Introduction¶
The DeepSeek Harness (DSH) ecosystem emphasizes plugin-based extensibility. When using the dsh-llm-pi-ai adapter to invoke models, an API key typically needs to be configured. If a developer has already completed ChatGPT OAuth login in Codex CLI, manually maintaining two sets of credentials is not only cumbersome but also error-prone. The dsh-codex-auth-bridge plugin aims to resolve this redundant configuration issue by allowing DSH to directly reuse Codex’s login state.
Core Features¶
The plugin is provided as a Host Cordis bundle. Main features include:
* Credential Reading and Refresh: Reads Codex’s auth.json and keeps OAuth tokens fresh through the native implementation of @earendil-works/pi-ai.
* Credential Synchronization: Writes the synchronized access token to DSH’s credential service.
* Routing Configuration: Automatically configures the built-in openai-codex model routing in pi-ai.
* Security: Neither the plugin code nor its runtime includes, uploads, or submits any token data.
Installation and Enablement¶
Before running the installation command, ensure the following prerequisites are met:
* Node.js version is 22.19 or higher.
* DSH is installed with the dsh-llm-pi-ai adapter.
* Codex has signed in to ChatGPT (i.e., ~/.codex/auth.json contains auth_mode: "chatgpt").
On a device already logged in to Codex, run the following command:
npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0
The installation process automatically performs the following steps:
1. Adds the package to ~/.dsh/profiles/web/package.json.
2. Adds dsh-codex-auth-bridge to the dsh.profile.bundles list in the corresponding profile.
3. Runs pnpm install in the profile directory.
After installation, restart dsh web. The model selector will include models exposed by pi-ai’s openai-codex directory.
Typical Usage¶
- Basic Installation: Run the installation command above to complete the setup.
- Specify a Profile: If you need to use a non-default profile, specify it with the
--profileparameter:
npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0 --profile web
- Local Source Installation: Install from local source code:
node ./bin/install.js --source file:../../packages/dsh-codex-auth-bridge
How It Works¶
The plugin runs synchronization logic at startup, every 10 minutes, and before each openai-codex LLM streaming request:
1. Reads ${CODEX_HOME:-~/.codex}/auth.json.
2. Decodes the expiration time of the access token.
3. If the token is expired or about to expire, refreshes the token via @earendil-works/pi-ai.
4. Atomically writes the refreshed token back to Codex’s auth.json.
5. Stores the current access token in DSH’s credential service under the reference name OPENAI_CODEX_ACCESS_TOKEN.
The plugin also configures the following Composition baseline:
llm-pi-ai:
providers:
openai-codex:
apiKeyEnv: OPENAI_CODEX_ACCESS_TOKEN
Use Cases and Notes¶
This plugin is suitable for developers who need to access ChatGPT models through DSH and have already performed ChatGPT OAuth login with Codex CLI.
Keep the following points in mind:
* Permissions and Security: Codex’s auth.json contains rotated refresh tokens and must be kept private. DSH’s local credential provider writes synchronized access tokens to $DSH_HOME/.credentials.yaml (typically with permissions 0600). The plugin itself does not log any token values.
* Concurrency Protection: The plugin implements a compare-before-write mechanism. If Codex concurrently refreshes tokens in the background, the new refresh token will not be overwritten.
* Environment Variables: Paths and the refresh interval can be adjusted via environment variables such as DSH_CODEX_AUTH_PATH and DSH_CODEX_REFRESH_MARGIN_MS.
Conclusion¶
By reusing Codex’s OAuth login, developers can avoid repeatedly configuring an API key in DSH. The plugin implements automatic token refresh and synchronization through @earendil-works/pi-ai, ensuring session continuity. For more details, see the GitHub repository.