zhangjianyu1006156/dsh-balance-display

DeepSeek API 余额显示插件:左下角余额胶囊、低余额预警、余额趋势、一键充值。密钥不出主机端。

Project Overview项目介绍

This is a DSH-native plugin built specifically for DeepSeek Harness that displays the remaining balance of a user’s DeepSeek API key in real time. It adds a balance capsule to the bottom of the DSH Web GUI left sidebar, and includes core features like low balance alerts, consumption trend tracking, and one-click direct access to DeepSeek’s official top-up page. All API key processing happens exclusively on the host side, so the key never gets exposed to the browser, eliminating the risk of key leakage through the client side. To install the published plugin from npm, users can simply run the command dsh plugin --profile web add dsh-balance-display from their terminal, then restart the dsh web process to activate it.

The plugin is designed for developers who use DeepSeek API and DeepSeek Harness to manage their API usage and billing costs. After installation and a required restart of dsh web, the balance capsule will appear automatically in the expected bottom-left location, and users can click it to manually refresh the current balance at any time. Hovering over the capsule shows a breakdown of total balance from top-ups and gifts, and users can open the DSH settings page to access the plugin’s dedicated configuration tab, where they can adjust alert thresholds, automatic refresh intervals, browser notification permissions, and other preferences to fit their usage needs.

The plugin is released under the open source MIT license, and is compatible with both the packaged desktop version of DSH and the official npm version of dsh web. It uses the common DSH profile plugin protocol, so it works seamlessly on both variants without any extra code modification. All balance history and user configuration preferences are stored exclusively in the user’s browser localStorage, so the DSH host never stores or accesses this local user data. To run the plugin for local development, users can install it via the link command dsh plugin --profile web add link:/path/to/dsh-balance-display.

这是专为DeepSeek Harness(DSH)开发的原生插件,用于在DSH网页端图形界面左侧栏底部实时显示DeepSeek API密钥的剩余额度。它支持低余额预警、余额消耗趋势查看、一键直达充值,并且全程仅在主机端处理API密钥,密钥不会传入浏览器端,保障密钥安全。

该插件面向使用DeepSeek API和DSH的开发者,安装完成后重启DSH网页端就能在侧边栏底部看到余额胶囊,点击可手动刷新,悬浮会显示充值和赠送的拆分信息。打开DSH设置页还能看到专属的余额显示标签页,用户可自行配置预警阈值、自动刷新间隔、浏览器通知权限等选项。

插件遵循MIT开源协议,兼容DSH桌面打包版和官网npm版,所有余额历史和用户偏好都存储在浏览器本地localStorage中,主机端不存储这些信息。安装可通过DSH官方命令行执行dsh plugin --profile web add dsh-balance-display完成,本地开发也支持链接安装。

Pre-install check安装前体检Compatibility · Security兼容性 · 安全性 1 warning1 项注意
  • Only 3 stars - very few users, little community feedback星标只有 3,几乎没人在用,遇到问题缺少社区反馈
DSH walks through these 9 checksDSH 会逐条核对这 9 项

Compatibility兼容性

  • DSH, Node, OS and profile requirementsDSH 版本 / Node 版本 / 操作系统 / profile 是否满足要求
  • External dependencies and runtimes (Electron / Python / Docker, ...)外部依赖与运行时(Electron / Python / Docker 等)是否齐备
  • Conflicts with installed plugins: command names, skill / tool names, ports, duplicate MCP registration与已装插件是否冲突:命令名、skill / tool 重名、端口占用、重复 MCP 注册

Security安全性

  • Repo matches the facts registered here; archived or abandoned?仓库是否与页面登记一致,是否归档或长期停更
  • Safety of preinstall / install / postinstall and install.sh / setup.ps1preinstall / install / postinstall 与 install.sh、setup.ps1 是否安全
  • curl|bash, download-then-execute, obfuscation, unrelated domains → stop immediatelycurl|bash、下载即执行、混淆代码、无关域名 → 立刻停止
  • Typosquatting or unmaintained packages among the new dependencies新增依赖里有没有 typosquatting 或无人维护的包
  • Requested permissions vs. what the feature actually needs申请了哪些权限、是否超出功能所需(filesystem / network / shell / clipboard)
  • Any sudo / admin requirement, plus uninstall and rollback是否要求 sudo / 管理员权限,以及卸载与回滚方式

Anything uncertain must be marked unknown with a note on how to confirm it. This site's signal screen is a static snapshot, not a security audit.拿不准的必须标「未知」并说明要我怎么确认。本站的信号筛查是静态快照,不能替代安全审计。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add dsh-balance-display

把 zhangjianyu1006156/dsh-balance-display 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

dsh-balance-display

DeepSeek API 余额显示插件 —— 在 DSH Web GUI 的左侧栏底部实时显示 API Key 剩余额度,支持低余额预警、余额消耗趋势、一键充值。

密钥全程只在主机端:主机端通过 dsh 凭据服务读取 key 并查询 api.deepseek.com/user/balance,浏览器端只从本机回环路由拉取脱敏后的余额 JSON,密钥绝不进入浏览器。

功能

  • 左下角余额胶囊:显示 余额 ¥92.12,点击刷新,悬浮显示充值/赠送拆分
  • 低余额预警:低于阈值(默认 ¥5,可调)圆点变红 + 悬浮警告 + 可选浏览器通知(跨过阈值只提醒一次)
  • 小额精度自适应:余额 < ¥1 时显示 4 位小数(¥0.5842),清楚还剩几分钱
  • 余额趋势:localStorage 记录历史点,设置页 sparkline 趋势图 + 今日/近 7 天消耗统计
  • 充值直达:胶囊与设置页均可一键打开 platform.deepseek.com/usage
  • 错误退避重试:连续失败时刷新间隔自动递增(1min → 5min → 30min)
  • 页面隐藏暂停轮询:切走标签页暂停刷新,回来立即刷新
  • 跟随主题:浅色 / 深色 / 跟随系统,与 DSH 外观设置一致
  • 中英文界面:跟随 dsh 语言设置实时切换
  • Agent 协作:在系统提示中声明插件,智能体可在余额过低时提醒用户充值

安装

已发布到 npm:

dsh plugin --profile web add dsh-balance-display

本地开发模式:

dsh plugin --profile web add link:/path/to/dsh-balance-display

装完重启 dsh web(宿主端改动需重启;纯客户端改动硬刷新浏览器即可)。侧边栏底部出现余额胶囊,设置页出现「余额显示」tab。

安全设计

风险 对策
Key 泄漏到浏览器 Key 只在主机端 resolve 后用于余额请求的 Authorization 头;客户端只 fetch 本机路由;路由响应 schema 无 key 字段
Key 泄漏到日志/错误 不写日志含 key 值;所有外发错误文本经 redact() 脱敏(sk-* / Bearer * → [redacted]),客户端二次脱敏兜底
客户端 bundle 携带 key 客户端是纯静态渲染代码,不含任何凭据;安装后 grep 断言零匹配
路由被滥用 仅 GET(余额)与 GET/POST(announce 配置);dsh web 默认仅绑定 127.0.0.1;不加 CORS 头
上游数据 XSS React 文本转义渲染,无 innerHTML
上游卡死 请求 10s 超时;缓存 TTL 有界;并发请求共享一次上游调用

配置

设置页「余额显示」tab:

项 说明
侧边栏显示余额角标 开关胶囊显示
自动刷新间隔(分钟) 默认 10
低余额预警阈值(¥) 默认 5
余额不足时浏览器通知 需授权通知权限
Agent 协作 在系统提示中声明插件(实时同步到主机端)

余额历史与偏好存于浏览器 localStorage(dsh.balanceDisplay.*),主机端不感知、不存储。

兼容性

兼容桌面打包版(内嵌 dsh rc.5)与官网 npm 版 dsh web(rc.6):两者共用同一套 profile 插件协议(bundle 挂载、/plugins/<id>/client.js 服务、webServer 路由、credentials 服务)。插件零 @deepseek-ai 运行时依赖,所有接入点特性检测,一份代码两种形态通用。

开发

dsh-balance-display/
├── package.json          # dsh.bundle.patch + dsh.client 清单
├── cordis.patch.yml      # 插件挂载行
└── lib/
    ├── index.js          # 主机端:余额路由 / config 路由 / 脱敏 / 缓存
    └── client.js         # 浏览器端:左下角胶囊 / 设置页 / i18n / 趋势图

测试(主机端 stub + 客户端 SSR 冒烟,无需启动 dsh):

node /tmp/test-balance-host.mjs      # 主机端:脱敏/缓存/并发去重/凭据失效/config 路由
node /tmp/test-balance-client3.mjs   # 客户端:精度/退避/消耗/历史/阈值

发布新版本:

npm version patch   # 或 minor / major
npm publish         # 需输 2FA 动态码

License

MIT

← 上一个 Prev dsh-unarchive 下一个 Next dsh-capability-discovery →