Introduction

In the DeepSeek Harness (DSH) environment, you sometimes need to simulate the behavior of specific clients (such as Codex Desktop or Claude Code), or clean up fingerprint headers bundled with the LLM SDK to avoid risk-control detection. DSH does not natively provide a Header hook for a single request. The dsh-custom-header plugin intercepts the fetch transport layer and directly modifies the Headers and Body of outbound requests, enabling client identity injection, URL rewriting, and Anthropic request body patching.

What Is This

This is an MIT-licensed plugin maintained by Asaiuta. It runs in DSH’s fetch transport layer (below the LLM SDK) and is responsible for modifying HTTP requests sent to LLM providers. The plugin processes requests through a middleware pipeline, supports multiple preset client configurations, and provides session-isolated Session ID management.

Core Features

  1. Client identity injection: Injects headers such as User-Agent, Originator, X-Claude-Code-Session-Id, and x-opencode-* from preset configurations to simulate clients like Codex and Claude Code.
  2. SDK fingerprint stripping: Automatically removes SDK runtime-generated fingerprint headers such as X-Stainless-*.
  3. URL rewriting: Supports path-match-based URL rewriting and allows appending query parameters via appendQuery.
  4. Anthropic request body patching: For the /v1/messages endpoint, patches the request body to bypass interception by identity or billing systems and injects metadata.user_id.
  5. Session isolation: Based on GenerateOptions.sessionId and AsyncLocalStorage, implements an independent Session ID scope for each conversation turn.
  6. 403 diagnostics: Detects status: 403 when streaming ends and provides diagnostic hints.

Installation and Enablement

Run the following command in the plugin directory to install it:

dsh plugin --profile web add file:$(pwd)

Or reference the plugin name directly (if published):

dsh plugin --profile web add dsh-custom-header

After installation, verify the configuration with the following command:

dsh --profile web --dump-config | grep dsh-custom-header

Typical Usage

1. Configuration File

Add configuration to DSH’s cordis.yml. The following is a basic configuration example:

dsh-custom-header:
  profile: auto
  autoHosts:
    - gateway.example.com
  autoCodexProfile: codex_desktop
  codexVersion: 0.147.0
  claudeCliVersion: 2.1.220
  opencodeVersion: 1.18.18
  opencodeClient: cli
  opencodeProject: global
  claudeSystemMode: identity
  extraHeaders: {}
  urlRewrites:
    /v1/messages:
      appendQuery: beta=true
  persistProfile: true

2. Preset Profile Selection

The plugin includes multiple preset configurations for simulating different clients:

Profile Purpose
codex_desktop Simulates the desktop Codex application, including a codex_app/1.2026.0628 UA and Originator: codex_app.
codex_official Simulates the official CLI with UA codex_cli_rs/0.147.0.
codex_tui Simulates the interactive TUI with UA codex-tui/0.147.0.
codex_claude_plugin Simulates a Claude Code plugin, including a specific Session ID and Anthropic headers.
pi_agent Simulates the Pi coding agent.
claude_code_messages Specialized configuration for handling Claude Messages request body patching.
opencode_zen Simulates the opencode client, including a specific Session ID format.
auto Dynamically selects a configuration based on autoHosts matching.
off Disables all modifications.

3. Runtime Control

At runtime, use the JS API to switch Profiles or view the status:

ctx.dshCustomHeader.setProfile('codex_desktop')
ctx.dshCustomHeader.status()

4. Settings Page

In the DSH settings interface, go to Plugins -> Custom Header (Request Header Modification). You can manually select a Profile, edit the autoHosts whitelist, adjust version fields, and switch the Claude system mode (identity / billing). After saving the settings, no restart is required, and the next request will take effect immediately.

Use Cases and Notes

  1. Permission requirements: This plugin requires a server that you manage or have access to. It modifies request headers to bypass or influence server-side risk-control or authentication logic.
  2. Cloudflare blocking: If the target server uses Cloudflare TLS/Bot edge protection, you may need to configure a different API endpoint, an administrator whitelist, or a local forward proxy.
  3. Node Undici layer limitations: accept-language and sec-fetch-mode are injected below the fetch call layer by Node.js undici, so this plugin cannot remove these headers. If the server enforces validation of these fields, the request needs to be terminated at a local reverse proxy layer.
  4. UA priority: UA override is final. A UA merged by DSH’s Attribution layer cannot override the UA injected at the fetch layer.
  5. Security defaults: With the default configuration profile: 'auto' and an empty autoHosts, the plugin will not modify any requests.

Brief Conclusion

dsh-custom-header provides the ability to customize requests at the DSH fetch layer, making it suitable for development scenarios that require simulating specific LLM client behavior or cleaning up SDK traces. Its core value lies in enabling flexible Header injection and Body patching through a middleware mechanism.

  • GitHub repository: https://github.com/Asaiuta/dsh-custom-header