Introduction¶
The DeepSeek Harness (DSH) plugin system allows runtime extension of functionality. The upstream Harness multi-provider adapters deliberately omit the openai-codex adapter, because Codex authentication requires ChatGPT OAuth, and the adapter does not hold credential storage or run the login flow. This community plugin fills these gaps by providing an installable plugin package: a file-based OAuth credential store, a human-readable /codex login command, and a codex provider route registered on the public LLM interface.
Installation¶
The installation process automatically handles approval of pnpm build scripts. Run the following command under the web profile:
npx --yes https://github.com/birat-chapagain/dsh-codex-oauth/releases/download/v0.1.6/dsh-codex-oauth.tgz install
This command writes a one-time pnpm build approval and runs dsh plugin add to add the plugin to the current profile.
Manual installation (same effect):
dsh plugin --profile web add https://github.com/birat-chapagain/dsh-codex-oauth/releases/download/v0.1.6/dsh-codex-oauth.tgz
pnpm 11.22+ has strict restrictions on build scripts in transitive dependencies. This plugin tree contains two unused build scripts (@google/genai, protobufjs). If manual installation encounters an ERR_PNPM_IGNORED_BUILDS error, add the following to the profile’s pnpm-workspace.yaml:
allowBuilds:
'@google/genai': true
protobufjs: true
Login¶
Login is a human command and does not enter the prompt flow as a model tool.
Web UI¶
In the DeepSeek Harness chat input box, type:
/codex login
The browser will open the ChatGPT authorization page. After authorization is complete, the command reports that the token has been stored. You can also use /codex logout and /codex status to manage it. If the device login flow is used, the UI will prompt you to use the CLI command.
CLI / Headless¶
The plugin includes a standalone binary dsh-codex-oauth, which can run outside Harness:
npx dsh-codex-oauth login # 浏览器流(桌面端)
npx dsh-codex-oauth login --method device # 设备码流(无头端)
npx dsh-codex-oauth status
npx dsh-codex-oauth logout
The device-code flow prints a one-time code and an OpenAI device verification URL. Enter the code on any device, and the CLI will wait for authorization and store the token in the same file from which Harness reads.
Usage¶
The plugin registers a codex provider route. It is accessed through gpt-5.x-codex and its related models (from the installed pi-ai directory).
In the Web UI model selector, choose codex or a Codex model. For a headless profile, you can set the default model in the profile’s cordis.patch.yml:
- id: agent-default-model
config:
provider: codex
model: gpt-5.4
Per-session selection in the Web UI requires no additional configuration. Provider, model, and capability resolution are implemented through the upstream seam and are consistent with built-in provider behavior.
Configuration¶
The plugin supports the following configuration options. Override these options in cordis.patch.yml:
| Field | Default | Description |
|---|---|---|
provider |
codex |
The provider route ID registered by the adapter. |
storePath |
$DSH_HOME/codex-oauth.json |
The OAuth credential storage location. |
transport |
sse |
The Codex response transport mode: sse, websocket, websocket-cached, or auto. sse exits gracefully after one-off headless interactions; websocket can be used for long-lived sessions. |
cacheRetention |
long |
pi-ai prompt-cache retention policy: none, short, long. |
streamIdleTimeoutMs |
300000 |
The maximum number of milliseconds without stream events while a read is pending. On timeout, the SDK stream is aborted and a TIMEOUT LLM failure is returned. |
Example configuration:
- id: codex-oauth
config:
provider: codex
transport: sse
Notes¶
- Subscription requirement: A valid ChatGPT Plus or Pro subscription is required. OpenAI Platform API keys are invalid, because subscription access is tied to a ChatGPT account rather than an API key.
- pnpm warnings: During installation, you may see peer dependency warnings for
@deepseek-ai/cordis,@deepseek-ai/dsh-llm, or@deepseek-ai/dsh-invariants. This is normal because the main Harness installation provides these packages, and the profile setsautoInstallPeers: false. Do not add duplicate Cordis or invariants packages to eliminate the warnings. - File permissions: Credential files have
0600permissions, are written atomically, and deny group/world read access. Do not point the model workspace to the Harness root directory. - URL restrictions: Only https URLs are supported.
- How it works: The login flow is implemented by the pi-ai provider.
Closing¶
The plugin adds OpenAI Codex subscription support to DeepSeek Harness without forking or modifying the Harness core code. You can view the source code or submit issues via the GitHub repository.