The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” To integrate GitHub Copilot as a model provider, developers need to handle the OAuth authentication flow and register the corresponding model routing. This plugin provides a wrapper around the official API, completes login through the device code flow, and registers the model routing into the DSH environment.

Plugin Overview

This plugin is maintained by user FMDD61, categorized as a model provider (model-provider), and released under the MIT open-source license. It primarily addresses two issues:
1. Integrating the GitHub Copilot authentication flow into DSH.
2. Registering an LLM route named github-copilot, which is backed by the Copilot model catalog in pi-ai.

Installation and Activation

The plugin is published as an NPM package and can be installed without cloning the source code. After installation, you must restart the dsh web service to load the configuration.

dsh plugin --profile web add dsh-oauth-copilot

After installation, the dsh web process loads the llm-github-copilot route configuration from dsh.bundle.patch and activates the authorization service entrypoint.

Authentication and State Check

Login is a pure terminal-based operation and does not introduce LLM prompt-injection risk. The CLI tool provides login, status check, token refresh, and logout functionality.

  1. Login: Run the following command to start the device code flow and authorize in a browser.
    npx -y dsh-oauth-copilot login
*(You can also install it globally with `npm install -g dsh-oauth-copilot` and then run `dsh-copilot-auth login` directly.)*
  1. Status Check: Check the authorization validity period and the list of available models.
    dsh-copilot-auth status
  1. Refresh Model List: Re-fetch the list of models allowed for the account and update the authorization record.
    dsh-copilot-auth refresh
  1. Logout: Remove locally stored authorization credentials.

Model Routing and Tools

The plugin registers the github-copilot route. By default, model tools (such as login and logout) are disabled and need to be explicitly enabled in the route configuration.

After enabling model tools, the model can directly call tools such as github_copilot_login, github_copilot_status, and github_copilot_logout.

Add the following content to the route configuration file:

- id: llm-github-copilot
  config:
    enableModelTools: true

Notes

  • Version Pinning: This plugin is pinned to the package versions dsh 0.1.5-rc.1 and pi-ai 0.85.1; future DSH upgrades require corresponding version range adjustments.
  • GitHub Enterprise Not Supported: Only github.com is supported. For security reasons, the plugin rejects enterprise domains to prevent token refresh from being redirected to an attacker-controlled server.
  • File Security: Credential files are stored using atomic writes, with permissions set to 0600, and stored outside the settings/description/environment directories. The CLI output hides tokens and error details.
  • Concurrency Limitation: CLI commands should not be run concurrently with other processes that are writing to the credential file.

Conclusion

This plugin uses the official API to integrate GitHub Copilot into DSH, making it suitable for developers who need to use Copilot models directly in the DeepSeek Harness environment. For more technical details and source code, refer to the GitHub repository.