spirits001/dsh-tokensforce
DeepSeek Harness(dsh)插件——tokensforce 网关集成:一键登录接入、供应商分组和使用仪表板标签页
Project Overview项目介绍
dsh-tokensforce is a native plugin built exclusively for DeepSeek Harness (DSH) that connects your local DSH instance to the TokensForce token gateway. To install the plugin, you can run the DSH CLI command dsh plugin --profile web add dsh-tokensforce and then start the DSH web client with the dsh web command. If you get an ERR_PNPM_ADDING_TO_ROOT error with older versions of pnpm, you can manually install the package in the ~/.dsh/profiles/web directory and add the package name to the dsh.profile.bundles list in that directory’s package.json to complete setup.
After you install the plugin and start DSH for the first time, if no models have been configured on your DSH instance, the plugin will automatically pop up a full-screen login window for TokensForce. The login process is identical to the official website version, using email verification codes to authenticate your personal account. Once you log in, if your account is associated with multiple organizations or groups within an organization, you can select which one you want to connect; if there is only one, this step is automatically skipped. After selection, the API key and gateway address are automatically added to your local DSH configuration, so you can start using the new models right away.
The plugin adds a dedicated TokensForce usage dashboard tab to your DSH session view, placed next to the default Conversation and Trace tabs. Clicking the tab opens the official TokensForce dashboard where you can check your token usage, costs, and model rankings. If you are not logged in or your login has expired, the tab will automatically show the login window again. The plugin also supports connecting to self-hosted TokensForce instances: you just need to modify the site origin constant in the source code and rebuild to connect to your private deployment. All credentials are stored locally via DSH’s built-in credential system, and the plugin is released under the permissive MIT open source license.
这是一款专为 DeepSeek Harness (DSH) 开发的原生插件,用于接入 TokensForce 词元网关。它支持用户登录一次即可直接使用网关内的模型,无需手动填写 API 密钥,也不需要修改本地配置文件,安装流程十分简便。用户可以通过 DSH 官方 CLI 执行 dsh plugin --profile web add dsh-tokensforce 命令完成安装,之后启动 DSH 网页端即可,若遇到旧版 pnpm 的安装错误,也可手动完成安装配置。
完成安装首次启动 DSH 后,若还未配置任何模型,插件会自动弹出全屏的 TokensForce 登录窗口,登录流程和官网网页版完全一致,采用邮箱验证码登录。登录完成后,如果账号归属多个企业或企业下有多个分组,用户可自行选择目标分组,若只有一个则自动跳过该步骤。所选分组的 API 密钥和网关地址会自动写入配置,用户选择模型即可开始对话。
插件还提供用量仪表盘入口,会在 DSH 会话视图新增一个和「对话」「轨迹」并列的「TokensForce」标签,点击即可查看用量、费用等数据。它支持接入私有部署的 TokensForce 实例,只需修改插件内的站点地址常量重新构建即可,密钥通过 DSH 自带的凭据机制存储在本地,十分安全。本插件采用 MIT 开源许可证,可免费使用和二次开发。
请帮我安装这个 DSH 插件。安装前先完成【兼容性检查 + 安全性检查】,检查通过再动手。
插件:dsh-tokensforce(spirits001/dsh-tokensforce)
仓库:https://github.com/spirits001/dsh-tokensforce
本站详情页:https://www.yhbd.top/plugins/spirits001-dsh-tokensforce/
本站登记:类型 plugin · 归类 原生 DSH 插件 · 许可证 MIT · ⭐ 2 · 最近提交 2026-09-05 · 主语言 TypeScript
按下面顺序执行,每步先把结论告诉我,再进入下一步:
【1 兼容性检查】
① 我这边:DSH 版本、Node 版本、操作系统、当前 profile(web / desktop)。
② 读它的 README、package.json、插件 manifest,列出它要求的 DSH 版本 / Node 版本 / 操作系统 / 外部依赖 / 需要另外先装的运行时。
③ 逐条比对,结论只写「满足 / 不满足 / 未知」三种;不满足的给出可行替代方案。
④ 检查是否和我已装的插件冲突:命令名重复、skill / tool 重名、端口占用、重复注册的 MCP server。
【2 安全性检查】
① 仓库可信度:和上面「本站登记」是否一致;star / fork 数、创建时间、最近提交,是否归档或长期停更。
② 安装脚本:逐行看 package.json 的 preinstall / install / postinstall,以及 install.sh、setup.ps1 之类脚本。出现 curl|bash、下载后直接执行、混淆代码、访问与插件功能无关的域名,立刻停下来告诉我,不要继续装。
③ 依赖:列出新增依赖,标出无人维护、或与知名包拼写近似的可疑包(typosquatting)。
④ 权限与副作用:它会读写哪些目录、访问哪些域名、需要哪些 DSH 权限(filesystem / network / shell / clipboard 等),以及怎么卸载和回滚。
⑤ 如果它要求 sudo / 管理员权限,或权限明显超出功能所需,先停下来问我。
【3 安装】
上面两步没有「不满足」和「高危项」时才执行;用官方推荐方式安装,不要自行提权。
【4 汇报】
用表格输出:检查项 / 结论 / 依据 / 是否需要我决策。拿不准的一律写「未知」并说明要我怎么确认——不要猜,也不要替我决定。
Send this message to DSH in your current session: it verifies compatibility and security first (answering met / not met / unknown item by item) and only installs once everything checks out — it will stop and ask you if it finds a high-risk item. The box scrolls; the copy is the full prompt. CLI install commands may not be accurate across systems, so DSH is the safer route.把上面这条消息直接发给当前会话里的 DSH:它会先核对兼容性与安全性(逐条给「满足 / 不满足 / 未知」),确认没问题再安装,有高危项会停下来问你。框内可滚动,复制到的是完整提示词;安装命令不一定准确,发给 DSH 更稳。
- Only 2 stars - very few users, little community feedback星标只有 2,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项
Compatibility兼容性
- DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
- External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
- Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册
Security安全性
- Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
- Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
- curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
- Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
- Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
- Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式
Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。
Or use CLI install (for developers)或使用命令行安装(适合开发者)
CLI Install命令行安装
dsh plugin --profile web add dsh-tokensforce
把 spirits001/dsh-tokensforce 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-tokensforce
为 DeepSeek Harness(dsh)接入 TokensForce 词元网关:登录一次,模型即用。不需要手动填 API Key,不需要改配置文件。

安装
dsh plugin --profile web add dsh-tokensforce
dsh web
打开 http://127.0.0.1:3080,登录向导会自动弹出。
如果
dsh plugin add报ERR_PNPM_ADDING_TO_ROOT(旧版 pnpm),在~/.dsh/profiles/web目录下手动pnpm add -w dsh-tokensforce, 再把包名加入该目录package.json的dsh.profile.bundles列表即可。
使用
首跑:dsh 启动且尚未配置任何模型时,自动弹出近全屏的 TokensForce 登录窗口 (就是 tokensforce.com 的登录页,邮箱验证码登录,与网页版完全一致):

选企业 / 选组:账号属于多个企业或企业下有多个组时让你选,只有一个则自动跳过;
完成:所选组的 API Key 与网关地址自动写入,选个模型就能开始对话。 每个组在「设置 → 模型」里是一行独立的提供方,可编辑、删除、发现模型。 每个模型写入显式 1M 上下文(压缩时机、设置页容量显示都以此为准,不会显示成 dsh 的 256K 占位默认);网关若披露了某个模型的真实上下文,则按披露值精确到该模型。
之后再添加其他组:打开设置,点右上角的「连接 TokensForce」按钮。 登录态保留 7 天,期间添加新组不用重新登录。
用量仪表盘:会话视图里多一个「TokensForce」标签(与「对话」「轨迹」并列), 点开就是 tokensforce 控制台仪表盘(用量、费用、排行),与网页版一致; 未登录或登录过期时,该标签内直接显示登录窗口,登录后自动进入仪表盘。

常见问题
装上后官方 DeepSeek 提供方去哪了?
本插件会禁用 llm-deepseek 的首跑引导,避免开屏出现两处要 Key 的提示;
模型引擎仍走 dsh 自带的 OpenAI 兼容通道。卸载插件即恢复原状。
我们公司自己部署了 tokensforce,能用吗?
能。安装后把 node_modules/dsh-tokensforce/lib/client.js 里的
SITE_ORIGIN 改成你的站点地址并重启 dsh;站点侧需放行登录页嵌入
(nginx 对 /login 不发 X-Frame-Options 等,可参考 tokensforce 的实现)。
更正式的做法是 fork 本仓库,改 src/client/logic.ts 中的常量后自行构建。
密钥存在哪?
组密钥经 dsh 自带的凭据机制存在你本机(~/.dsh/.credentials.yaml),
浏览器只保留登录态(JWT,7 天有效)。模型请求由 dsh 宿主进程直连网关,
不经过浏览器。
反馈
- 使用问题:Issues
- 维护与二次开发:见 CONTRIBUTING.md
Ayuilos/Miffan
cloveric/tarocub
HuanLinOTO/dsh-plugin-aigc-canvas
zmh2000829/DSH-agent-bridge
wenzetan/dsh-llm-newapi