DeepSeek Harness (DSH) supports extending functionality through plugins. The built-in Grok provider currently only supports API keys. If you use a SuperGrok or X Premium+ subscription, using the model directly through DSH can be cumbersome. The following section introduces the dsh-llm-grok-oauth plugin, which adds an OAuth sign-in entry under Settings → Models, allowing you to access your subscription without an xAI API key.
What This Is¶
This is a DeepSeek Harness plugin for signing in with a Grok account under Settings → Models and running models on a SuperGrok / X Premium+ subscription. It does not rely on an xAI API key; instead, it obtains access tokens through the OAuth flow.
- Maintainer: wangyaominde
- Category: Web tools
- License: MIT
Core Features¶
- Grok account OAuth sign-in
- No xAI API key required
- Supports SuperGrok / X Premium+ subscriptions
- Automatic token refresh
- Real-time model catalog
- Streaming
Installation and Enablement¶
Before installing, make sure DeepSeek Harness 0.1.0-rc.6 or later is installed.
Install the plugin with the following command:
npx @deepseek-ai/dsh plugin --profile web add github:wangyaominde/dsh-llm-grok-oauth
After installation, you must restart dsh web. Client modules are loaded when the process starts, so the sign-in button will not load without a restart.
Typical Usage¶
- Open Settings → Models in DSH.
- On the Grok (xAI subscription) option, click Sign in with Grok.
- Complete the xAI authorization flow in your browser. The authorization code is scoped to the current session and is not shared across machines.
- Return to the session and select a Grok model. If the current session still defaults to DeepSeek, start a new session first.
Use Cases and Notes¶
- Account requirement: A SuperGrok or X Premium+ account is required.
- Network connectivity: The DSH process must be able to access
https://auth.x.aiandhttps://cli-chat-proxy.grok.com. Sign-in, model catalog retrieval, and chat share the same proxy stack (HTTPS_PROXYor the macOS system proxy). If your browser can open these hosts but DSH sign-in fails, set the proxy in the environment variables used to startdsh weband retry. - CLI compatibility: The official Grok CLI is not required, but if you are already signed in, the plugin silently reuses that session. Signing out only clears the plugin session and does not affect CLI login files.
- Known issue: Older versions may show a
TRANSPORTerror when signing in again immediately after signing out or when sending a message. Update to version 0.2.10 and fully restartdsh web.
Short Conclusion¶
This plugin addresses the pain point of manually managing API keys when using a Grok subscription in DSH, and provides a more convenient sign-in experience.