duhu2000/qcc-mcp-oauth

Plugin插件 Native原生 ⭐ 4 MIT Models & Routing模型与路由

DeepSeek Harness插件:一键OAuth授权连接企查查MCP服务

Project Overview项目介绍

This is a native plugin built exclusively for DeepSeek Harness (DSH) that enables one-click OAuth 2.0 connection to Qichacha’s MCP enterprise data services. It supports the Authorization Code flow with PKCE(S256) encryption and dynamic client registration, so users do not need to pre-configure a client secret to get started. To install the plugin, users can either send the GitHub repository link to their DSH agent for automatic installation, or run a one-click curl script, or install it manually via the DSH CLI. It can also be installed directly from npm or cloned from GitHub for local debugging.

This plugin is designed for DSH users who need to access Qichacha’s enterprise data directly within their DSH conversation workflow. After installation and a required restart of the DSH web process, the plugin will automatically open the Qichacha authorization page in the user’s default browser if no valid token is detected. Users can also manually trigger the connection by typing “connect Qichacha” in the DSH chat, check the current connection status, or disconnect the service at any time via dedicated chat commands. Once connected, all authorized MCP tools are immediately available to use in conversation.

The plugin is released under the permissive MIT open source license, and requires Node.js 20 or newer to run, along with an existing DSH web profile installation. Access tokens are stored locally in the DSH storage directory with 0700 permissions, so they never get committed to git or included in conversation history for better security. One key limitation is that personal Qichacha accounts only get access to 5 of the 6 default data endpoints offered by the plugin, with full historical enterprise data requiring a business certification from Qichacha.

这是一款专为DeepSeek Harness(DSH)开发的原生插件,用于在DSH中一键通过OAuth 2.0授权接入企查查的MCP数据服务,支持获取工商、风险、知产、经营、董监高及企业历史等六大类企业数据。插件采用Authorization Code + PKCE(S256)流程,支持动态客户端注册,无需提前配置client_secret,授权完成后自动完成接入。

面向需要在DeepSeek Harness对话中查询企业工商信息的开发者与从业者,完成安装重启后,插件会在激活状态检测到无有效授权时自动打开浏览器跳转至企查查授权页,用户也可手动输入“连接企查查”触发授权流程。用户授权完成后,即可直接在对话中调用企查查MCP工具查询所需数据,还可随时查询连接状态或一键断开授权。

本插件基于MIT许可开源,要求安装环境为Node.js 20及以上版本和DSH的web profile。token默认存储在DSH本地存储目录(权限0700),不会进入代码仓库和对话历史,较为安全。已知限制包括个人账号默认仅支持5类企查查数据接口,历史数据需要企业认证后才可使用。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 4 stars - very few users, little community feedback星标只有 4,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add qcc-dsh-mcp-oauth

把 duhu2000/qcc-mcp-oauth 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

企查查 MCP OAuth 插件(DeepSeek Harness)

One-click OAuth connect to 企查查 (Qichacha) MCP services inside DeepSeek Harness. 在 DeepSeek Harness 中一键 OAuth 授权接入企查查 MCP 数据(工商 / 风险 / 知产 / 经营 / 董监高)。

License: MIT

功能 / Features

  • 🔑 一键 OAuth 连接:Authorization Code + PKCE(S256),动态注册客户端(无 client_secret),自动打开浏览器跳转企查查授权页,loopback 回调自动完成
  • 🌐 一次授权、全 Server 可用:一份 access_token / refresh_token 覆盖企查查 MCP 企业数据 SERVER(company / risk / ipr / operation / history / executive,共 6 个);history(历史信息)需企业认证,插件按 token 实际授权范围动态挂载——企业认证账号 6 个、个人账号 5 个
  • 🔄 自动刷新:access_token 过期前自动 refresh(token 轮换),失败才需要重新授权
  • 💾 安全持久化:token 存储于 DSH 存储域(~/.dsh/storages,目录 0700),重启 Host 自动恢复连接
  • 🛠 对话即管理:内置 qcc_oauth_connect / qcc_oauth_status / qcc_oauth_disconnect 三个工具
  • 🚪 一键断开:调用 OAuth revoke 撤销 refresh_token 并停用 MCP 工具

安装 / Install

前置:DeepSeek Harness(dsh CLI,web profile),Node ≥ 20。

🤖 让 Agent 安装(最省事,推荐给不熟悉命令行的用户)

把下面的链接直接发给你的 DeepSeek Harness 对话(推荐先在 dshmarket 插件市场搜索「企查查」一键安装;市场直装失败时,同样把链接发给 Agent 即可代为安装):

帮我安装这个插件 https://github.com/duhu2000/qcc-mcp-oauth

Agent 会按本 README 执行以下命令(你也可以自己跑):

# 方式一:一键脚本(自动安装 + 注册 bundle + 提示重启)
bash <(curl -fsSL https://raw.githubusercontent.com/duhu2000/qcc-mcp-oauth/main/install.sh)

# 方式二:手动两步
dsh plugin --profile web add qcc-dsh-mcp-oauth   # 安装依赖并自动注册 bundle
# 重启 dsh web

说明:安装时的 peer dependencies 警告可忽略——@deepseek-ai/* 等对等依赖由 DSH web profile 自带(host 依赖),无需另行安装;安装完成后必须重启 dsh web 才能生效。

方式 A:npm 安装

# 1. 安装插件到 profile(声明了 dsh.bundle 的包会被 dsh plugin add 自动注册到 bundles)
dsh plugin --profile web add qcc-dsh-mcp-oauth

# 2. 重启 dsh web

若未自动注册:手动在 ~/.dsh/profiles/web/package.json 的 dsh.profile.bundles 追加 "qcc-dsh-mcp-oauth"(与 @deepseek-ai/dsh-base、@deepseek-ai/dsh-web-app 并列),再重启。

方式 B:GitHub 直装

dsh plugin --profile web add github:duhu2000/qcc-mcp-oauth
# 再重启 dsh web

方式 C:源码 / 本地调试

git clone https://github.com/duhu2000/qcc-mcp-oauth.git
cd qcc-mcp-oauth
dsh plugin --profile web add "link:$(pwd)"      # 或 pnpm add "file:$(pwd)"
# 再重启 dsh web

Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →

← 上一个 Prev dsh-client-ui-aqua-unofficial 下一个 Next dsh-agent-team-room →