Introduction

DeepSeek Harness (DSH) agents often need to call external SaaS platforms (such as Slack, GitHub, Gmail, or Stripe) at runtime. Managing the API keys for these platforms, or allowing calls without a unified approval workflow, is a common challenge for developers.

The @agentvalet/dsh plugin is introduced below. It runs as a broker, establishes a connection between the agent and the platform, enforces the owner’s authorization and approval workflow, and does not store any API keys on the machine running the agent.

What It Is

Plugin name: @agentvalet/dsh

Maintainer: AgentValet

Core positioning: A plugin that controls platform access permissions. Agents use it to call SaaS platforms connected through the AgentValet broker, and the broker validates the owner’s authorization and approval status.

Core Features

  1. Brokered access control: The AgentValet broker centrally evaluates authorization and approval decisions, instead of running a local policy engine.
  2. Zero local credentials: Platform credentials (such as Slack or GitHub keys) are stored only on the broker side, with no key residue on the machine running the agent.
  3. Full-operation toolset: Provides tools for four types of operations: list, read, write, and delete.
  4. Routing instruction writing: Automatically writes routing instructions into $DSH_HOME/AGENTS.md, indicating that platform calls must go through the AgentValet broker and must not bypass it.

Installation and Enablement

Install the plugin using DSH’s package manager:

dsh plugin --profile web add @agentvalet/dsh

After installation, the corresponding profile (configuration file) must be restarted or reloaded for the plugin to take effect. This plugin includes av-identity (the AgentValet service) and av-tools (the four tools).

Connection and Configuration

A profile that is installed but not connected cannot call any platform, and usually returns an “not connected” error. The connection process requires the administrator to generate a one-time Bootstrap Token in the AgentValet console.

  1. Generate a one-time bootstrap token in the AgentValet dashboard for the new agent.
  2. Run the connection command in the terminal:
AGENTVALET_BOOTSTRAP_TOKEN=<token> npx agentvalet-dsh-connect --profile web

The command above generates an RS256 key pair and sends the public key to the /v1/agents/bind endpoint of AgentValet. The private key remains local and is written to $DSH_HOME/agentvalet/<profile>.json (default ~/.dsh/agentvalet/...) with permissions 0600.

After a successful connection, the agent’s default mode in the dashboard is “deny access.” It can be called only after the owner grants access to specific platforms and scopes.

Routing instructions:
The connection operation also writes a section of routing instructions into $DSH_HOME/AGENTS.md, located between <!-- agentvalet:start --> and <!-- agentvalet:end -->. When DSH reads the file, it routes platform calls to the AgentValet broker according to these instructions. Other content in the file is not modified.

Tools

The plugin provides four tools for agents to interact with platforms:

Tool name HTTP method Description
agentvalet_list_platforms — Lists the platforms and scopes currently authorized for this agent. This tool should be called before making any platform call to check permissions.
agentvalet_read_platform GET Reads data from an authorized platform.
agentvalet_write_platform POST (default) / PUT / PATCH Creates or updates data. Write operations usually require owner approval.
agentvalet_delete_platform DELETE Deletes data. Such operations usually require owner approval.

All tools use a unified response format: { ok: true, data } on success and { ok: false, error } on failure. This means that whether the result is a permission denial, pending approval, or agent suspension, the response is readable plaintext, making it easier for the agent to interpret and handle.

Notes

  1. No sandbox: This plugin only controls which platform calls succeed. It is not a replacement for a sandbox and should be used together with sandboxing solutions.
  2. No sub-agent delegation or scope attenuation: The plugin does not support delegation between agents, and does not support reissuing an attenuated scope of the primary agent to sub-agents.
  3. No local policy engine: All authorization, scope, and approval decisions are evaluated by the AgentValet broker. The machine on which the plugin runs does not perform policy calculation.
  4. One-time token: The Bootstrap Token is one-time. If you try to run the connection command again on an already connected profile, it will be rejected to prevent confusion of the audit history.
  5. Compatibility: The plugin is compatible with Harness versions in the range >=0.1.0-rc.5 <0.2.0. Compatibility with version 0.1.0-rc.7 has been verified.

Conclusion

@agentvalet/dsh addresses the pain points of credential management and approval when DSH agents access external SaaS platforms. Through the broker model, it returns control to the owner and ensures that no sensitive credentials remain on the agent’s machine.