birat-chapagain/dsh-codex-oauth
Use your OpenAI Codex subscription (ChatGPT Plus/Pro) inside DeepSeek Harness — via OAuth, the same way the official Codex CLI and other harnesses do.
catalog 简介 / catalog descriptioncatalog description:DeepSeek Harness plugin: use your OpenAI Codex (ChatGPT Plus/Pro) subscription through OAuth
项目介绍Project Overview
dsh-codex-oauth 是 DeepSeek Harness 的社区插件,通过 ChatGPT OAuth 让你在 Harness 中使用 OpenAI Codex 订阅(Plus/Pro)。它提供文件凭据存储、/codex login 命令和 codex 提供商路由,支持浏览器与设备码登录及自动刷新。适合想用 Codex 订阅而非平台 API Key 的场景。注意:仅支持文本输入,令牌文件应像 API Key 一样保护,且不要把模型工作区指向 Harness 主目录。
dsh-codex-oauth is a community plugin for DeepSeek Harness that lets you use an OpenAI Codex subscription (ChatGPT Plus/Pro) through ChatGPT OAuth. It adds a file-backed credential store, the /codex login command, and a codex provider route, with browser or device-code login and automatic token refresh. Use it when you want subscription-based Codex access instead of a platform API key. Caveat: text input only; protect the token file like an API key, and do not point the model workspace at your Harness home.
请帮我了解并安装插件:【dsh-codex-oauth】【https://github.com/birat-chapagain/dsh-codex-oauth】
把上面这条消息直接发给当前会话里的 DSH,让它帮你了解并安装。安装命令不一定准确,发给 DSH 更稳。Send this message to DSH in your current session. CLI install commands may not be accurate across systems — DSH will figure it out for you.
或使用命令行安装(适合开发者)Or use CLI install (for developers)
命令行安装CLI Install
dsh plugin --profile web add github:birat-chapagain/dsh-codex-oauth
把 birat-chapagain/dsh-codex-oauth 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-codex-oauth
Use your OpenAI Codex subscription (ChatGPT Plus/Pro) inside DeepSeek Harness — via OAuth, the same way the official Codex CLI and other harnesses do.
The upstream harness's multi-provider adapter deliberately withholds openai-codex because Codex authenticates through ChatGPT OAuth, and that adapter holds no credential store and runs no login flow. This community plugin supplies both pieces as an installable bundle: a file-backed OAuth credential store, a /codex login human command, and a codex provider route registered on the public LLM seam.
- Built on the published seam packages (
@deepseek-ai/dsh-llm,@deepseek-ai/cordis) — no fork, no core change. - pi-ai's provider-owned Codex OAuth flows handle the wire protocol: browser login with a local callback server, headless device-code login, and automatic refresh under a cross-process credential-store lock.
- Tokens live in
$DSH_HOME/codex-oauth.json(0600, owner-only directory), the same place the CLI bin and the harness plugin both read.
Requirements
- A ChatGPT Plus or Pro subscription. (A plain OpenAI platform API key does not work — subscription access is bound to your ChatGPT account, not an API key.)
- DeepSeek Harness installed (
npx @deepseek-ai/dsh webor a source checkout).
Install
One command installs the bundle into the web profile (it writes the one-time pnpm build approvals and runs dsh plugin add for you):
npx --yes https://github.com/birat-chapagain/dsh-codex-oauth/releases/download/v0.1.6/dsh-codex-oauth.tgz install
Then restart dsh web and run /codex login once.
Manual alternatives (same effect, both use prebuilt artifacts with no build permission):
dsh plugin --profile web add https://github.com/birat-chapagain/dsh-codex-oauth/releases/download/v0.1.6/dsh-codex-oauth.tgz
# or, from git (pin a commit for reproducibility: github:…/…#<sha>):
dsh plugin --profile web add github:birat-chapagain/dsh-codex-oauth
pnpm 11.22+ hard-fails when any transitive dependency has an unapproved build script — pi-ai's tree carries two (@google/genai, protobufjs, both unused by the Codex route). The one-command installer approves exactly those packages, repairs their set this to true or false placeholders, and preserves every unrelated allowBuilds value, including explicit denials. A manual install that ends with ERR_PNPM_IGNORED_BUILDS just needs this one-time snippet in the profile's pnpm-workspace.yaml:
allowBuilds:
'@google/genai': true
protobufjs: true
(If pnpm prints different exact keys in its error, use those — the printed keys are authoritative.)
Expected peer-dependency warning
pnpm may report @deepseek-ai/cordis, @deepseek-ai/dsh-llm, or @deepseek-ai/dsh-invariants as missing peers. This bundle is a Harness plugin: Harness supplies those packages from the host installation, while the profile intentionally sets autoInstallPeers: false. pnpm checks only the profile's package graph and cannot see the host packages that Harness makes available when it loads plugins.
The warning alone is not an installation failure. Do not add duplicate Cordis, LLM, or invariants packages to the profile to silence it; duplicate host packages can create separate plugin contexts or service instances. Confirm the installation with dsh --profile web --dump-config, then start dsh web; investigate the warning only if either command fails or pnpm names a different missing package.
The profile manifest ends up listing the bundle after @deepseek-ai/dsh-base; verify the composed tree without booting:
dsh --profile web --dump-config
Log in
Logging in is a human command, not a model tool — it never enters a prompt.
Web UI
Type /codex login in the chat input. A browser window opens on the ChatGPT authorization page; complete it, and the command reports when the token is stored. Use /codex logout and /codex status to manage it. Device login needs instructions while authentication is pending, but a human command returns only one final result, so /codex login device immediately directs you to the CLI command below instead of starting a flow whose code the UI cannot show.
Headless / CLI
The bundle also ships a dsh-codex-oauth bin that runs outside the harness (the headless profile has no command plane):
npx dsh-codex-oauth login # browser flow (desktop)
npx dsh-codex-oauth login --method device # device-code flow (headless)
npx dsh-codex-oauth status
npx dsh-codex-oauth logout
Device flow prints a one-time code plus the OpenAI device-verification URL; enter the code on any device, and the CLI waits until you authorize and stores the token in the same file the harness reads.
Use Codex
The plugin registers provider route codex with the Codex catalog models (gpt-5.x-codex and friends, from the installed pi-ai catalog). Select codex / a Codex model in the Web model picker, or set the default for a headless profile in the profile's cordis.patch.yml:
- id: agent-default-model
config:
provider: codex
model: gpt-5.4
Per-session selection in the Web UI needs no patch. Provider, model, and capabilities resolve through the same LLM seam as shipped providers; prompts, tools, persistence, and history replay behave identically.
Configuration
| Field | Default | Meaning |
|---|---|---|
provider |
codex |
Provider route id the adapter registers. |
storePath |
$DSH_HOME/codex-oauth.json |
OAuth credential store location. |
transport |
sse |
Codex Responses transport: sse, websocket, websocket-cached, or auto. sse exits cleanly after one-shot headless turns; websocket/websocket-cached reuse the connection for long interactive sessions but keep one-shot processes alive. |
cacheRetention |
long |
pi-ai prompt-cache retention: none, short, long. |
streamIdleTimeoutMs |
300000 |
Maximum milliseconds without a provider stream event while a read is pending. A timeout aborts the SDK stream and returns a TIMEOUT LLM failure. |
Override in a later patch layer (profile cordis.patch.yml replaces this row's whole config):
- id: codex-oauth
config:
provider: codex
transport: sse
Security notes
- The store document is written atomically with
0600permissions under a0700directory, and a group/world-readable document is refused on POSIX. It holds your ChatGPT OAuth tokens — treat it like an API key. - The harness process and its tool subprocesses run as your user; like the upstream credentials document, this file is not hidden from tools the model can drive. Do not point the model's workspace at your Harness home.
- Only
httpsURLs issued by the login flow are ever handed to the browser opener. A missing or failing OS opener is reported without terminating the harness; the CLI still prints the URL for manual use. - The login flow is pi-ai's provider-owned implementation (authorization-code + device-code against
chatgpt.com); this plugin answers its interaction prompts and stores the result.
How it works
src/store.ts—FileCredentialStore, a persistent pi-aiCredentialStorewith serialized read-modify-write (dsh-atomic-write).src/auth.ts— login/status/logout over pi-ai'sopenai-codexOAuth provider.src/adapter.ts—CodexAdapter extends LlmAdapter(from@deepseek-ai/dsh-llm), registered withctx.llm.registerAdapter(['codex'], …);stream()resolves/refreshes auth through pi-ai, enforces provider-idle timeout, and aborts SDK work when its consumer stops.src/convert.ts— request/stream vocabulary conversion, adapted from@deepseek-ai/dsh-llm-pi-ai(MIT, © DeepSeek AI) with image attachment support and provider-native replay state omitted.src/index.ts— the Cordis function plugin (name/inject/Config/apply); registers the adapter and, when the composition mountsctx.commands, the/codexcommand.
Limitations
- Text only. Model metadata advertises only text input, and image content is refused with
UNSUPPORTED_CONTENTbefore any provider request. - No browser Models-page card. Configuration happens through the patch layer and the picker lists the route through the adapter registry; login is the bin or
/codexcommand, not the credentials page. - No provider-native replay state. Historical assistant messages replay as provider-neutral content (correct, but without signature/cache reuse).
- Browser login assumes a desktop browser. Machines without one run
dsh-codex-oauth login --method devicein a terminal. - One browser login at a time. The OAuth callback uses one local port; wait for one browser flow to finish before starting another. The store lock separately serializes credential writes.
Development
npm install
npm test # builds lib/ then runs vitest (unit + Loader composition + built-bin smokes)
The composition test boots the real dsh-llm service and this plugin through the Cordis Loader with only the pi-ai SDK mocked, and the bin tests exercise the built artifact under plain Node.
License
MIT. The conversion modules in src/convert.ts are adapted from @deepseek-ai/dsh-llm-pi-ai (MIT, © DeepSeek AI).
ruvnet/ruflo
amruthpillai/reactive-resume
volcengine/OpenViking
Molunerfinn/PicGo
titanwings/colleague-skill
nocobase/nocobase
Tencent/WeKnora