Skip to content
dsh.fish
Bundle

dsh-codex-auth-bridge

Reuse the Codex CLI ChatGPT OAuth login in DeepSeek Harness through pi-ai's openai-codex provider.

Source
shaomingbo
stars
1 stars
License
MIT
Updated
Updated 5 days ago

Readme

# dsh-codex-auth-bridge

Reuse the Codex CLI's ChatGPT OAuth login in [DeepSeek Harness (DSH)](https://github.com/deepseek-ai/deepseek-harness).

The package is a **Host Cordis bundle**. It reads Codex's `auth.json`, keeps the OAuth token fresh through pi-ai's native `openai-codex` OAuth implementation, synchronizes the access token into DSH's credential service, and configures pi-ai's built-in `openai-codex` model route.

It does not contain, upload, or commit any token.

## Requirements

- Node.js 22.19 or later
- A DSH installation using the `dsh-llm-pi-ai` adapter
- Codex logged in with ChatGPT (`~/.codex/auth.json` contains `auth_mode: "chatgpt"`)

## Install

Run this on each device after logging in with Codex:

```bash
npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0
```

The installer:

1. adds this package to `~/.dsh/profiles/web/package.json`;
2. adds `dsh-codex-auth-bridge` to that profile's `dsh.profile.bundles` list;
3. runs `pnpm install` in the profile.

Restart `dsh web` afterward. The model picker will include the models exposed by pi-ai's installed `openai-codex` catalog.

Use another profile or source when needed:

```bash
npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0 --profile web
node ./bin/install.js --source file:../../packages/dsh-codex-auth-bridge
```

## How it works

At startup, every ten minutes, and immediately before an `openai-codex` LLM stream:

1. read `${CODEX_HOME:-~/.codex}/auth.json`;
2. decode the access-token expiry;
3. refresh an expired or soon-to-expire token through `@earendil-works/pi-ai`;
4. atomically write rotated tokens back to Codex's `auth.json`;
5. store the current access token under `OPENAI_CODEX_ACCESS_TOKEN` using DSH's credential service.

The bundle also configures this composition base:

```yaml
llm-pi-ai:
  providers:
    openai-codex:
      apiKeyEnv: OPENAI_CODEX_ACCESS_TOKEN
```

Because `api` is intentionally omitted, `dsh-llm-pi-ai` reuses pi-ai's provider-native `openai-codex-responses` transport instead of treating the ChatGPT backend as a generic OpenAI endpoint.

## Environment overrides

| Variable | Default | Purpose |
| --- | --- | --- |
| `DSH_CODEX_AUTH_PATH` | `${CODEX_HOME:-~/.codex}/auth.json` | Exact Codex auth file |
| `DSH_CODEX_CREDENTIAL_REF` | `OPENAI_CODEX_ACCESS_TOKEN` | DSH credential reference |
| `DSH_CODEX_PROVIDER_ID` | `openai-codex` | Provider route preflighted before requests |
| `DSH_CODEX_REFRESH_MARGIN_MS` | `300000` | Refresh margin before JWT expiry |
| `DSH_CODEX_SYNC_INTERVAL_MS` | `600000` | Background synchronization interval |

If you override `DSH_CODEX_CREDENTIAL_REF`, also update `apiKeyEnv` in the bundle or your DSH settings.

## Security notes

- Codex's `auth.json` contains a rotating refresh token and must remain private.
- DSH's local credential provider writes the synchronized access token to `$DSH_HOME/.credentials.yaml`, normally with mode `0600`.
- The plugin never logs token values.
- A compare-before-write check avoids overwriting a newer refresh token if Codex refreshes concurrently.

## Development

```bash
npm install
npm test
npm run check
```

## License

MIT

Install

dsh plugin --profile web add github:shaomingbo/dsh-codex-auth-bridge

Profile: web

  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source