When using DeepSeek Harness (DSH) to handle relay stations or third-party models that require multiple API keys, rate limiting or quota exhaustion issues are common. The dsh-api-key-pool plugin is designed to address this pain point. Through automatic key rotation and failover mechanisms, it allows developers to maintain service stability without manually switching keys.

This is a DSH administration and security plugin maintained by xiaozhe7772222, primarily used for managing API key rotation pools.

Core Features

The plugin mainly includes the following capabilities:

  • Multi-key automatic rotation: Configure multiple keys for the same provider, and requests rotate through them sequentially to balance load.
  • Automatic failover on failure: If a key returns 401 / 403 / 429, it is automatically marked as faulty and the next healthy key is used.
  • Cooldown and recovery: Faulty keys enter a cooldown period using exponential backoff (default starting at 30s) and automatically return to the rotation pool when it expires.
  • Web admin panel: In the DSH Web UI, you can view health status, add or remove keys, and reset cooldowns.
  • Key masking: REST endpoints only return masked keys and do not expose full secrets.
  • Persistent configuration: Keys added via the Web panel are saved to pool-config.json and retained after restart.

Installation and Enablement

First, clone the repository and install it into DSH’s plugin directory:

git clone https://github.com/xiaozhe7772222/dsh-api-key-pool.git
cd dsh-api-key-pool
mkdir -p ~/.dsh/profiles/web/plugins/dsh-api-key-pool
cp -r lib package.json cordis.patch.yml ~/.dsh/profiles/web/plugins/dsh-api-key-pool/

Then declare the bundle in your ~/.dsh/profiles/web/package.json:

{
  "dsh": {
    "profile": {
      "bundles": [
        {
          "name": "dsh-api-key-pool",
          "platform": ["web"],
          "optional": false
        }
      ]
    }
  }
}

Finally, restart the DSH service:

npx @deepseek-ai/dsh web

Typical Usage

Static Configuration

Configure the provider’s keys and cooldown times in cordis.patch.yml:

- insert:
    - id: api-key-pool
      name: dsh-api-key-pool
      inject: [llm, webServer]
      config:
        pools:
          provider-a:
            apiKeyEnv: PROVIDER_A_API_KEY
            keys:
              - sk-your-first-key
              - sk-your-second-key
              - sk-your-third-key
            cooldownMs: 30000
          provider-b:
            apiKeyEnv: PROVIDER_B_API_KEY
            keys:
              - sk-key2-1
              - sk-key2-2
            cooldownMs: 60000
        defaultCooldownMs: 30000

Web Admin Panel

After starting DSH, go to Settings -> Plugins -> API Key Pool in the Web UI:
* View the key health status for each provider (green is healthy, orange is cooling down).
* Add or remove keys.
* Reset the cooldown status for a provider.

REST API Management

The plugin provides REST APIs for programmatic management:

  • View Status: GET /dsh-api-key-pool/pools
  • Add Key: POST /dsh-api-key-pool/pools (body: {"action":"add","provider":"provider-a","key":"sk-new-key"})
  • Remove Key: POST /dsh-api-key-pool/pools (body: {"action":"remove","provider":"provider-a","key":"sk-old-key"})
  • Reset Cooldown: POST /dsh-api-key-pool/pools (body: {"action":"reset","provider":"provider-a"})

Applicability and Notes

  • Runtime environment: Requires Node.js >= 18, as well as @deepseek-ai/cordis, @deepseek-ai/dsh-llm, and @deepseek-ai/schemastery.
  • Permissions: The plugin runs with DSH process permissions; review the source code before installation.
  • Security advice: Never commit real API keys to public repositories.

This plugin effectively mitigates API rate-limiting risks through rotation and cooldown mechanisms. You can obtain the source code via the following link: GitHub.