Introduction¶
DeepSeek Harness (DSH) uses a plugin-based architecture. Currently, the main DSH model router does not include ChatGPT/Codex OAuth support. The dsh-chatgpt-codex plugin fills this gap. It enables direct use of ChatGPT accounts and Codex models within DSH, supports browser callback and device-code login, and does not rely on the pi-ai adapter.
Core Features¶
This plugin manages the ChatGPT authentication lifecycle and streams Codex responses into DSH’s native protocol.
- Authentication methods: Supports browser callback (PKCE, strict state validation, localhost callback) and device-code login (suitable for SSH, containers, or headless environments).
- Credential management: Automatically refreshes access tokens and supports in-process and cross-process locks to prevent concurrency conflicts. Credentials are stored atomically under
$DSH_HOMEwith restricted permissions. - Model support: Registers as a native
openai-codexDSH model provider without requiringpi-ai. Supports GPT-5.6 (Luna, Terra, Sol) and models such as GPT-5.5/5.4. - Streaming and replay: Supports streaming of text, reasoning summaries, function calls, images, Usage, and Finish Reasons. Uses encrypted reasoning replay to ensure correctness across multi-turn conversations.
Installation and Setup¶
1. Login¶
Before installing the plugin, authentication must be completed. Choose the login method based on your environment:
- Desktop browser callback (recommended):
dsh-chatgpt-codex login
- Device-code login (recommended for SSH or containers):
dsh-chatgpt-codex login --device
The authentication file is stored by default at `$DSH_HOME/chatgpt-codex/auth.json`.
2. Add Plugin¶
Use the official installation command to register the plugin to the specified profile:
dsh plugin --profile codex add github:sudipnext/dsh-chatgpt-codex#v0.1.0
3. Run Harness¶
Start using the profile defined by the plugin:
dsh --profile codex
This profile registers the openai-codex provider and sets gpt-5.6-luna as the default model.
Usage¶
After installation and login, you can manage credentials with the following commands:
- Check status (safe output, does not print tokens):
dsh-chatgpt-codex status
- Check JSON status:
dsh-chatgpt-codex status --json
- Manually refresh token:
dsh-chatgpt-codex refresh
- Logout (removes local credentials only; does not revoke the session remotely):
dsh-chatgpt-codex logout
Notes¶
- Independent project: This is an independent community plugin, not an official project from OpenAI or DeepSeek.
- Model availability: The model catalog is for reference only. Actual availability depends on your ChatGPT subscription plan, workspace policies, region, and OpenAI’s current release status.
- Security note: The
logoutcommand only deletes locally stored credential files and does not remotely sign out the OpenAI session. Please keep credential files properly protected when they are no longer in use.