Introduction

DeepSeek Harness (DSH) is a foundational framework for building AI agents, and its core design philosophy is “everything is a plugin.” In real-world deployments, controlling LLM traffic rates at the provider and model level, managing API quotas, and handling free-tier gateway validation of client identity are often operational challenges developers need to solve. This article introduces a plugin that can be used directly in DSH for rate limiting and client impersonation.

Plugin Overview

dsh-provider-rate-limit is an administrative plugin for DeepSeek Harness, maintained by jyao-SUSE-power-group. It solves the problem of rate-limiting LLM traffic at the provider and model level, and provides gateway identity rules (client impersonation) to handle validation of client identity by some free-tier gateways.

Core Capabilities

  • Token Bucket throttling algorithm: Fine-grained rate limiting for (provider, model) routes, with support for burst traffic and idle recovery.
  • Dual-mode response: When the bucket is empty, it supports both wait (queue and wait) and reject (immediate rejection) modes.
  • Strict FIFO mechanism: A reservation-based design that ensures requests are admitted in arrival order, without polling.
  • Gateway identity impersonation: URL pattern matching is used to rewrite User-Agent or inject static headers, with support for dynamicIds dynamic ID injection.
  • Global control and hot reload: Provides a master switch and a localized settings UI; configuration changes take effect without a restart.
  • Real-time statistics: Displays real-time statistics in the Composer Dock, with hover support for viewing route-level detailed data. Provides an SSE push endpoint and an HTTP API.
  • High-performance route lookup: Uses a Map to achieve O(1) route matching.
  • Concurrency control: Supports maxConcurrentRequests configuration to prevent route overload.

Installation and Enablement

Install the plugin using the DSH plugin manager.

dsh plugin --profile web add github:jyao-SUSE-power-group/dsh-provider-rate-limit

After installation, restart DeepSeek Harness. The plugin will register with the llm service via a cordis patch.

Configuration and Usage

Go to Settings → Plugins → Provider Rate Limit to configure the plugin. All options support hot reload.

Routing rules: Match by provider or model name using substring matching. Unmatched traffic uses the global limits. For example, you can match routes where the provider is opencode and the model starts with claude-.

Identity impersonation rules: For specific URL patterns, you can rewrite the User-Agent or inject static headers. For example, some free gateways require specific client identifiers to pass validation.

Statistics viewing: In the chat interface, a rate-limit statistics line is displayed in the Composer Dock below the input box. Hover over that line to view detailed request data for each route.

Notes

  • The plugin runs with the permissions of the current DSH process. Please review the source code and license before installing.
  • Use the identity impersonation feature only if you have legitimate usage rights and comply with the applicable terms of service.

Summary

This plugin implements smooth rate limiting and burst traffic support using the Token Bucket algorithm, while its strict FIFO mechanism guarantees request ordering. For more information or to view the source code, visit the plugin catalog page or the GitHub repository.