mingzeng21/dsh-notion
通过官方 Notion MCP 将 DeepSeek Harness (dsh) 连接到 Notion —— OAuth 2.0 + PKCE,一次性登录,静默令牌刷新。
Project Overview项目介绍
dsh-notion is a native plugin built exclusively for DeepSeek Harness (DSH) that connects your DSH agent to Notion via the official Notion MCP server. It uses the OAuth 2.0 protocol with authorization code and PKCE flow to handle authentication, so you only need to complete a one-time authorization in your browser to get full access. After authorization, your DSH agent can use a set of standard prefixed tools mcp__notion__* to search, read, and write Notion pages, databases, and comments directly from within DSH. It supports dynamic client registration per RFC 7591, so you never need to manually copy a client ID or secret to use it.
To install the plugin, you run the command dsh plugin --profile <your-profile-name> add dsh-notion-mcp, replacing the profile placeholder with the profile you use to run your DSH agent, such as web, headless, or tui. To complete authorization, you run dsh --profile notion notion login in a minimal profile, which will output an authorization URL and spin up a temporary local HTTP server on port 53007 to catch the Notion callback. Once you approve access in your browser, the plugin verifies the state, exchanges the authorization code for an access token, saves the token securely, and mounts the Notion MCP client. This plugin is ideal for users who want their DSH agent to interact directly with content stored in their Notion workspace.
This plugin requires DSH version v0.1.0-rc.8 or newer, and Node.js version ^22.19.0 or >=24.0.0; Node.js 23 is explicitly not supported. Tokens are stored atomically in DSH's built-in credential layer, and the plugin repository never contains any embedded secrets or user tokens. The plugin automatically refreshes access tokens before they expire, which is approximately every 8 hours, and handles the invalid_grant error by clearing expired tokens and prompting for re-authorization. It is released under the open source MIT license, and one authorization works globally across all DSH profiles that install the plugin.
dsh-notion 是专为 DeepSeek Harness (DSH) 开发的原生插件,通过官方 Notion MCP 服务器,使用 OAuth 2.0(授权码 + PKCE)流程将 DSH 连接到 Notion。用户只需要在浏览器完成一次性授权,DSH agent 就可以通过标准 mcp__notion__* 工具对 Notion 的页面、数据库和评论进行搜索、读取和写入操作,支持动态客户端注册,无需手动复制客户端ID或密钥。
安装完成后,插件会自动完成完整 OAuth 流程、将令牌安全存储到 DSH 的凭据层,并在后台静默刷新令牌保持有效性,最后将 Notion 的各类工具以标准命名格式挂载给 agent。它适合需要让 DSH agent 直接读写 Notion 工作区内容的用户,比如让 agent 总结技术文档后写入 Notion 存档,或是从 Notion 数据库读取信息供 agent 分析。
本插件要求环境为 DeepSeek Harness v0.1.0-rc.8 及以上版本,Node.js 版本需为 22.19.0 以上或 24.0.0 以上,Node 23 不在支持范围内。令牌完全存储在 DSH 的凭据层,仓库本身不包含任何密钥或用户令牌,采用 MIT 许可证开源,授权一次即可在所有配置了该插件的 DSH 配置文件中使用。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-notion(mingzeng21/dsh-notion)
仓库:https://github.com/mingzeng21/dsh-notion
本站详情页:https://www.yhbd.top/plugins/mingzeng21-dsh-notion/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 5 · 最近提交 2026-09-26 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 5 stars - very few users, little community feedback星标只有 5,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-notion-mcp
把 mingzeng21/dsh-notion 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-notion-mcp
通过官方 Notion MCP 服务器,用 OAuth 2.0(授权码 + PKCE)把 DeepSeek Harness(dsh)连接到 Notion。完成一次性浏览器授权后,你的 dsh agent 就能通过标准的 mcp__notion__* 工具搜索、读取和写入 Notion 的页面、数据库与评论。
中文 | English
它能帮你做什么
装上 dsh-notion-mcp 后,你的 dsh agent 即可直接读写 Notion。你只需要在浏览器里完成一次授权,剩下的事插件都会自动打理:跑完整套 OAuth 2.0(授权码 + PKCE)流程、把 token 安全保存到 dsh 的凭据层、在后台静默刷新保持有效,并把 Notion 的搜索、页面、数据库、评论等工具以 mcp__notion__* 的形式挂载给 agent。
特性
- 零配置 OAuth —— 动态客户端注册(RFC 7591)在运行时注册客户端,无需复制任何
client_id或密钥。 - 一次性浏览器登录 ——
dsh notion login打印授权 URL,并在127.0.0.1:53007等待回调。 - 静默刷新 token —— access token(约 8 小时)到期前自动刷新;轮换后的 refresh token 原子落盘。
invalid_grant终态处理 —— 过期或已被轮换作废的 refresh token 绝不重试;插件会清掉它并提示你重新授权。- 仓库不含任何密钥 —— token 存在 dsh 的凭据存储里,不进入本仓库。
截图
让 dsh agent 总结一段技术架构并写入 Notion:

写好的 Notion 页面:

工作原理
dsh notion login
│ 1. OAuth 发现(RFC 9470 / RFC 8414)
│ 2. 动态客户端注册(RFC 7591)
│ 3. PKCE S256 + state → 授权 URL
▼
浏览器批准 → 回调到 127.0.0.1:53007
│ 4. 用 code(加 PKCE verifier)换取 token
▼
token 落盘 → Notion MCP 挂载为 mcp__notion__*
启动时插件会读取已存 token 并挂载 MCP 客户端;临近过期时在后台刷新(串行化,避免并发重放已轮换的 refresh token)。
安装
dsh plugin --profile web add dsh-notion-mcp
把 web 换成你运行 agent 所用的 profile(web、headless、tui 等)。
授权
notion 命令需要在一个「最小 profile」里运行——像 web 这类 UI app 会独占自己的命令行,不会把 notion 转发给插件。token 是全局存储的,所以在任意最小 profile 里授权一次,所有安装了本插件的 profile 都能直接使用:
dsh plugin --profile notion add dsh-notion-mcp
dsh --profile notion notion login
该命令会注册一个动态 OAuth 客户端,在 127.0.0.1:53007 起一个临时本地 HTTP 服务,并打印授权 URL。在浏览器里打开并批准后,Notion 会重定向到 http://127.0.0.1:53007/callback,插件校验 state、用 code(加 PKCE verifier)换取 token、落盘并挂载客户端。
授权完成后,Notion 工具即以 mcp__notion__* 形式可用。
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
Q00/ouroboros
crafter-station/petdex
whiteguo233/OpenBiliClaw
anywhere-labs/Agents-Anywhere
agentrq/agentrq
freestylefly/wesight