Introduction¶
In the DeepSeek Harness (DSH) environment, you sometimes need to simulate the behavior of specific clients (such as Codex Desktop or Claude Code), or clean up fingerprint headers bundled with the LLM SDK to avoid risk-control detection. DSH does not natively provide a Header hook for a single request. The dsh-custom-header plugin intercepts the fetch transport layer and directly modifies the Headers and Body of outbound requests, enabling client identity injection, URL rewriting, and Anthropic request body patching.
What Is This¶
This is an MIT-licensed plugin maintained by Asaiuta. It runs in DSH’s fetch transport layer (below the LLM SDK) and is responsible for modifying HTTP requests sent to LLM providers. The plugin processes requests through a middleware pipeline, supports multiple preset client configurations, and provides session-isolated Session ID management.
Core Features¶
- Client identity injection: Injects headers such as
User-Agent,Originator,X-Claude-Code-Session-Id, andx-opencode-*from preset configurations to simulate clients like Codex and Claude Code. - SDK fingerprint stripping: Automatically removes SDK runtime-generated fingerprint headers such as
X-Stainless-*. - URL rewriting: Supports path-match-based URL rewriting and allows appending query parameters via
appendQuery. - Anthropic request body patching: For the
/v1/messagesendpoint, patches the request body to bypass interception by identity or billing systems and injectsmetadata.user_id. - Session isolation: Based on
GenerateOptions.sessionIdandAsyncLocalStorage, implements an independent Session ID scope for each conversation turn. - 403 diagnostics: Detects
status: 403when streaming ends and provides diagnostic hints.
Installation and Enablement¶
Run the following command in the plugin directory to install it:
dsh plugin --profile web add file:$(pwd)
Or reference the plugin name directly (if published):
dsh plugin --profile web add dsh-custom-header
After installation, verify the configuration with the following command:
dsh --profile web --dump-config | grep dsh-custom-header
Typical Usage¶
1. Configuration File¶
Add configuration to DSH’s cordis.yml. The following is a basic configuration example:
dsh-custom-header:
profile: auto
autoHosts:
- gateway.example.com
autoCodexProfile: codex_desktop
codexVersion: 0.147.0
claudeCliVersion: 2.1.220
opencodeVersion: 1.18.18
opencodeClient: cli
opencodeProject: global
claudeSystemMode: identity
extraHeaders: {}
urlRewrites:
/v1/messages:
appendQuery: beta=true
persistProfile: true
2. Preset Profile Selection¶
The plugin includes multiple preset configurations for simulating different clients:
| Profile | Purpose |
|---|---|
codex_desktop |
Simulates the desktop Codex application, including a codex_app/1.2026.0628 UA and Originator: codex_app. |
codex_official |
Simulates the official CLI with UA codex_cli_rs/0.147.0. |
codex_tui |
Simulates the interactive TUI with UA codex-tui/0.147.0. |
codex_claude_plugin |
Simulates a Claude Code plugin, including a specific Session ID and Anthropic headers. |
pi_agent |
Simulates the Pi coding agent. |
claude_code_messages |
Specialized configuration for handling Claude Messages request body patching. |
opencode_zen |
Simulates the opencode client, including a specific Session ID format. |
auto |
Dynamically selects a configuration based on autoHosts matching. |
off |
Disables all modifications. |
3. Runtime Control¶
At runtime, use the JS API to switch Profiles or view the status:
ctx.dshCustomHeader.setProfile('codex_desktop')
ctx.dshCustomHeader.status()
4. Settings Page¶
In the DSH settings interface, go to Plugins -> Custom Header (Request Header Modification). You can manually select a Profile, edit the autoHosts whitelist, adjust version fields, and switch the Claude system mode (identity / billing). After saving the settings, no restart is required, and the next request will take effect immediately.
Use Cases and Notes¶
- Permission requirements: This plugin requires a server that you manage or have access to. It modifies request headers to bypass or influence server-side risk-control or authentication logic.
- Cloudflare blocking: If the target server uses Cloudflare TLS/Bot edge protection, you may need to configure a different API endpoint, an administrator whitelist, or a local forward proxy.
- Node Undici layer limitations:
accept-languageandsec-fetch-modeare injected below thefetchcall layer by Node.jsundici, so this plugin cannot remove these headers. If the server enforces validation of these fields, the request needs to be terminated at a local reverse proxy layer. - UA priority: UA override is final. A UA merged by DSH’s Attribution layer cannot override the UA injected at the fetch layer.
- Security defaults: With the default configuration
profile: 'auto'and an emptyautoHosts, the plugin will not modify any requests.
Brief Conclusion¶
dsh-custom-header provides the ability to customize requests at the DSH fetch layer, making it suitable for development scenarios that require simulating specific LLM client behavior or cleaning up SDK traces. Its core value lies in enabling flexible Header injection and Body patching through a middleware mechanism.
- GitHub repository: https://github.com/Asaiuta/dsh-custom-header