khiqwq/dsh-credentials-system

A DeepSeek Harness credential provider backed by the operating system's user-bound secret protection. $DSH_HOME/.credentials.system.json holds only versioned DPAPI ciphertext and reference names; a blob is bound to the current Windows user, the store id and its exact credential reference, and there is no plaintext-file, environment-variable, machine-wide or local-key fallback. describe() returns only configured, source and writable — there is no reveal API. It also provides provider.migrateLegacy({ refs?, archive? }), a Host-side migration from the legacy plaintext YAML that strictly parses, encrypts each selected value, verifies the write in memory and only renames the source when every entry migrated, plus an explicit portable export encrypted with scrypt (N=131072, r=8, p=1) and AES-256-GCM.

Other ★ 0 updated 2026-08-14 ✅ runtime-tested
View on GitHub ↗

Install

⚠️ Install command not yet confirmed — check the README on GitHub for the exact command.

Compatibility

Windows x64/ARM64 only — it relies on the OS user-bound secret protection (DPAPI CurrentUser). The README is explicit that it must replace the built-in plaintext provider and never run as an automatic fallback: @deepseek-ai/dsh-credentials-local stores plaintext in $DSH_HOME/.credentials.yaml, and owner-only permissions plus role("secret") redaction are boundaries, not encryption.

Details

Recent updates

The README documents the security properties, the composition and the migration path rather than a versioned changelog; version 0.1 is the only release described. Verify the repository before adopting it.

FAQ

How do I install dsh-credentials-system?
There is no one-line install — the README documents disabling @deepseek-ai/dsh-credentials-local and inserting the credentials-system row in your profile's cordis config; verify the exact composition in the repository.
Which platforms are supported?
Windows x64/ARM64 in version 0.1, using DPAPI CurrentUser; the README describes no other backend.
Can I export credentials?
Yes, as an explicit backup/migration operation: the README says the complete payload, including reference names, is encrypted with scrypt (N=131072, r=8, p=1) and AES-256-GCM, and a wrong passphrase and a damaged file return the same error.

Alternatives

fieldnote-ops/keyringseam · revive/dsh-git-credentials · ChenLaoshiYF/dsh-mcpguard

More plugins in Other

Browse more in Other

Guides for Other plugins