Introduction¶
When developing agents using DeepSeek Harness (DSH), debugging HTTP requests typically relies on external tools or requires manually writing requests in Agent code. This approach lacks a unified execution audit trail and cannot share context between the debugging interface and the Agent toolchain.
The dsh-api-client plugin aims to solve these problems. It provides a set of Agent-native HTTP tools while retaining a Postman-level debugging experience, enabling both Human and Agent to share the same HTTP executor and audit system.
Plugin Overview¶
This is a DSH-native plugin maintained by Beatther-c. Its core positioning is:
- Human UI: A Postman-level API debugging interface.
- Agent Tools: Agent-native callable HTTP tools.
- Compatibility: Supports importing Postman Collection v2.1.
Human and Agent share the same HTTP execution engine. High-risk methods automatically enter the Approval flow.
Core Features¶
1. Postman-Level Debugging Experience¶
The plugin provides complete HTTP request editing and response viewing capabilities:
* Tree Structure: Supports three-level directory management for Collection / Folder / Request.
* Editor: Supports editing Params / Headers / Auth / Body, with a built-in JSON Editor.
* Response Viewing: Offers three view modes: Pretty / Raw / Preview.
* Method Support: Covers seven standard HTTP methods.
2. Agent-Native Tools¶
The plugin exposes a set of DSH-native tools that Agents can call directly:
* api_client_request: Initiate a request.
* api_client_run_request: Run a request.
* api_client_list_collections: List collections.
* api_client_list_requests: List requests.
* api_client_get_request: Get request details.
* api_client_get_last_response: Get the last response.
3. Security and Policy¶
- Environments and Secrets: Supports the
shared/secrets/directory, with division of labor usingSecretRefreferences. History and Agent Context are redacted across the full chain, and History never persists secrets in plaintext. - SSRF Protection: Defaults to a fail-closed policy, refusing access to localhost and private network addresses, supporting blocked hosts/ports configuration, and providing DNS rebinding protection.
4. Native Integration¶
- UI Adaptation: Supports a dual-path UI adaptation using official Slot priority + DOM fallback (based on feature detection).
- Configuration and Theme: Integrated into the Settings configuration page, with the theme following DSH.
Installation and Enablement¶
Before using it, ensure the DeepSeek Harness version meets the requirement.
# 需要版本 >= 0.1.2-rc.1
dsh plugin --profile web add dsh-api-client
After installation, an API Client entry will appear below “New Session” in the DSH sidebar.
Typical Usage¶
Human-Side Operations¶
- Click the sidebar entry to enter the main view.
- Create or import a Postman Collection.
- Edit request parameters and Body, then click Send.
- View results in History or the Response Viewer.
- Manage variables and secrets in Environment (always displayed in redacted form in the UI).
- Adjust timeout, network policy, or permissions in Settings → Plugins → API Client.
Agent-Side Operations¶
The Agent can directly call api_client_* tools in the session to execute HTTP requests, or send the current redacted debugging context to a new session via the “Hand to Agent” feature for analysis.
Notes¶
- Dependency Requirement: The plugin requires DeepSeek Harness >= 0.1.2-rc.1.
- Permission Security: The plugin runs with the current DSH process permissions, and SSRF defaults to fail-closed. It is recommended to inspect the source code before installation.
- License: Follows the MIT License.
- Ecosystem Affiliation: This plugin is listed in the SkillHub community directory and has no affiliation with DeepSeek official.
Summary¶
dsh-api-client natively integrates traditional API debugging tools with the Agent toolchain. For agent developers who frequently debug interfaces, it provides a solution that fits both Human habits and Agent tool specifications.