Introduction

When developing agents using DeepSeek Harness (DSH), debugging HTTP requests typically relies on external tools or requires manually writing requests in Agent code. This approach lacks a unified execution audit trail and cannot share context between the debugging interface and the Agent toolchain.

The dsh-api-client plugin aims to solve these problems. It provides a set of Agent-native HTTP tools while retaining a Postman-level debugging experience, enabling both Human and Agent to share the same HTTP executor and audit system.

Plugin Overview

This is a DSH-native plugin maintained by Beatther-c. Its core positioning is:

  • Human UI: A Postman-level API debugging interface.
  • Agent Tools: Agent-native callable HTTP tools.
  • Compatibility: Supports importing Postman Collection v2.1.

Human and Agent share the same HTTP execution engine. High-risk methods automatically enter the Approval flow.

Core Features

1. Postman-Level Debugging Experience

The plugin provides complete HTTP request editing and response viewing capabilities:
* Tree Structure: Supports three-level directory management for Collection / Folder / Request.
* Editor: Supports editing Params / Headers / Auth / Body, with a built-in JSON Editor.
* Response Viewing: Offers three view modes: Pretty / Raw / Preview.
* Method Support: Covers seven standard HTTP methods.

2. Agent-Native Tools

The plugin exposes a set of DSH-native tools that Agents can call directly:
* api_client_request: Initiate a request.
* api_client_run_request: Run a request.
* api_client_list_collections: List collections.
* api_client_list_requests: List requests.
* api_client_get_request: Get request details.
* api_client_get_last_response: Get the last response.

3. Security and Policy

  • Environments and Secrets: Supports the shared/secrets/ directory, with division of labor using SecretRef references. History and Agent Context are redacted across the full chain, and History never persists secrets in plaintext.
  • SSRF Protection: Defaults to a fail-closed policy, refusing access to localhost and private network addresses, supporting blocked hosts/ports configuration, and providing DNS rebinding protection.

4. Native Integration

  • UI Adaptation: Supports a dual-path UI adaptation using official Slot priority + DOM fallback (based on feature detection).
  • Configuration and Theme: Integrated into the Settings configuration page, with the theme following DSH.

Installation and Enablement

Before using it, ensure the DeepSeek Harness version meets the requirement.

# 需要版本 >= 0.1.2-rc.1
dsh plugin --profile web add dsh-api-client

After installation, an API Client entry will appear below “New Session” in the DSH sidebar.

Typical Usage

Human-Side Operations

  1. Click the sidebar entry to enter the main view.
  2. Create or import a Postman Collection.
  3. Edit request parameters and Body, then click Send.
  4. View results in History or the Response Viewer.
  5. Manage variables and secrets in Environment (always displayed in redacted form in the UI).
  6. Adjust timeout, network policy, or permissions in Settings → Plugins → API Client.

Agent-Side Operations

The Agent can directly call api_client_* tools in the session to execute HTTP requests, or send the current redacted debugging context to a new session via the “Hand to Agent” feature for analysis.

Notes

  • Dependency Requirement: The plugin requires DeepSeek Harness >= 0.1.2-rc.1.
  • Permission Security: The plugin runs with the current DSH process permissions, and SSRF defaults to fail-closed. It is recommended to inspect the source code before installation.
  • License: Follows the MIT License.
  • Ecosystem Affiliation: This plugin is listed in the SkillHub community directory and has no affiliation with DeepSeek official.

Summary

dsh-api-client natively integrates traditional API debugging tools with the Agent toolchain. For agent developers who frequently debug interfaces, it provides a solution that fits both Human habits and Agent tool specifications.