DeepSeek Harness 插件

dsh-codex-auth-bridge

Reuse the Codex CLI ChatGPT OAuth login in DeepSeek Harness through pi-ai's openai-codex provider.(英文原文)

跳到安装方式

来源信息

GitHub 仓库
shaomingbo/dsh-codex-auth-bridge
最近更新
2026年8月15日
分类
工具与能力
GitHub stars
0
载体类型
plugin
目录证据
上游声明已找到 dsh.bundle
证据路径
package.json#dsh.bundle
核对版本
0.1.0-rc.8
上游核对日期
2026-08-20

该证据由上游目录提供。本站没有安装、运行或安全审核这个插件。

安装

默认先复制一段 Prompt,让 Agent 读 GitHub 仓库和源码;需要自己装时再切到命令。

复制这段 Prompt,发给 DSH、Codex 或其他 Agent,让它先读 GitHub 仓库和源码。

请先不要安装或执行任何命令。阅读这个插件的 GitHub 仓库、README 和关键源码,然后用清楚、直接的方式回答以下问题,帮助我判断它是否适合我的需求:

1. 这个插件是什么,解决什么问题;
2. 适合哪些用户和典型使用场景;
3. 安装后如何使用,并给出一个最小使用示例;
4. 有哪些已知限制,以及隐私、安全、兼容性或维护风险;
5. 给出“推荐 / 有条件推荐 / 不推荐”的明确建议和理由。

请区分仓库明确说明、根据源码推断和未知信息。证据不足时请明确说明,不要猜测或照抄 README。

GitHub:https://github.com/shaomingbo/dsh-codex-auth-bridge
插件名:dsh-codex-auth-bridge
作者:shaomingbo

检查来源文件

安装前先看这个插件目录里的 README 和其他文件。

文件资源管理器3 个文件
README.md来源说明 · 只读预览

dsh-codex-auth-bridge

Reuse the Codex CLI's ChatGPT OAuth login in DeepSeek Harness (DSH).

The package is a Host Cordis bundle. It reads Codex's auth.json, keeps the OAuth token fresh through pi-ai's native openai-codex OAuth implementation, synchronizes the access token into DSH's credential service, and configures pi-ai's built-in openai-codex model route.

It does not contain, upload, or commit any token.

Requirements

  • Node.js 22.19 or later
  • A DSH installation using the dsh-llm-pi-ai adapter
  • Codex logged in with ChatGPT (~/.codex/auth.json contains auth_mode: "chatgpt")

Install

Run this on each device after logging in with Codex:

npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0

The installer:

1. adds this package to ~/.dsh/profiles/web/package.json; 2. adds dsh-codex-auth-bridge to that profile's dsh.profile.bundles list; 3. runs pnpm install in the profile.

Restart dsh web afterward. The model picker will include the models exposed by pi-ai's installed openai-codex catalog.

Use another profile or source when needed:

npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0 --profile web
node ./bin/install.js --source file:../../packages/dsh-codex-auth-bridge

How it works

At startup, every ten minutes, and immediately before an openai-codex LLM stream:

1. read ${CODEX_HOME:-~/.codex}/auth.json; 2. decode the access-token expiry; 3. refresh an expired or soon-to-expire token through @earendil-works/pi-ai; 4. atomically write rotated tokens back to Codex's auth.json; 5. store the current access token under OPENAI_CODEX_ACCESS_TOKEN using DSH's credential service.

The bundle also configures this composition base:

llm-pi-ai:
  providers:
    openai-codex:
      apiKeyEnv: OPENAI_CODEX_ACCESS_TOKEN

Because api is intentionally omitted, dsh-llm-pi-ai reuses pi-ai's provider-native openai-codex-responses transport instead of treating the ChatGPT backend as a generic OpenAI endpoint.

Environment overrides

VariableDefaultPurpose
DSH_CODEX_AUTH_PATH${CODEX_HOME:-~/.codex}/auth.jsonExact Codex auth file
DSH_CODEX_CREDENTIAL_REFOPENAI_CODEX_ACCESS_TOKENDSH credential reference
DSH_CODEX_PROVIDER_IDopenai-codexProvider route preflighted before requests
DSH_CODEX_REFRESH_MARGIN_MS300000Refresh margin before JWT expiry
DSH_CODEX_SYNC_INTERVAL_MS600000Background synchronization interval

If you override DSH_CODEX_CREDENTIAL_REF, also update apiKeyEnv in the bundle or your DSH settings.

Security notes

  • Codex's auth.json contains a rotating refresh token and must remain private.
  • DSH's local credential provider writes the synchronized access token to $DSH_HOME/.credentials.yaml, normally with mode 0600.
  • The plugin never logs token values.
  • A compare-before-write check avoids overwriting a newer refresh token if Codex refreshes concurrently.

Development

npm install
npm test
npm run check

License

MIT