MirDie/dsh-xai
xAI Grok SuperGrok / X Premium OAuth,用于DeepSeek Harness
Project Overview项目介绍
This is a native plugin built exclusively for DeepSeek Harness (DSH). It enables users to access SuperGrok and X Premium subscriptions via xAI’s device-code sign-in flow, eliminating the need for a manually configured XAI_API_KEY or any source patches to DSH itself. It supports OAuth authentication through both DSH’s settings panel and a standalone CLI command, with automatic token refresh built in. It can also optionally import existing credentials from the Grok CLI’s ~/.grok/auth.json file without altering the original file in any way.
Installation is straightforward for end users and does not require cloning the repository first. You can run the dsh plugin add command to fetch the package directly into your active DSH profile. If you launched DSH via npx and do not have dsh available on your system PATH, you can use npx @deepseek-ai/dsh plugin add instead to complete installation. After installation, you can sign in via the graphical settings panel, or use the CLI for headless or SSH-connected hosts to manage your account.
Stored credentials are saved in $DSH_HOME/.xai-oauth-auth.json, which defaults to ~/.dsh on most systems. All writes to the credential file are atomic, and token refresh is locked across local DSH processes to prevent race conditions. Note that xAI rotates refresh tokens, so after importing credentials from Grok CLI, your existing Grok CLI login may become invalid until you re-login there. This plugin is released under the open-source Apache-2.0 license.
这是一个专为 DeepSeek Harness (DSH) 开发的原生插件,允许用户通过 xAI 的设备码登录流程,在 DSH 中使用 SuperGrok 或 X Premium 订阅,无需配置 XAI_API_KEY,也不需要修改 DSH 源代码。它支持通过 DSH 设置面板或独立 CLI 完成 OAuth 登录,自带自动令牌刷新功能,还可以可选地从 Grok CLI 的 ~/.grok/auth.json 导入已有凭证,且不会修改原文件。登录或导入完成后,插件会从已登录的 xAI 账号拉取可用模型展示在 DSH 的模型选择器中,本地已安装的模型目录会作为备选。
对于普通用户来说,安装流程非常简单,不需要克隆仓库,只需要通过 DSH 的 CLI 执行 dsh plugin add 命令拉取包到当前配置文件即可。如果是通过 npx 启动 DSH 且本地没有 dsh 命令在环境变量中,也可以直接用 npx @deepseek-ai/dsh plugin add 完成安装。登录操作既可以在图形界面的设置页面完成,也适合无图形界面的 SSH 或无头主机通过 CLI 完成登录、导入凭证、查看状态、登出等操作。
插件的凭证存储在 $DSH_HOME/.xai-oauth-auth.json(默认是 ~/.dsh),写入操作是原子性的,跨进程的令牌刷新也做了锁处理,浏览器端不会返回敏感的令牌信息。需要注意的是,xAI 的刷新令牌会轮换,导入凭证后,下次刷新可能会导致原 Grok CLI 失效,需要重新登录 Grok CLI。本项目采用 Apache-2.0 协议开源,部分 SuperGrok 订阅层级可能会出现登录成功但推理返回 403 的情况,这是 xAI 的权限限制,不是插件问题。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-xai(MirDie/dsh-xai)
仓库:https://github.com/MirDie/dsh-xai
本站详情页:https://www.yhbd.top/plugins/mirdie-dsh-xai/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 NOASSERTION · ⭐ 3 · 最近提交 2026-09-23 · 主语言 JavaScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add github:MirDie/dsh-xai
把 MirDie/dsh-xai 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-xai
English | 中文
Use a SuperGrok or X Premium subscription in DeepSeek Harness through xAI's device-code sign-in — no XAI_API_KEY required, and no dsh source patch required.
This is an independent dsh bundle. It adds:
- SuperGrok / X Premium OAuth from the dsh Settings panel or a standalone CLI, with automatic token refresh
- optional one-shot import of
~/.grok/auth.json(Grok CLI). The Grok file is never written - after login or import,
GET https://api.x.ai/v1/modelsnarrows the picker to the signed-in account; the installed catalog is the fallback - streaming, tool calls, reasoning, and dsh compaction through the normal LLM service
The catalog xai API-key route stays untouched. This plugin registers xai-oauth so both can coexist.
Install
You do not need to clone this repository first. dsh plugin add fetches the package into the profile:
dsh plugin --profile web add github:MirDie/dsh-xai
dsh web
If you started the UI with npx and have no dsh on PATH, use the same package as the CLI:
npx @deepseek-ai/dsh plugin --profile web add github:MirDie/dsh-xai
npx @deepseek-ai/dsh web
Do not run npm dsh or pnpm dsh from your home directory. npx does not install a global dsh command.
Clone only when you are changing this plugin:
git clone https://github.com/MirDie/dsh-xai.git
dsh plugin --profile web add ./dsh-xai
Open Settings → xAI Grok → Sign in with SuperGrok. The plugin starts xAI's device-code flow, opens the verification URL, and polls until you approve. Headless / SSH hosts can use the CLI instead:
dsh plugin --profile web exec dsh-xai login
dsh plugin --profile web exec dsh-xai import
dsh plugin --profile web exec dsh-xai status
dsh plugin --profile web exec dsh-xai logout
The bundle selects xai-oauth / grok-4.5 for new agents. A model already saved in dsh settings still takes precedence.
The Settings page can choose which account models appear in the composer picker (xai-oauth / <id>). After updating the plugin, restart dsh web if the picker is still empty.
See INSTALL.md / INSTALL.zh.md for the full runbook.
Showing the opening section of the README — the full document lives in the repository以上为 README 开头摘要,完整文档在仓库内 · View the full README on GitHub →在 GitHub 查看完整 README →
Q00/ouroboros
crafter-station/petdex
whiteguo233/OpenBiliClaw
anywhere-labs/Agents-Anywhere
agentrq/agentrq
freestylefly/wesight