Introduction

In DeepSeek Harness (DSH) usage scenarios, managing sensitive information such as API tokens, server logins, and website accounts is a pain point. If this information is stored in a fragmented way, it not only increases maintenance costs but also creates security risks. The following section introduces the dsh-vault plugin, which provides centralized credential management for DSH and supports storing confidential fields separately from configuration.

What It Is

dsh-vault is a persistent credential vault plugin for DeepSeek Harness, maintained by user njjpro. It centrally manages credentials such as API tokens, server logins, and website accounts through the settings panel and securely stores confidential data in the DSH credential store for direct access by the model.

Core Features

  1. Centralized Management: Centrally manage all credentials (API tokens, server logins, website accounts, etc.) in the settings panel, with support for five built-in credential categories.
  2. Separate Storage: Store confidential fields separately from configuration. Sensitive information such as tokens is stored in the credential store, while non-confidential fields such as IPs are stored in settings.
  3. Tool Invocation: Provides two tools, vault_status and vault_get, for the model to call directly during tasks to retrieve credential values.
  4. UI Security: Confidential fields are not echoed in the UI; only the configured or unconfigured status is displayed.

Installation and Enabling

Run the following command to install the plugin:

dsh plugin add https://github.com/njjpro/dsh-vault

After installation, restart DSH. A “Credentials” section will appear in Settings.

Usage

  1. Add a Credential: Go to Settings → Credentials → click “+ Add Credential”, select a type, and fill in the fields (changes are saved when the input field loses focus).
  2. Model Invocation: The model will automatically call vault_status to check credential configuration status, or call vault_get to retrieve a specific credential value (e.g., id=github field=token).

Data Storage and Security

  • Storage Location:
    • Entry structures and non-confidential fields are stored under the dsh-vault namespace in ~/.dsh/settings.yaml.
    • Confidential fields are stored in the DSH credential store ~/.dsh/.credentials.yaml.
  • Security Mechanisms:
    • Confidential fields pass through the UI only when being written and are not echoed in the UI afterward.
    • The return value of vault_get appears only in the corresponding tool call and does not display the specific value in the UI rendering layer.
    • Uninstalling the plugin does not delete keys in the credential store. To clear them, click “Clear stored secret” in the entry.

Dependency Requirements

The plugin depends on @deepseek-ai/cordis ^4.0.1.

Summary

dsh-vault addresses the issues of fragmented credential management and the risk of confidential fields being echoed in the UI in the DSH environment. Through centralized configuration and tool-based invocation, it enables the model to access external resources securely. For more details, see the plugin catalog or source code: catalog_url github_url