Introduction¶
The core philosophy of DeepSeek Harness (DSH) is “everything is a plugin”. When using Cline Pass as a gateway proxy, a common requirement is to pin traffic to the official DeepSeek channel, preventing fallback to other routes. The dsh-clinepass-deepseekv4.1 plugin is designed for this purpose: it integrates Cline Pass into DSH and, through local interception and response validation, ensures that requests only go through the DeepSeek upstream.
Core Features¶
The plugin mainly addresses three concerns: route configuration, channel-pinning validation, and usage monitoring.
-
Routing and Key Management
Routing is implemented via a standardpi-ai provider profile. The API Key does not require manual configuration files; it can be entered directly in the DSH Settings → Models interface. Interface elements such as the model catalog and endpoints are provided natively by DSH, with no custom UI required. -
Usage Bar Display
The card integrates usage monitoring, showing the remaining quota for the 5-hour, weekly, and monthly time windows. The DSH process fetches this data from the gateway using the key from the credential store and mounts it on a same-origin path for the browser to read; the browser cannot access the key directly. -
Port and Path Behavior
- Starting from version 0.5.0: the plugin no longer opens any local listening ports.
- Starting from version 0.7.0: to allow the browser to read usage data, the plugin registers the path
/api/clinepass.usageon DSH’s HTTP service, but the process still has no socket listeners.
How It Works¶
The plugin’s core logic is divided into request injection, response validation, and prompt processing.
1. Request Injection and Prompt Processing¶
- Pinning-field injection: Although the Vercel AI Gateway no longer enforces the
providerOptions.gateway.onlyfield at present, the plugin still preserves this field in outgoing request bodies in case the gateway behavior changes in the future. - Prompt model-name prefix handling: The gateway requires the
modelfield to be intype/modelformat, while DSH catalog IDs are unprefixed. During prompt assembly, the plugin replaces{{model}}in templates with the full channel ID (for example,cline-pass/deepseek-v4.1-flash) without affecting the actual ID in the gateway request body.
2. Local Gate Mechanism¶
This is the most critical part of the plugin. Since tests after 2026-09-22 show that the gateway no longer enforces the only field, the plugin implements local interception logic:
- Response capture: The plugin forwards SSE streaming responses frame by frame, but holds back the final
data: [DONE]frame. - Adjudication: Upon receiving the terminal frame, it parses the
routingmetadata in the response (includingfinalProvider,resolvedProvider, andmodelAttempts) and checks for records of non-DeepSeek channels. - Interception and retraction:
- If a violation is found, the plugin withholds the content, invalidates the call, prevents the content from being assembled into context, and prevents tool calls from being triggered.
- Streaming scenario: A retraction strategy is used, meaning the content may have been displayed but is already invalidated. This avoids TPS (tokens per second) data distortion caused by buffering.
- Non-streaming scenario: After reading the full response, it directly flags a violation and returns an HTTP 400 error.
3. Message Sanitization¶
To prevent channel names from being abused (for example, by inserting context_length_exceeded into error messages), the plugin filters displayed channel names. Only names that match a required shape and do not contain dangerous roots are written into error messages; all others fall back to a fixed phrase.
Configuration and Usage¶
Because the plugin relies on DSH internal behavior, using it does not require complex installation scripts.
-
Configure the Key
In the DSH UI, go to Settings → Models, find the corresponding provider profile, and enter the Cline Pass API Key. -
Configure the validation level
Set theenforcementparameter in the profile configuration:strict(default): blocks all violating traffic.warn: warns only, without blocking.off: disables validation and keeps only the request injection logic.
# cordis.patch.yml 或配置文件中的相关段
- id: clinepass
config:
enforcement: strict
Notes¶
-
Unofficial and maintenance status
This is a share-oriented snapshot project and is not intended for long-term maintenance. The author provides it as-is under the MIT license and makes no commitment to tracking upstream API drift. If DeepSeek Harness changes its internal behavior (for example, if thepi-aicomponent no longer uses globalfetch), the plugin will silently stop working. -
Upstream dependency risk
The plugin depends on DSH internal behavior. If upstream behavior changes, the plugin will not report an error; it will simply stop working. It is recommended to read the source code before use to confirm the dependency points. -
Version discrepancy
Available evidence shows the package.json version is0.9.0, while the README contains hints suggestingv4.1; rely on the actual files when using it. -
Releases page is empty
The maintainer releases via theRELEASING.mdprocess by pushing tags only, so the GitHub Releases page may be empty, but this does not affect normal plugin usage.