Introduction

The DeepSeek Harness (DSH) plugin system allows runtime extension of functionality. The upstream Harness multi-provider adapters deliberately omit the openai-codex adapter, because Codex authentication requires ChatGPT OAuth, and the adapter does not hold credential storage or run the login flow. This community plugin fills these gaps by providing an installable plugin package: a file-based OAuth credential store, a human-readable /codex login command, and a codex provider route registered on the public LLM interface.

Installation

The installation process automatically handles approval of pnpm build scripts. Run the following command under the web profile:

npx --yes https://github.com/birat-chapagain/dsh-codex-oauth/releases/download/v0.1.6/dsh-codex-oauth.tgz install

This command writes a one-time pnpm build approval and runs dsh plugin add to add the plugin to the current profile.

Manual installation (same effect):

dsh plugin --profile web add https://github.com/birat-chapagain/dsh-codex-oauth/releases/download/v0.1.6/dsh-codex-oauth.tgz

pnpm 11.22+ has strict restrictions on build scripts in transitive dependencies. This plugin tree contains two unused build scripts (@google/genai, protobufjs). If manual installation encounters an ERR_PNPM_IGNORED_BUILDS error, add the following to the profile’s pnpm-workspace.yaml:

allowBuilds:
  '@google/genai': true
  protobufjs: true

Login

Login is a human command and does not enter the prompt flow as a model tool.

Web UI

In the DeepSeek Harness chat input box, type:

/codex login

The browser will open the ChatGPT authorization page. After authorization is complete, the command reports that the token has been stored. You can also use /codex logout and /codex status to manage it. If the device login flow is used, the UI will prompt you to use the CLI command.

CLI / Headless

The plugin includes a standalone binary dsh-codex-oauth, which can run outside Harness:

npx dsh-codex-oauth login                 # 浏览器流(桌面端)
npx dsh-codex-oauth login --method device # 设备码流(无头端)
npx dsh-codex-oauth status
npx dsh-codex-oauth logout

The device-code flow prints a one-time code and an OpenAI device verification URL. Enter the code on any device, and the CLI will wait for authorization and store the token in the same file from which Harness reads.

Usage

The plugin registers a codex provider route. It is accessed through gpt-5.x-codex and its related models (from the installed pi-ai directory).

In the Web UI model selector, choose codex or a Codex model. For a headless profile, you can set the default model in the profile’s cordis.patch.yml:

- id: agent-default-model
  config:
    provider: codex
    model: gpt-5.4

Per-session selection in the Web UI requires no additional configuration. Provider, model, and capability resolution are implemented through the upstream seam and are consistent with built-in provider behavior.

Configuration

The plugin supports the following configuration options. Override these options in cordis.patch.yml:

Field Default Description
provider codex The provider route ID registered by the adapter.
storePath $DSH_HOME/codex-oauth.json The OAuth credential storage location.
transport sse The Codex response transport mode: sse, websocket, websocket-cached, or auto. sse exits gracefully after one-off headless interactions; websocket can be used for long-lived sessions.
cacheRetention long pi-ai prompt-cache retention policy: none, short, long.
streamIdleTimeoutMs 300000 The maximum number of milliseconds without stream events while a read is pending. On timeout, the SDK stream is aborted and a TIMEOUT LLM failure is returned.

Example configuration:

- id: codex-oauth
  config:
    provider: codex
    transport: sse

Notes

  • Subscription requirement: A valid ChatGPT Plus or Pro subscription is required. OpenAI Platform API keys are invalid, because subscription access is tied to a ChatGPT account rather than an API key.
  • pnpm warnings: During installation, you may see peer dependency warnings for @deepseek-ai/cordis, @deepseek-ai/dsh-llm, or @deepseek-ai/dsh-invariants. This is normal because the main Harness installation provides these packages, and the profile sets autoInstallPeers: false. Do not add duplicate Cordis or invariants packages to eliminate the warnings.
  • File permissions: Credential files have 0600 permissions, are written atomically, and deny group/world read access. Do not point the model workspace to the Harness root directory.
  • URL restrictions: Only https URLs are supported.
  • How it works: The login flow is implemented by the pi-ai provider.

Closing

The plugin adds OpenAI Codex subscription support to DeepSeek Harness without forking or modifying the Harness core code. You can view the source code or submit issues via the GitHub repository.