Introduction

DeepSeek Harness (DSH) extends agent capabilities through a plugin mechanism. When developing agents that interact with social networks, integrating the X (Twitter) API usually requires handling complex OAuth 2.0 flows, token refreshing, and permission management. dsh-x-connect is a plugin provided for this scenario. It wraps the X API v2 connection as native DSH tools, allowing agents to directly search, read, summarize, and publish content.

What It Is

This is an X API v2 connector for DeepSeek Harness. It binds an X account using OAuth 2.0 Authorization Code with PKCE and provides DSH models with the ability to search, read, summarize, and publish posts.

Installation and Enablement

Before installation, ensure your environment meets Node.js ^22.19 || >=24.

  1. Install the plugin using the official DSH command:
    dsh plugin --profile web add dsh-x-connect
  1. After installation, restart dsh web.
  2. Open Settings → Plugins → X Connect to configure it.

X App Configuration

The plugin requires you to create an app in the X Developer Console and obtain credentials:

  1. Create a project and app in the X Developer Console.
  2. Enable OAuth 2.0, configure a Public/Native client, and use Authorization Code with PKCE.
  3. Register http://127.0.0.1:56130/callback (or another local loopback URI with an explicit port) as the callback URI.
  4. Enter the OAuth 2.0 Client ID in the DSH settings page and save.
  5. Authorize the required permissions: keep at least tweet.read, users.read, and offline.access; publishing requires enabling tweet.write.
  6. In the settings card, click Generate authorization link, complete authorization on the X website, then return to DSH and click Test connection.

The callback listener is started only during authorization, listens only on the local loopback interface, and is not exposed externally.

Core Features

  • Account binding and testing: Configure and bind an account on the settings page, with support for testing the connection status.
  • Information reading and summarization: Provides the ability to search, read a single post or a user timeline, and return structured content to the DSH model for summarization.
  • Secure publishing: Publishing posts and replies requires DSH one-time approval by default and is sent only after user confirmation.
  • Local management: OAuth tokens are refreshed locally, and operation audit logs are recorded.
  • Security design: Uses only X’s Public Client PKCE mode and never sends the OAuth Client Secret.

Agent Tool List

The plugin provides the following tools for agents to call:

Tool name Description
x_status View account, permissions, callback status, and estimated usage
x_connect / x_disconnect Bind or remove local OAuth credentials
x_me Read the bound account profile
x_search Search recent X posts
x_user_tweets Read an account’s timeline
x_tweet Read a post by specified ID or URL
x_post Publish a post or reply (requires approval)
x_activity_log Inspect or (after approval) clear local activity logs

Typical Usage

Agents do not need a prefix when calling tools; natural language descriptions can be used directly.

Example 1: Summarize the Last 5 Original Posts

Ask the agent to call x_user_tweets once, retrieve the latest 5 posts from the currently bound account, excluding reposts and replies, and summarize the key points, date, and link of each post in one sentence.

Call x_user_tweets exactly once for the currently bound account with maxResults 5.
Exclude reposts and replies. Summarize each result in one sentence with its date and URL.
Do not search other accounts and do not publish anything.

Example 2: Read and Summarize a Specific Post

Ask the agent to call x_tweet to read a post from the specified URL and summarize its main claim and one caveat.

Call x_tweet exactly once for https://x.com/<username>/status/<post-id>.
Summarize its main claim and one caveat. Do not call x_search or x_post.

Example 3: Draft and Publish a Reply

Use a two-step approach. Step one requests a draft; step two publishes after user approval.

Step 1 (draft):

Call x_tweet exactly once for https://x.com/<username>/status/<post-id>.
Draft a reply under 100 characters with no URL. Show the draft only; do not call x_post.

Step 2 (publish):

Call x_post exactly once to reply to <post-id> with this exact text:
<approved reply text>
Do not alter the text and do not call any other X tool.

Keep “Require one-time approval before posting” enabled. Before calling x_post, DSH displays the final text and estimated cost; rejecting approval blocks the publish action.

Applicable Scenarios and Notes

  • Billing notes: X API is billed based on usage. The current rates are $0.005 per Post read, $0.010 per User read, $0.015 for creating text-only content, and $0.200 for creating content with a URL. The plugin estimates costs based on the documented rates at the time of publishing, but official X documentation prevails. Failed requests are not charged, but deduplication is a soft guarantee.
  • Credential security: OAuth credentials are stored in ~/.dsh/x-connect/credentials.json, with file permissions 0600, readable/writable locally only, and are not returned to the browser or model.
  • Environment requirements: The plugin runs with DSH process permissions. Before installation, verify the source code and license (MIT).

Summary

dsh-x-connect reduces the technical barrier for agents to connect to social networks by wrapping X API OAuth flows and tool calls. It emphasizes local management and secure approval, making it suitable for DSH development scenarios that require agents to automatically process social media content.

Plugin Directory | GitHub Repository