Introduction

DeepSeek Harness (DSH) uses a plugin-based architecture designed to provide developers with flexible LLM integration capabilities. Integrating Grok Build requires handling a complex OAuth authentication flow, including managing refresh tokens and synchronizing access tokens. Maintaining these steps manually is not only cumbersome but also carries security risks. This plugin bridges the local session of Grok Build CLI with DSH’s credential service, enabling reuse and synchronization of authentication state.

What This Is

This is a hosted Cordis bundle. It is maintained by shaomingbo. It reads the local session of Grok Build, delegates refresh token handling to the official grok binary, synchronizes only access tokens to DSH’s credential service, and provisions pi-ai routes for the Grok Build subscription agent.

Core Features

  • Hosted Cordis bundle.
  • Reads the local session of Grok Build.
  • Delegates refresh token handling to the official grok binary.
  • Synchronizes only short-lived access tokens to DSH’s credential service.
  • Provisions pi-ai routes for the Grok Build subscription agent.
  • Does not embed, upload, or commit any tokens.

Installation and Enablement

Before installing, please ensure the environment meets the following requirements:
- Node.js 22.19 or higher
- DSH with the dsh-llm-pi-ai adapter installed
- The official Grok Build CLI is installed and logged in

The installation command is as follows:

npx --yes github:shaomingbo/dsh-grok-build-auth-bridge#v0.1.0

This command adds the package and its Cordis bundle to ~/.dsh/profiles/web/package.json and runs pnpm install. After installation is complete, please restart dsh web.

Typical Usage

After logging in to the Grok Build CLI, you can verify the status and install the plugin with the following commands:

grok update
grok login
grok models
npx --yes github:shaomingbo/dsh-grok-build-auth-bridge#v0.1.0

After restarting dsh web, the plugin automatically creates the route. You need to configure the following parameters in DSH’s settings (existing providers will not be overwritten):
- Provider: grok-build
- Model: grok-4.6
- Protocol: OpenAI Responses
- Endpoint: https://cli-chat-proxy.grok.com/v1

Use Cases and Notes

  • Unix system security: The plugin refuses to read ~/.grok/auth.json if the file is accessible to group or others. Use chmod 600 ~/.grok/auth.json to ensure proper permissions.
  • Environment variable interference: If the parent environment exports GROK_BUILD_ACCESS_TOKEN, it shadows DSH’s writable credential store. Unset this variable before starting DSH.
  • Permission risk: The plugin runs with the permissions of the DSH process. Before installing, it is recommended to review the source code to confirm its behavior is as expected.
  • MIT license: This plugin follows the MIT license.

Brief Conclusion

This plugin simplifies Grok Build integration in DSH by reusing the official CLI’s security mechanisms. By delegating refresh logic and synchronizing only access tokens, it balances convenience and security. For more details, see the community catalog or the GitHub repository.