKey, telemetryToken and telemetryPassword.

Those secrets now go to the Keychain as items readable AFTER the phone’s first unlock, and the settings file is written with those fields BLANK. On launch, an OLDER build’s file is MIGRATED automatically. Two details MATTER for anyone who runs the app:

  • The new key items are NOT marked this-device-only, unlike the sign-in tokens, so by design they STILL move with an ENCRYPTED backup or Quick Start to a NEW phone.
  • The fix is on the main branch. As of this writing, the project’s latest tagged release is still 2.14.0 from October 2, which PREDATES the merge, so source builders NEED a current checkout to get it.

The contributor’s test notes say the full suite PASSED on an iPhone 16 Pro Max, 131 tests with 0 failures. They also say the migration path ran on that device only through UNIT tests, because the tester used sign-ins rather than stored keys. The repository added a required GitHub Actions BUILD check on main on October 4 as well, in pull request 68.

Ray-Ban Meta Gen 2 Wayfarer smart glasses with polarized lenses, showing the camera and capture LED in the frame corners
Ray-Ban Meta Gen 2 Wayfarer. The glasses supply the camera and microphones; OpenVision runs the model on the phone or in the owner’s cloud account. Photo: ItzANormalFioko via Wikimedia Commons, CC BY-SA 3.0.

Why this matters for Meta’s glasses

OpenVision does NOT change what the HARDWARE does. The glasses provide the camera and microphones, the phone holds the conversation with whichever account is signed in, and pairing STILL runs through Meta’s OWN app. The project builds on Meta’s Wearables Device Access Toolkit; its 2.13.0 release in August moved to SDK 0.9.0 and listed glasses firmware V126 or later and Meta AI app V282 or later as requirements.

That is ALSO why the project lives on GitHub rather than a store. As we covered with the Expo wrapper for the same toolkit, Meta has not yet opened PUBLIC store distribution for these glasses apps. Until it does, hobbyist and open-source projects are where MODEL CHOICE on Ray-Ban Meta glasses is being TESTED, and this week’s changes show both the APPEAL and the exposure. Reusing a CLI’s sign-in saves users MONEY but rests on an UNDOCUMENTED surface, and an app that juggles six backends had been keeping their CREDENTIALS in a file that any backup could read in the CLEAR.

Coverage of both changes first appeared at MIXED and in its follow-up on the Keychain fix. Details in this article were CHECKED against the project’s GitHub release notes and pull requests.

Sources: OpenVision v2.14.0 release notes; OpenVision pull requests #60, #61, #66 and #68; MIXED, October 5, 2026.

Leave a Comment