In the DeepSeek Harness (DSH) plugin ecosystem, connecting an enterprise data source (such as Qixin Insight) usually involves cumbersome API Key configuration or service endpoint setup. The dsh-qixin-insight-mcp-oauth plugin uses the OAuth 2.1 (PKCE) standard authorization flow to mount the Qixin Insight MCP service into Harness, enabling the model to query business registration, equity, judicial, and risk intelligence data directly.
Core Positioning¶
This is a DeepSeek Harness plugin maintained by qixin-ai-data and categorized as a “Web tool.” It addresses the issue that traditional MCP integration requires manually configuring API Keys and service endpoints. By performing one-click authorization in the browser, it mounts Qixin Insight tools into the conversation.
Installation and Enablement¶
The plugin is published on npm. The installation command is as follows:
dsh plugin --profile web add dsh-qixin-insight-mcp-oauth
After installation, you need to restart the dsh process for the change to take effect.
Typical Usage¶
The plugin is operated through conversational tools. There are mainly three commands:
- Connect to the service
In the conversation, enter “Connect Qixin Insight MCP.”
This triggers the toolqixin_insight_mcp_connect: the plugin initiates authorization, opens a browser for the user to log in, and automatically mounts the MCP tools after completion. If valid authorization already exists, it is reused directly. - Check the status
In the conversation, enter “Is Qixin Insight MCP connected?”
This triggers the toolqixin_insight_mcp_status: it returns the connection status, audience binding, Token expiration time, and the mounted tool prefix. - Disconnect from the service
In the conversation, enter “Disconnect Qixin Insight MCP.”
This triggers the toolqixin_insight_mcp_disconnect: it performs RFC 7009 revocation of refresh_token, unmounts the tools, and deletes the local credentials.
Technical Details and Notes¶
Credential Management¶
- No configuration file storage required: The plugin does not write API Keys or Tokens into configuration files such as
cordis.yml. - Storage location: Credentials are stored in the DSH credential service (
ctx.credentials), ensuring safe cross-process writing and mutual exclusivity. - Automatic refresh: Tokens are automatically refreshed before expiration, and the connection is automatically restored after the host restarts.
- Revocation support: When disconnecting, it supports RFC 7009 revocation of refresh_token.
Environment Requirements¶
- Node.js version: Requires
^22.19.0 || >=24.0.0.
Known Limitations¶
- No UI settings page: It can only be operated through conversational tools; there is no graphical settings page.
- Uninstall cleanup: After uninstalling the plugin, you must first execute the disconnect command (
qixin_insight_mcp_disconnect); otherwise, a grant record will still remain in the DSH credential service, and refresh_token will remain valid. - Tool jitter: During Token expiration and rotation, there will be a brief tool jitter caused by one
tools/listround trip. - Single-endpoint limitation: One plugin entry corresponds to one MCP endpoint.
Summary¶
This plugin uses the OAuth 2.1 and PKCE standards to simplify the integration process for enterprise data sources. It delegates credential management to the DSH credential service for unified handling, making it suitable for scenarios that require secure and convenient access to Qixin Insight data within the DSH environment.