FernanDAlumin/dsh-codex-subs-plugin
An experimental DeepSeek Harness adapter that uses ChatGPT OAuth to access a Cod
dsh-codex-subs-plugin is an experimental primary-model adapter for DeepSeek Harness that uses ChatGPT OAuth to route the primary LLM through an account's Codex subscription instead of an OpenAI Platform API key. It runs a browser PKCE + state flow with a 127.0.0.1-only callback (or a headless device-code flow), stores the access/refresh token and account id independently, translates DSH GenerateOptions into a Responses request sent only to chatgpt.com/backend-api/codex/responses, and translates the Responses SSE stream back into DSH StreamChunk -- preserving encrypted reasoning and tool replay state under store:false. It does not read or copy credentials from Codex CLI or OpenCode, does not convert a subscription into an API key, and refuses to follow redirects automatically, redacting network errors. Helper commands dsh-codex-subs status and ... doctor report local auth/installation/proxy/endpoint state without making a network request or printing tokens.
Install
dsh plugin --profile headless add .Requirements: Node.js ^22.19.0 or >=24.0.0, pnpm, and an installed dsh CLI. From the repo root the README runs pnpm install, pnpm run check, then dsh plugin --profile headless add .. The bundle is non-invasive: it only registers the codex-subscription provider and does not replace DSH's existing default model. Do not confuse the npm name dsh-codex-subs-plugin (not published; empty on the registry 2026-09-30) with this package -- install from the repository. The README also documents dsh plugin --profile headless exec dsh-codex-subs login for login and ... logout to delete the local credential.
Compatibility
Node.js ^22.19.0 or >=24.0.0, pnpm, and an installed dsh CLI. Experimental: it depends on compatibility surfaces OpenAI does not document as stable (the auth.openai.com device-code endpoints, the ChatGPT-Account-Id header, and chatgpt.com/backend-api/codex), so server-side changes may break it, and a subscription does not provide unlimited usage. Credentials are stored independently at $DSH_CODEX_SUBS_AUTH_FILE or $DSH_HOME/codex-subs/auth.json or ~/.dsh/codex-subs/auth.json with atomic writes and 0600 permissions. If you only need Codex as a subagent, the README recommends DSH's built-in @deepseek-ai/dsh-subagent-codex instead.
Details
- Repo: FernanDAlumin/dsh-codex-subs-plugin
- Category: Coding & Development
- Stars: 1
- Version: source / local checkout install (name dsh-codex-subs-plugin NOT published to npm -- registry empty 2026-09-30); MIT
- Last push: 2026-08-14
- First seen: 2026-08-14
Recent updates
The README documents the OAuth + device-code login flows, the required settings.yaml default-model block (provider codex-subscription, model, reasoningEffort), the proxy environment (HTTP_PROXY / HTTPS_PROXY / NO_PROXY with lowercase precedence; ALL_PROXY is ignored), the unsupported_country_region_territory troubleshooting path, the plugin config row (llm-codex-subscription with config keys provider/displayName/reasoningEffort/textVerbosity/streamIdleTimeoutMs plus optional authFile and models, and no baseURL/endpoint setting), the implemented feature list (atomic refresh-token rotation, single-flight refresh, forced one safe replay after the first 401), and a development verification flow.
FAQ
- How do I install dsh-codex-subs-plugin?
- Per the README: from the repo root run pnpm install, pnpm run check, then dsh plugin --profile headless add .. It needs Node.js ^22.19.0 or >=24.0.0, pnpm, and an installed dsh CLI. The npm name dsh-codex-subs-plugin is not published, so install from the repository.
- Does it use my API key?
- No -- the README states it uses ChatGPT OAuth (PKCE browser flow or a headless device-code flow) and sends requests only to the fixed chatgpt.com/backend-api/codex endpoint. It does not read or copy credentials from Codex CLI or OpenCode and does not convert a subscription into an API key.
- How do I verify the routing works?
- The README's real runtime verification is dsh --profile headless "Reply with exactly: codex-subscription-ok", which reads the effective default model and sends a request through the adapter; a successful reply jointly verifies runtime routing, OAuth, networking, and server-side access (it consumes subscription usage).
Alternatives
Letter2025/dsh-model-failover · LiangYin233/dsh-provider-model-configurator · jiay98528-dev/dsh-model-sync