Introduction

DeepSeek Harness (DSH) supports extending model reasoning capabilities through plugins. When developers use OpenAI Codex models, they typically need to apply for and hold an OPENAI_API_KEY. If they already have a ChatGPT Plus or Pro subscription, calling the model directly via OAuth can eliminate the need to request an API key. The following section introduces the dsh-llm-chatgpt-oauth plugin, which integrates ChatGPT subscription access into DSH through the openai-codex route provided by pi-ai.

Plugin Purpose

This is a standalone community project, maintained by the user zhangxiubo and open-sourced under the MIT license.

Its core purpose is to register a DeepSeek Harness provider route named openai-codex. It uses chatgpt.com/backend-api for OAuth authentication, allowing DSH to directly use the current Codex model catalog from pi-ai (for example, gpt-5.4, gpt-5.5, etc.) without requiring OPENAI_API_KEY.

Core Features

The plugin provides the following capabilities:
* Model Catalog Registration: Registers the OpenAI Codex model catalog for DSH to use.
* OAuth Authentication: Authenticates through the official ChatGPT backend API.
* Keyless Operation: No OPENAI_API_KEY configuration is required.
* Message Conversion: Inherits Harness message conversion, tool calling, reasoning level, replay metadata, and attachment handling capabilities.
* Token Management: Automatically refreshes OAuth access tokens and supports private, atomic credential persistence.
* CLI Tool: Provides a dedicated device-code login command dsh-llm-chatgpt-auth login.
* Bootstrap Login: Supports bootstrapping login from an existing Codex CLI login state (optional).
* Settings Integration: Displays an OpenAI Codex (ChatGPT) provider row on DSH’s Models settings page and supports real-time, settings-based updates for action options.

Installation

Before installation, ensure the environment meets the dependency requirements (see below). Installation is completed through DSH’s plugin management command:

dsh plugin --profile web add 'github:zhangxiubo/dsh-llm-chatgpt-oauth#v0.1.0'

After installation, the dsh web process must be restarted to load the configuration.

Usage

After installation, you can authenticate via the command line or select a model on the DSH settings page.

Authentication Operations

Use the plugin’s authentication commands to manage credentials:

dsh-llm-chatgpt-auth login
dsh-llm-chatgpt-auth status
dsh-llm-chatgpt-auth logout

Configure Default Model

In ${DSH_HOME:-~/.dsh}/settings.yaml, set the default model and specify the openai-codex provider:

agent-default-model:
  provider: openai-codex
  model: gpt-5.4
  reasoningEffort: high

Advanced Configuration

The plugin supports configuration in settings.yaml under the llm-chatgpt-oauth namespace, such as disabling Codex CLI bootstrap or setting a timeout:

llm-chatgpt-oauth:
  displayName: OpenAI Codex (ChatGPT)
  streamIdleTimeoutMs: 300000
  bootstrapFromCodexCli: false

Dependencies and Environment

Running this plugin requires the following environment conditions:

  • Node.js: Version must be >=22.19.0.
  • Package Manager: pnpm must be installed for the command line.
  • DSH Version Compatibility: DeepSeek Harness must be compatible with @deepseek-ai/dsh-llm-pi-ai@0.1.0-rc.7.
  • Pi-AI Version Compatibility: @earendil-works/pi-ai@0.82.1 is required.
  • Account Permissions: A ChatGPT account with access to OpenAI Codex models is required.

Notes

  • Unofficial Project: This is a standalone community project, not an official package from OpenAI, DeepSeek, or pi-ai.
  • Security Mechanism: It does not convert the public api.openai.com route into subscription access, nor does it scrape browser sessions.
  • Model Limitations: Model availability and usage limits are controlled by the ChatGPT account and may change independently of the plugin state.
  • Version Pinning: The plugin strictly pins the peer versions for Harness and pi-ai. Before upgrading these pinned versions, they should be validated through the full test suite and selected live tests.
  • Private Package: The package is marked as private on npm, distributed through GitHub Releases, and is not published directly to the npm registry.

Resources