Preface¶
The core design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” In model inference scenarios, directly using the OpenAI or xAI API requires managing an API Key. If you want to use the official capabilities of ChatGPT or Grok, you usually need to install the corresponding official CLI tools.
The DSH Connect plugin uses an adapter pattern to integrate the official ChatGPT and Grok CLIs into the DSH ecosystem. It does not rely on an API Key. Instead, it logs in via OAuth and uses official processes to perform model inference and tool calls.
Plugin Introduction¶
This is a community-maintained Cordis plugin that includes a model provider adapter and a Web settings panel.
- Core value: Unifies the model catalogs of DeepSeek Harness, ChatGPT, and Grok, and supports streaming output, dynamic tool calls, and session recovery.
- Provider IDs:
- ChatGPT:
openai-codex - Grok:
xai-grok
- ChatGPT:
- Dependency requirements: The plugin itself does not scan
node_modulesor download model binaries. It requires the official CLI to be already installed in the system path in order to run.
Installation and Enablement¶
DSH does not automatically scan node_modules. For a plugin to take effect, it must meet both of the following conditions: it must be installed in the profile workspace directory and listed in that profile’s package.json.
Use the official command to install it. It will automatically handle the two steps above:
dsh plugin --profile web add @canary-builds/dsh-connect
If the dsh plugin command is unavailable, you need to perform the following two steps manually:
- Enter the profile directory:
cd ~/.dsh/profiles/web
- Install the package and modify
package.json:
npm install @canary-builds/dsh-connect
Add the package name to the `dsh.profile.bundles` array in `package.json`:
"dsh": {
"profile": {
"bundles": [
"@deepseek-ai/dsh-base",
"@deepseek-ai/dsh-web-app",
"@canary-builds/dsh-connect"
]
}
}
After installation, restart the service for the corresponding profile (for example, `systemctl --user restart dsh-web`) and refresh your browser.
Prerequisites: Official CLIs¶
Both ChatGPT and Grok require the corresponding official CLI to be installed separately. They must be installed under the same user that runs DSH; otherwise, they cannot be executed.
| Provider | Binary Name | Installation Requirement |
|---|---|---|
| ChatGPT | codex |
Must be installed. If not installed, ChatGPT login will fail immediately. |
| Grok | grok |
Must be installed. Grok does not depend on Codex. |
The ChatGPT codex binary can be installed with npm install -g @openai/codex. After installation, restart DSH.
Configuration and Environment¶
SSH Port Forwarding¶
The ChatGPT OAuth callback address is fixed to 127.0.0.1:1455. If you are running the DSH Web UI on a remote server, you must configure SSH port forwarding; otherwise, login cannot be completed:
ssh -N -o ExitOnForwardFailure=yes -L 3080:127.0.0.1:3080 -L 1455:127.0.0.1:1455 user@harness-host
Grok device login does not require port forwarding. You can enter the device code directly on the settings page.
Environment Variables and Configuration File¶
The plugin supports overriding default paths through environment variables or a configuration file.
Environment variables:
* DSH_CODEX_BIN: Specifies the absolute path to the Codex executable.
* DSH_CODEX_HOME: Specifies the Codex login directory (default ~/.deepseek-harness/codex).
* DSH_GROK_BIN: Specifies the absolute path to the Grok executable.
* DSH_GROK_HOME: Specifies the Grok login directory (default ~/.grok).
Configuration file:
The default path is ~/.dsh/connect.json. This file is used to store path configuration. Do not store credentials here.
{
"codexBin": "/absolute/path/to/codex",
"codexHome": "/absolute/path/to/codex-home",
"grokBin": "/absolute/path/to/grok",
"grokHome": "/absolute/path/to/grok-home",
"noProxy": "example.com"
}
Diagnostic Tool¶
Use the dsh-connect-doctor command to check whether the environment configuration is correct. This command is located in the node_modules/.bin directory of the profile.
Permissions and Security¶
- Tool execution permission: Harness has final authority over tool execution. The plugin disables Codex’s native tool calls and instead executes them through Harness.
- Grok restriction: Grok does not have access to the shell or file system. When Grok requests a tool, the plugin returns it to Harness for processing instead of executing it inside the Grok process.
- Version pinning: It is recommended to pin versions in production environments, for example
@canary-builds/dsh-connect@0.4.0.
Directory and Links¶
This plugin is listed in the community directory: dhs-connect - SkillHub
Source code and changelog: Canary-Builds/dhs-connect - GitHub