sudipnext/dsh-chatgpt-codex
DeepSeek Harness 的 ChatGPT OAuth 和 Codex 模型 — 浏览器回调、设备代码、无需 API 密钥、无 pi-ai
项目介绍Project Overview
这是一个 DSH 插件,让 DeepSeek Harness 通过 ChatGPT 账号使用 Codex 模型,无需 OpenAI API Key。它支持浏览器 PKCE 与无头设备码 OAuth、自动刷新令牌,并把 Codex Responses 流式接入 DSH 消息和工具协议。适合桌面、SSH 或容器中以主模型方式调用 Codex。注意:模型可用性取决于 ChatGPT 套餐、区域和策略,且依赖 DSH next API。
This DSH plugin lets DeepSeek Harness use Codex models through a ChatGPT account, with no OpenAI API key. It supports browser PKCE and headless device-code OAuth, automatic token refresh, and streams Codex Responses into DSH messages and tools. Use it when running Codex as a main DSH model on desktop, SSH, or containers. Model availability depends on the ChatGPT plan, region, and policy, and it targets the pre-release DSH next API.
请帮我了解并安装插件:【dsh-chatgpt-codex】【https://github.com/sudipnext/dsh-chatgpt-codex】
把上面这条消息直接发给当前会话里的 DSH,让它帮你了解并安装。安装命令不一定准确,发给 DSH 更稳。Send this message to DSH in your current session. CLI install commands may not be accurate across systems — DSH will figure it out for you.
或使用命令行安装(适合开发者)Or use CLI install (for developers)
命令行安装CLI Install
dsh plugin --profile codex add github:sudipnext/dsh-chatgpt-codex#v0.1.0
把 sudipnext/dsh-chatgpt-codex 加入你的 DSH 配置(web profile)即可启用。
READMEREADME
dsh-chatgpt-codex
Use your ChatGPT account and Codex models inside DeepSeek Harness. This standalone DSH plugin supports both a localhost browser callback and headless device-code authentication, refreshes OAuth tokens automatically, and streams Codex Responses into the native DSH message/tool protocol.
No OpenAI API key. No pi-ai runtime dependency.
[!IMPORTANT] DeepSeek Harness does not currently ship ChatGPT/Codex OAuth for its main model route. It has a Codex subagent launcher that reuses the official Codex app's login, but that is a separate one-shot delegation path. This plugin fills the main-model gap and targets the current DSH
nextAPI (0.1.0-rc.6or newer).
Features
- ChatGPT browser OAuth with PKCE, a strict state check, and a localhost callback
- ChatGPT device-code OAuth for SSH, containers, and headless machines
- Automatic access-token refresh with in-process and cross-process rotation locks
- Owner-only atomic credential storage under
$DSH_HOME - Native
openai-codexDSH model provider—nopi-aiadapter - Official OpenAI JavaScript SDK for the Codex Responses transport
- Streaming text, reasoning summaries, function calls, images, usage, and finish reasons
- Encrypted reasoning-item replay for correct multi-turn Codex sessions
- Current GPT-5.6 Luna, Terra, and Sol discovery entries, plus GPT-5.5/5.4 models
Install in two minutes
The repository commits its built artifacts, so GitHub installation does not run a dependency prepare script.
1. Sign in with ChatGPT
Browser callback (recommended on a desktop):
pnpm dlx github:sudipnext/dsh-chatgpt-codex#v0.1.0 login
Device code (recommended over SSH or in a container):
pnpm dlx github:sudipnext/dsh-chatgpt-codex#v0.1.0 login --device
The default credential file is $DSH_HOME/chatgpt-codex/auth.json, or ~/.dsh/chatgpt-codex/auth.json when DSH_HOME is unset.
2. Add the DSH bundle
dsh plugin --profile codex add github:sudipnext/dsh-chatgpt-codex#v0.1.0
3. Run DeepSeek Harness
dsh --profile codex
The bundle registers openai-codex and selects gpt-5.6-luna as the profile's default model. A later profile patch can choose another model.
Authentication commands
# Browser callback without automatically opening a browser
dsh-chatgpt-codex login --no-open
# Device authorization; the code expires after 15 minutes
dsh-chatgpt-codex login --device
# Safe status output never prints tokens
dsh-chatgpt-codex status
dsh-chatgpt-codex status --json
# Rotate the access token immediately
dsh-chatgpt-codex refresh
# Remove local credentials
dsh-chatgpt-codex logout
For a GitHub-only installation, prefix these commands with pnpm dlx github:sudipnext/dsh-chatgpt-codex#v0.1.0.
Configuration
Override the plugin row in the profile's $DSH_HOME/profiles/<name>/cordis.patch.yml:
- id: llm-chatgpt-codex
config:
defaultReasoningEffort: high
textVerbosity: low
requestTimeoutMs: 300000
- id: agent-default-model
config:
provider: openai-codex
model: gpt-5.6-terra
Available plugin settings:
| Setting | Default | Purpose |
|---|---|---|
authFile |
$DSH_HOME/chatgpt-codex/auth.json |
OAuth credential document |
issuer |
https://auth.openai.com |
OAuth issuer, primarily for compatible deployments/tests |
baseURL |
https://chatgpt.com/backend-api/codex |
Codex Responses base URL |
originator |
dsh-chatgpt-codex |
Honest product identity sent upstream |
models |
Current bundled catalog | Advisory DSH model picker entries |
defaultReasoningEffort |
high |
low, medium, high, xhigh, or max |
textVerbosity |
low |
low, medium, or high |
requestTimeoutMs |
300000 |
Provider request timeout |
The model catalog is advisory. Actual model availability depends on the signed-in ChatGPT plan, workspace policy, region, and current OpenAI rollout.
Why this does not use pi-ai
DeepSeek Harness's general llm-pi-ai adapter intentionally does not expose OAuth-only providers because it has no credential store or login lifecycle. This project owns the missing lifecycle directly:
- The CLI performs ChatGPT PKCE or device-code authentication.
AuthManagerstores and rotates the OAuth token set.CodexAdapterconverts native DSH history/tools to stateless Responses input.- The official
openaiSDK carries the HTTPS/SSE transport. - The stream translator emits DSH blocks and stores the encrypted replay items needed on the next turn.
See Architecture for the exact components and trust boundaries.
Security
- OAuth state is cryptographically random and compared in constant time.
- PKCE uses S256 and a fresh verifier for every login.
- The callback server listens only on
127.0.0.1and closes after one result. - Credentials are written atomically with mode
0600on POSIX; parent storage uses0700. - Tokens are never printed by status, errors, tests, or logs.
- This plugin uses its own credential file rather than copying
~/.codex/auth.json, avoiding refresh-token rotation races with the official Codex client.
Read SECURITY.md before reporting a vulnerability. logout removes local credentials but does not revoke the OpenAI session remotely.
Compatibility and status
This is an independent community plugin, not an official OpenAI or DeepSeek project. Both Codex's private ChatGPT backend and pre-release DSH APIs can change. The repository pins behavior with keyless OAuth, wire, replay, and storage tests; releases describe any required migration.
Using ChatGPT/Codex remains subject to your OpenAI account terms and workspace policy. A ChatGPT subscription does not guarantee every catalog model.
Development
pnpm install
pnpm run check
The test suite uses local HTTP servers and synthetic JWTs; it does not require or read real ChatGPT credentials.
License
MIT © 2026 sudipnext
nexu-io/open-design
freestylefly/awesome-gpt-image-2
anywhere-labs/dsh-desktop
walkinglabs/learn-harness-engineering
awesome-dsh-plugin/awesome-dsh-plugin
MemTensor/MemOS