In the development workflow of DeepSeek Harness (DSH), real-time visibility of the account balance helps with cost control and resource planning. Checking it manually or by switching between windows is less efficient. This article introduces the dsh-deepseek-balance plugin maintained by MatsMQ. It integrates balance querying into the DSH Web interface and provides an intuitive monitoring experience.

Feature Overview

This is a balance widget designed for the DSH Web GUI. It obtains the API Key through a host-side secure channel and requests balance data from the official API. The browser side only receives the result, ensuring that the Key never leaves the host process. Core features include:

  • Dual display: A balance badge is shown on the right side of the session title bar, and detailed data is displayed in Settings → Plugins → Account Balance.
  • Automatic refresh: Polls automatically every 30 seconds, with data synchronized across views.
  • Security handling: Authentication is handled on the host side, while browser-side data is protected through same-origin fence validation.

Installation and Enablement

Before installing, ensure that the webServer and credentials services are enabled on the host side (included in the web profile) and that React is loaded on the browser side. Use the following command to install it from GitHub:

dsh plugin --profile web add https://github.com/MatsMQ/dsh-deepseek-balance

Usage Steps

After installation, make sure the credentials are configured correctly and restart the service:

  1. On the host, configure the environment variable DEEPSEEK_API_KEY (or write it to $DSH_HOME/.credentials.yaml), ensuring it matches the Key used in the model settings.
  2. Restart the DSH Web service; the plugin will be loaded automatically on startup.
  3. Open any session, and you can see the balance badge on the right side of the title bar.
  4. In Settings → Plugins → Account Balance, you can view the total balance, gifted balance, top-up balance, and availability status.

Configuration Options

The plugin is configured through cordis.patch.yml. The default values are as follows:

Field Default Value Description
credentialRef DEEPSEEK_API_KEY Name of the credential reference used
upstreamUrl https://api.deepseek.com/user/balance Balance query endpoint
timeoutMs 10000 Upstream request timeout (milliseconds)

Security Boundaries and Notes

  • Key isolation: The API Key is used only within the host process, transmitted through the DSH credentials channel, and cannot be accessed on the browser side.
  • Network listening: The default Web deployment listens only on 127.0.0.1. If it is bound to 0.0.0.0, balance information is exposed to the local network (but the Key remains secure).
  • File protection: The plugin does not modify any configuration files or credential files.
  • Routing security: The API request route is GET /dsh-balance, and browser requests are protected by a same-origin fence (Sec-Fetch-Site).

This plugin is suitable for developers who need to continuously monitor their DeepSeek balance in the DSH Web interface. Before using it, please review the source code and license, and ensure that the host service dependencies are satisfied.