dsh-codex-auth-bridge
Reuse the Codex CLI's ChatGPT OAuth login in DeepSeek Harness (DSH).
The package is a Host Cordis bundle. It reads Codex's auth.json, keeps the OAuth token fresh through pi-ai's native openai-codex OAuth implementation, synchronizes the access token into DSH's credential service, and configures pi-ai's built-in openai-codex model route.
It does not contain, upload, or commit any token.
Requirements
- Node.js 22.19 or later
- A DSH installation using the
dsh-llm-pi-aiadapter - Codex logged in with ChatGPT (
~/.codex/auth.jsoncontainsauth_mode: "chatgpt")
Install
Run this on each device after logging in with Codex:
npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0The installer:
1. adds this package to ~/.dsh/profiles/web/package.json; 2. adds dsh-codex-auth-bridge to that profile's dsh.profile.bundles list; 3. runs pnpm install in the profile.
Restart dsh web afterward. The model picker will include the models exposed by pi-ai's installed openai-codex catalog.
Use another profile or source when needed:
npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0 --profile web
node ./bin/install.js --source file:../../packages/dsh-codex-auth-bridgeHow it works
At startup, every ten minutes, and immediately before an openai-codex LLM stream:
1. read ${CODEX_HOME:-~/.codex}/auth.json; 2. decode the access-token expiry; 3. refresh an expired or soon-to-expire token through @earendil-works/pi-ai; 4. atomically write rotated tokens back to Codex's auth.json; 5. store the current access token under OPENAI_CODEX_ACCESS_TOKEN using DSH's credential service.
The bundle also configures this composition base:
llm-pi-ai:
providers:
openai-codex:
apiKeyEnv: OPENAI_CODEX_ACCESS_TOKENBecause api is intentionally omitted, dsh-llm-pi-ai reuses pi-ai's provider-native openai-codex-responses transport instead of treating the ChatGPT backend as a generic OpenAI endpoint.
Environment overrides
| Variable | Default | Purpose |
|---|---|---|
DSH_CODEX_AUTH_PATH | ${CODEX_HOME:-~/.codex}/auth.json | Exact Codex auth file |
DSH_CODEX_CREDENTIAL_REF | OPENAI_CODEX_ACCESS_TOKEN | DSH credential reference |
DSH_CODEX_PROVIDER_ID | openai-codex | Provider route preflighted before requests |
DSH_CODEX_REFRESH_MARGIN_MS | 300000 | Refresh margin before JWT expiry |
DSH_CODEX_SYNC_INTERVAL_MS | 600000 | Background synchronization interval |
If you override DSH_CODEX_CREDENTIAL_REF, also update apiKeyEnv in the bundle or your DSH settings.
Security notes
- Codex's
auth.jsoncontains a rotating refresh token and must remain private. - DSH's local credential provider writes the synchronized access token to
$DSH_HOME/.credentials.yaml, normally with mode0600. - The plugin never logs token values.
- A compare-before-write check avoids overwriting a newer refresh token if Codex refreshes concurrently.
Development
npm install
npm test
npm run checkLicense
MIT