Introduction

DeepSeek Harness (DSH) uses a plugin-based architecture. Currently, the main DSH model router does not include ChatGPT/Codex OAuth support. The dsh-chatgpt-codex plugin fills this gap. It enables direct use of ChatGPT accounts and Codex models within DSH, supports browser callback and device-code login, and does not rely on the pi-ai adapter.

Core Features

This plugin manages the ChatGPT authentication lifecycle and streams Codex responses into DSH’s native protocol.

  • Authentication methods: Supports browser callback (PKCE, strict state validation, localhost callback) and device-code login (suitable for SSH, containers, or headless environments).
  • Credential management: Automatically refreshes access tokens and supports in-process and cross-process locks to prevent concurrency conflicts. Credentials are stored atomically under $DSH_HOME with restricted permissions.
  • Model support: Registers as a native openai-codex DSH model provider without requiring pi-ai. Supports GPT-5.6 (Luna, Terra, Sol) and models such as GPT-5.5/5.4.
  • Streaming and replay: Supports streaming of text, reasoning summaries, function calls, images, Usage, and Finish Reasons. Uses encrypted reasoning replay to ensure correctness across multi-turn conversations.

Installation and Setup

1. Login

Before installing the plugin, authentication must be completed. Choose the login method based on your environment:

  • Desktop browser callback (recommended):
    dsh-chatgpt-codex login
  • Device-code login (recommended for SSH or containers):
    dsh-chatgpt-codex login --device
The authentication file is stored by default at `$DSH_HOME/chatgpt-codex/auth.json`.

2. Add Plugin

Use the official installation command to register the plugin to the specified profile:

dsh plugin --profile codex add github:sudipnext/dsh-chatgpt-codex#v0.1.0

3. Run Harness

Start using the profile defined by the plugin:

dsh --profile codex

This profile registers the openai-codex provider and sets gpt-5.6-luna as the default model.

Usage

After installation and login, you can manage credentials with the following commands:

  • Check status (safe output, does not print tokens):
    dsh-chatgpt-codex status
  • Check JSON status:
    dsh-chatgpt-codex status --json
  • Manually refresh token:
    dsh-chatgpt-codex refresh
  • Logout (removes local credentials only; does not revoke the session remotely):
    dsh-chatgpt-codex logout

Notes

  • Independent project: This is an independent community plugin, not an official project from OpenAI or DeepSeek.
  • Model availability: The model catalog is for reference only. Actual availability depends on your ChatGPT subscription plan, workspace policies, region, and OpenAI’s current release status.
  • Security note: The logout command only deletes locally stored credential files and does not remotely sign out the OpenAI session. Please keep credential files properly protected when they are no longer in use.