Foreword¶
In the development environment of DeepSeek Harness (DSH), directly calling paid APIs for third-party large models often incurs significant costs. The dsh-subscriptions plugin provides an alternative: it allows personal subscription services (such as ChatGPT Plus, Claude Pro, and others) to be integrated into DSH via the OAuth protocol and used as local LLM providers. This plugin addresses multi-account management, rate-limiting handling, and secure credential storage.
What Is This¶
This plugin is maintained by GooDAnDReaREADY and is a model inference plugin. It uses the standard OAuth PKCE protocol to encapsulate 16 mainstream AI subscription services as first-class LLM providers for DSH. The plugin includes a built-in multi-account pool, automatic rotation mechanism, and a zero-leak credential security model, and supports login in headless environments.
Core Features¶
1. Built-in Supported Providers¶
The plugin includes adapter layers for 16 providers, supporting authentication through subscriptions instead of API keys:
- ChatGPT Codex
- Claude
- Grok
- Antigravity
- Kimi
- GLM
- Cursor
- Kiro
- Copilot
- Qwen
- ERNIE
- Spark
- JetBrains
- Perplexity
- Replit
- Cody
2. Multi-account Pool and Rate-limiting Handling¶
The plugin supports configuring multiple accounts for the same provider. When encountering 429 rate limits or quota exhaustion, the system automatically switches to a healthy account in the pool to continue making requests. It also supports proactive switching based on remaining quota, as well as dynamic cooldown calculation based on Retry-After and other information returned by upstream services.
3. Zero-leak Credential Security¶
OAuth tokens are not exposed in HTTP responses or the Web UI. All credentials are encrypted and stored in $DSH_HOME/.credentials.yaml, managed centrally by DSH’s credential service. The UI only displays account labels, connection status, and quota bars.
4. Headless and Remote Login Support¶
For environments without a browser, the plugin provides two login methods:
- Loopback Callback: Automatically starts a local HTTP server to receive callbacks (enabled by default), with no need to manually paste URLs.
- Device Code Login: Supports device-code flows for services such as Codex, allowing authorization to be completed on headless servers.
5. Cordis Service Integration¶
The plugin runs as a Cordis service and provides a ctx.subscriptions interface. Other DSH plugins (such as image generation plugins) can call this service directly in memory, avoiding extra HTTP round trips and token leakage risks.
Dependencies and Notes¶
- Runtime Environment: Node.js 20 or later is required.
- Dependencies: The plugin depends on core libraries such as
@deepseek-ai/cordisand@deepseek-ai/dsh-credentials. - Permissions: The plugin runs with the permissions of the current DSH process, and credentials are stored under the user directory.
Typical Usage¶
In other DSH plugins, subscription APIs can be invoked via ctx.subscriptions:
const res = await ctx.subscriptions.request('codex', '/backend-api/codex/images/generations', {
method: 'POST',
body: JSON.stringify({ prompt: 'Cyberpunk landscape', size: '1024x1024' }),
})
Summary¶
dsh-subscriptions is suitable for users who want to use personal subscription quotas for local agent development. It reduces maintenance overhead through multi-account pools and automatic rotation, while ensuring security through encrypted storage and in-memory service integration.
- Project URL: GitHub - GooDAnDReaREADY/dsh-subscriptions
- Directory Page: SkillHub - dsh-subscriptions