Skip to content
dsh.fish
Bundle

dsh-openai-codex

Experimental ChatGPT subscription OAuth provider plugin for DeepSeek Harness

Source
bufeibufei
stars
3 stars
License
MIT
Updated
Updated 4 hours ago

Readme

# dsh-openai-codex

`dsh-openai-codex` is an experimental, out-of-tree DeepSeek Harness plugin. It registers pi-ai's `openai-codex` models against the public DSH `ctx.llm` adapter seam and manages a ChatGPT OAuth login in its own credential file. It does not patch or replace an installed DSH package.

The plugin targets `@deepseek-ai/dsh` `0.1.0-rc.7`. ChatGPT sign-in is subscription-backed access, not OpenAI Platform API billing. This third-party integration uses the Codex backend behavior implemented by pi-ai; OpenAI documents ChatGPT sign-in for official Codex clients, not this plugin, so endpoint or policy changes may break it.

## Install

Install the tagged GitHub release into each DSH profile that should expose Codex:

```powershell
dsh plugin --profile headless add github:bufeibufei/dsh-openai-codex#v0.1.1
dsh plugin --profile web add github:bufeibufei/dsh-openai-codex#v0.1.1
```

The repository ships runnable JavaScript and reuses DSH rc.7's installed pi-ai runtime through an exact peer dependency, so a GitHub installation requires no package build.

The release also publishes a tarball for an offline or pinned local installation:

```powershell
dsh plugin --profile web add .\dsh-openai-codex-0.1.1.tgz
```

## Authenticate

Run the plugin's binary inside either installed profile. Both profiles share the same credential when they use the same `DSH_HOME`:

```powershell
dsh plugin --profile headless exec dsh-codex-auth login
```

Open the displayed URL, enter the device code, and approve access. Device-code login may need to be enabled in your ChatGPT security or workspace settings.

Node does not enable environment-proxy support by default. When the terminal uses `HTTP_PROXY` or `HTTPS_PROXY`, enable it for login, refresh, and model requests before starting DSH:

```powershell
$env:NODE_USE_ENV_PROXY = '1'
```

Other commands:

```powershell
dsh plugin --profile headless exec dsh-codex-auth status
dsh plugin --profile headless exec dsh-codex-auth models
dsh plugin --profile headless exec dsh-codex-auth path
dsh plugin --profile headless exec dsh-codex-auth logout
```

After login, open DSH's Models settings and choose provider `openai-codex` plus one of the listed models. For a CLI-only profile, set the same provider/model through the existing DSH settings surface before starting a task.

Verify the bundle layer without starting an agent:

```powershell
dsh --profile headless --dump-config
```

## Storage and security

The credential is stored at `$DSH_HOME/.dsh-openai-codex/auth.json`, or `~/.dsh/.dsh-openai-codex/auth.json` when `DSH_HOME` is unset. Writes use a same-directory temporary file, atomic rename, and a cross-process writer lock. POSIX installations request directory mode `0700` and file mode `0600`.

These permissions protect against other OS users only. DSH tools that run as your own user may be able to read this file and put tokens into a session transcript. Use an isolated OS account or filesystem policy for untrusted agents. Never commit the file, attach it to diagnostics, or paste its contents.

The managed OAuth token is sent only through pi-ai's fixed `https://chatgpt.com/backend-api` Codex provider. The plugin exposes no endpoint override or custom-header setting. It fixes transport to SSE so a completed one-shot DSH process does not retain an authenticated WebSocket cache.

## Compatibility limits

- This package deliberately has no native `dsh auth` top-level command and no OAuth card in the DSH Web UI; those require host product surfaces. Its command is `dsh-codex-auth`, invoked through `dsh plugin ... exec`.
- Do not also configure an `openai-codex` route in DSH's built-in `llm-pi-ai` settings. Two adapters cannot own the same route.
- The implementation is pinned to pi-ai `0.82.1`, matching DSH `0.1.0-rc.7`'s adapter event format.
- The plugin does not reuse or overwrite `codex login` state in `~/.codex/auth.json`.

## Development

```powershell
npm install
npm run check
npm test
npm pack
```

All tests are keyless. A real login and model call require an eligible ChatGPT account.

Install

dsh plugin --profile web add github:bufeibufei/dsh-openai-codex

Profile: web

  • This source has no pinned commit, so a later push upstream changes what installs. Prefer pinning a commit.
Source