DeepSeek Harness plugin

dsh-codex-auth-bridge

Reuse the Codex CLI ChatGPT OAuth login in DeepSeek Harness through pi-ai's openai-codex provider.

Jump to install

Source facts

Repository
shaomingbo/dsh-codex-auth-bridge
Latest update
Aug 15, 2026
Category
Tools & Capabilities
GitHub stars
0
Format
plugin
Catalog evidence
Upstream dsh.bundle evidence
Evidence path
package.json#dsh.bundle
Checked against
0.1.0-rc.8
Upstream check date
2026-08-20

This evidence comes from the upstream catalog. This site has not installed, run, or security-reviewed the plugin.

Install

Start with a prompt that asks an agent to review the GitHub repository and source. Switch to the command if you want to install it yourself.

Copy this prompt into DSH, Codex, or another agent and ask it to review the GitHub repository and source first.

Do not install or run any commands yet. Read this plugin's GitHub repository, README, and relevant source code. Then answer the questions below clearly and directly so I can decide whether it fits my needs:

1. What is this plugin, and what problem does it solve?
2. Who is it for, and what are its typical use cases?
3. How is it used after installation? Include one minimal example.
4. What known limitations or privacy, security, compatibility, or maintenance risks does it have?
5. Give a clear recommendation: recommend, conditionally recommend, or do not recommend, with reasons.

Distinguish statements documented by the repository, inferences from source code, and unknowns. If evidence is insufficient, say so explicitly. Do not guess or simply repeat the README.

GitHub: https://github.com/shaomingbo/dsh-codex-auth-bridge
Plugin: dsh-codex-auth-bridge
Author: shaomingbo

Check the source files

Read the README and other files from this plugin directory before installing.

File explorer3 files
README.mdSource · read only

dsh-codex-auth-bridge

Reuse the Codex CLI's ChatGPT OAuth login in DeepSeek Harness (DSH).

The package is a Host Cordis bundle. It reads Codex's auth.json, keeps the OAuth token fresh through pi-ai's native openai-codex OAuth implementation, synchronizes the access token into DSH's credential service, and configures pi-ai's built-in openai-codex model route.

It does not contain, upload, or commit any token.

Requirements

  • Node.js 22.19 or later
  • A DSH installation using the dsh-llm-pi-ai adapter
  • Codex logged in with ChatGPT (~/.codex/auth.json contains auth_mode: "chatgpt")

Install

Run this on each device after logging in with Codex:

npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0

The installer:

1. adds this package to ~/.dsh/profiles/web/package.json; 2. adds dsh-codex-auth-bridge to that profile's dsh.profile.bundles list; 3. runs pnpm install in the profile.

Restart dsh web afterward. The model picker will include the models exposed by pi-ai's installed openai-codex catalog.

Use another profile or source when needed:

npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0 --profile web
node ./bin/install.js --source file:../../packages/dsh-codex-auth-bridge

How it works

At startup, every ten minutes, and immediately before an openai-codex LLM stream:

1. read ${CODEX_HOME:-~/.codex}/auth.json; 2. decode the access-token expiry; 3. refresh an expired or soon-to-expire token through @earendil-works/pi-ai; 4. atomically write rotated tokens back to Codex's auth.json; 5. store the current access token under OPENAI_CODEX_ACCESS_TOKEN using DSH's credential service.

The bundle also configures this composition base:

llm-pi-ai:
  providers:
    openai-codex:
      apiKeyEnv: OPENAI_CODEX_ACCESS_TOKEN

Because api is intentionally omitted, dsh-llm-pi-ai reuses pi-ai's provider-native openai-codex-responses transport instead of treating the ChatGPT backend as a generic OpenAI endpoint.

Environment overrides

VariableDefaultPurpose
DSH_CODEX_AUTH_PATH${CODEX_HOME:-~/.codex}/auth.jsonExact Codex auth file
DSH_CODEX_CREDENTIAL_REFOPENAI_CODEX_ACCESS_TOKENDSH credential reference
DSH_CODEX_PROVIDER_IDopenai-codexProvider route preflighted before requests
DSH_CODEX_REFRESH_MARGIN_MS300000Refresh margin before JWT expiry
DSH_CODEX_SYNC_INTERVAL_MS600000Background synchronization interval

If you override DSH_CODEX_CREDENTIAL_REF, also update apiKeyEnv in the bundle or your DSH settings.

Security notes

  • Codex's auth.json contains a rotating refresh token and must remain private.
  • DSH's local credential provider writes the synchronized access token to $DSH_HOME/.credentials.yaml, normally with mode 0600.
  • The plugin never logs token values.
  • A compare-before-write check avoids overwriting a newer refresh token if Codex refreshes concurrently.

Development

npm install
npm test
npm run check

License

MIT