Bundle
dsh-fingerprint-relay
Managed local fingerprint relays so DSH can reach providers that gate on the client's TLS fingerprint
- Source
- Wilfred-wei
- License
- MIT
- Updated
- Updated 6 days ago
Readme
# DSH Fingerprint Relay
Lets DSH reach providers that **gate on the client's TLS fingerprint** (for example agentrouter.org).
The plugin runs a local Python egress process that the upstream allow-lists, and forwards DSH's requests through it.
[中文说明](README.zh.md)
## When you need it
The provider works in a browser or its official CLI, but DSH gets `unauthorized client detected` or a 403.
## Requirements
- DSH Desktop (framework `0.1.0-rc.8`)
- Python 3.11+
## Install
```powershell
git clone https://github.com/Wilfred-wei/dsh-fingerprint-relay.git
cd dsh-fingerprint-relay
.\scripts\install.ps1
```
The script installs the plugin, creates a Python venv, installs its dependencies, writes the interpreter path into your profile, and verifies the result.
Then **restart DSH Desktop**.
<details>
<summary>Without the script: two manual steps</summary>
```powershell
# 1. install the plugin
dsh plugin --profile web add dsh-fingerprint-relay
# 2. create the Python environment
$relay = "$env:USERPROFILE\.dsh\profiles\node_modules\dsh-fingerprint-relay"
python -m venv "$env:USERPROFILE\.dsh\fingerprint-relay-venv"
& "$env:USERPROFILE\.dsh\fingerprint-relay-venv\Scripts\python.exe" -m pip install -r "$relay\resources\requirements.txt"
```
Then point the plugin at that interpreter in `%USERPROFILE%\.dsh\profiles\web\cordis.patch.yml`:
```yaml
- id: fingerprint-relay-host
config:
pythonPath: C:\Users\<you>\.dsh\fingerprint-relay-venv\Scripts\python.exe
```
</details>
## Usage
1. Settings -> **Fingerprint relay** -> **Add relay**
- Upstream URL: `https://agentrouter.org`
- Local port: `7187`
2. Press **Start**; the status becomes `running / healthy`
3. Under **Providers through a relay**, point an Anthropic provider (such as `agent-claude`) at it
4. Chat as usual
The API key stays where it already is — in the provider's own configuration. The relay stores no keys.
## Limitations
- Anthropic Messages channel only; on new-api style gateways set the provider's protocol to `anthropic-messages` even for GPT models (the gateway converts them). Native OpenAI endpoints are not supported.
- The egress process listens on `127.0.0.1` only
- Accepted on Windows
## Troubleshooting
| Symptom | Fix |
| --- | --- |
| No "Fingerprint relay" section in Settings | Restart DSH Desktop; `dsh --profile web --dump-config` should list `fingerprint-relay-host` |
| Start fails: missing Python packages | Re-run `.\scripts\install.ps1`, or `pip install fastapi uvicorn httpx anthropic` for that interpreter |
| Start fails: port in use | Pick another local port |
| Requests return 401 | That provider has no API key configured |
| Long stall, then `no stream data for 120s` | The upstream stalled; the relay already retried once — send again |
| Config change had no effect | Press **Stop** then **Start** in Settings |
## Building from source
```bash
npm install --legacy-peer-deps
npm run build
npm test
npm pack --ignore-scripts
```
Architecture and behaviour specs live in `docs/`.
## License
MIT
Install
dsh plugin --profile web add github:Wilfred-wei/dsh-fingerprint-relay
Profile: web
With the hub plugin installed, ask your agent to install it by name — it resolves the same plan shown here.
dsh plugin --profile web add github:stvlynn/dsh.fish#path:packages/dsh-plugin-hub
install dsh-fingerprint-relay from the hub
- This package builds from source on install. pnpm will ask you to allow its build script — that is permission to run the package’s code on your machine, outside the agent sandbox. Only allow sources you trust.
- This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.