Introduction

The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In local model inference or agent development, calling OpenAI Codex is a common requirement. Existing DSH plugins typically rely on API Keys for authentication, while the OpenAI Codex backend is based on an OAuth mechanism and has no API Key available. The dsh-llm-openai-codex plugin resolves this conflict. It reuses pi-ai’s general request machinery and uses ChatGPT OAuth access tokens as authentication credentials, making Codex models available in DSH.

Plugin Overview

  • Name: dsh-llm-openai-codex
  • Type: Model inference
  • Maintainer: auggie246
  • License: MIT
  • Core capabilities:
    • Adds an openai-codex route for DSH.
    • Uses OAuth login without requiring OPENAI_API_KEY.
    • Supports automatic token refresh.
    • Supports automatic model discovery.
    • Provides a web login card (PKCE or device code).

Installation and Activation

Before installation, make sure your environment meets the following requirements:
* DeepSeek Harness version 0.2.0-rc.2, with the web profile configured (older 0.1.x versions are not supported).
* Node.js version >=22.19.0.
* A ChatGPT subscription with Codex access (Plus, Pro, Business, or Enterprise).
* DSH-managed credentials or a shared Codex CLI login file.

1. Install the plugin
Install it using the following command:

dsh plugin --profile web add dsh-llm-openai-codex

2. Activate the plugin
Edit ~/.dsh/profiles/web/cordis.patch.yml and add the following content:

- insert:
    - id: llm-openai-codex
      name: 'dsh-llm-openai-codex'

After saving the file, restart dsh web or the DSH process.

Usage

After the plugin is activated, open the Plugins page in the left sidebar of DSH and find the dsh-llm-openai-codex plugin entry. The login card is located below the plugin description.

1. Credential Sources
The login card supports two credential sources:
* DSH-managed credentials (default): the plugin stores the token in $DSH_HOME/credentials/openai-codex.json.
* Shared Codex CLI: the plugin reads ~/.codex/auth.json or $CODEX_HOME/auth.json.

2. Login Actions
* Click Connect ChatGPT in browser: perform PKCE OAuth login in a browser. The callback URL is http://localhost:1455/auth/callback.
* Click Use device code: use this when the callback port is occupied or the browser is in a remote environment.

3. Select a Model
After successful login, select a model in the DSH model selector using the openai-codex/<model> format.

Configuration Options

In the configuration block in cordis.patch.yml, storage is the only key written by the web interface; it specifies the credential storage path. Other configuration options take effect after restarting DSH. Common settings include:
* storage: specifies the credential source (dsh or a path).
* modelDiscovery: auto: automatically fetches the latest model list from the backend.
* refreshMarginMs: remaining time before token refresh (default 60000ms).
* retryPolicy: failure retry policy.

Notes

  • API Key login is not supported: this plugin is not compatible with Codex CLI login methods that only use an API Key.
  • Login card location: the login entry is on the Plugins page in the sidebar, not in the Settings page.
  • No API Key required: the OPENAI_API_KEY environment variable does not need to be set during installation or runtime.

Ecosystem Context

This plugin is included in the community directory. The DSH plugin ecosystem is maintained by the community and aims to extend the framework’s inference capabilities. There is no direct affiliation with the official DeepSeek organization.

References