DeepSeek Harness Plugin Hub

Publish and manage complete Harness Profiles. Discover Plugins for your next setup.

Explore

PluginsPresetsDocsNews

Community

Publish a pluginContactReport an issue

Resources

Plugin Hub on GitHubDeepSeek HarnessSystem statusPrivacy notice
© 2026 DeepSeek Harness Plugin HubPowered byPaxTech

Independent and unofficial. Not affiliated with, authorized by, or endorsed by DeepSeek.

Plugin Oauth Subs — DSH Plugin for DeepSeek Harness
← Plugins
P

dsh-plugin-oauth-subs

Plugin Oauth Subs

ChatGPT Codex, xAI Grok, Zhipu GLM, AWS Kiro, Google Antigravity, Cursor, Ollama Cloud, Kimi, and GitHub Copilot subscription OAuth for DeepSeek Harness — PKCE / device-code / Google login, local Responses proxy, llm-pi-ai sync.

The plugin will be installed here. Keep web if you are unsure.

npx -y @deepseek-ai/dsh plugin --profile web add github:xxww0098/dsh-plugin-oauth-subs#b2cfdb633a4bdc95b3f9e19aa4b0b58acabf70b2
READMECompatibilityVersions

Compatibility and provenance

Plugin Oauth Subs is published as dsh-plugin-oauth-subs and currently resolves to version 0.0.95. The Hub verifies its manifest and preserves the exact installation source for reproducible installs.

DSH compatibility
*
Runtime surfaces
web
Release source
github
Registry updated
9/20/2026

Versions

0.0.95stable
9/20/2026
0.0.94stable
9/19/2026
0.0.93stable
9/18/2026
Show 23 more versionsCollapse versions
0.0.92stable
9/17/2026
0.0.91stable
9/17/2026
0.0.90stable
9/15/2026
0.0.89stable
9/11/2026
0.0.88stable
9/10/2026
0.0.87stable
9/10/2026
0.0.85stable
9/9/2026
0.0.84stable
9/9/2026
0.0.83stable
9/9/2026
0.0.81stable
9/8/2026
0.0.80stable
9/7/2026
0.0.79stable
9/6/2026
0.0.78stable
9/6/2026
0.0.77stable
9/6/2026
0.0.76stable
9/5/2026
0.0.75stable
9/5/2026
0.0.74stable
9/5/2026
0.0.73stable
9/5/2026
0.0.70stable
9/3/2026
0.0.69stable
9/3/2026
0.0.68stable
9/3/2026
0.0.65stable
9/3/2026
0.0.63stable
9/3/2026

Related plugins

Loading related plugins…

Latest
0.0.95
DSH
*
HMR
Process restart
Tree shaking
Safe tree shaking not declared
Unpacked size
Unavailable
Files
Unavailable
Surface
web
License
MIT
Source
github
GitHub
★ 4
Weekly downloads
0
Last push
9/20/2026
View source ↗
README badge

Click the badge to copy Markdown for your README.

Do you maintain this Plugin?Claim benefit · Priority security scan

Verify the GitHub repository declared in package.json to manage this listing. After you claim it, Hub will prioritize a security scan of the current version and publish the result when it passes.

Claim this Plugin →
Report an issue
DeepSeek Harness Plugin Hub
ProfilesPluginsCategoriesNewsDocsSign inManage Profiles
ProfilesPluginsCategoriesNewsDocsSign in

Related plugins

More verified plugins in security-access.

Doctor@linxin666/dsh-doctorTransactional rescue mode for DSH profiles with a supervised launcher, isolated recovery capsule, deterministic repairs, health monitoring, and a local Web recovery consolePocketdsh-pocketPut DeepSeek Harness in your pocket: one package, one settings page, and scan a QR code on your phone to access DSH on your computer in sync (LAN + public network, real-time screen mirroring).DSCODE@toddzheng024/dscode-bundleA complete DeepSeek coding agent with persistent shell, Ultra collaboration and automatic permission review.Auto Reviewdsh-auto-reviewSecond-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent decides allow/deny on the approval answerer chain, with fail-closed fallback and full session-log audit.

README

dsh-plugin-oauth-subs

简体中文 | English

Use a ChatGPT / Codex, xAI Grok, Zhipu GLM, AWS Kiro, Google Antigravity, Cursor, Ollama Cloud, Kimi Code Plan, GitHub Copilot, Devin Agent, or Cline subscription inside DeepSeek Harness. Official OAuth, plus Kiro API keys, Cursor CLI/IDE reuse, Ollama API keys (ollama.com Cloud, not localhost:11434), Kimi device-code / kimi-code.json, GitHub Copilot device-code / hosts.json, Devin CLI credentials.toml, and Cline WorkOS device-code. Loopback proxy + llm-pi-ai route sync; each family picks one DSH api from openai-responses | openai-completions | anthropic-messages.

Install

dsh plugin --profile web add https://github.com/xxww0098/dsh-plugin-oauth-subs
dsh web

Open Settings → OAuth subs. One card per account (quota on every card; Ollama Cloud has no quota bars). About Installed re-reads the package.json this process loaded (not a module-load freeze). A leftover dsh web after a wrapper/pidfile restart still serves the old process until that PID is killed (pgrep -lf 'dsh web'). If profile node_modules is newer, About lists On disk and may add …#<tag> even when that file is already latest. Or pnpm dsh web --patch ./cordis.patch.yml (id: oauth-subs).

Families

ProviderAuthDSH apiUpstream hop
ChatGPT CodexPKCE localhost:1455 (1457 fallback); paste-callback; app_EMoamEEZ73f0CkXaXp7hrannopenai-responseschatgpt.com/backend-api/codex/responses
xAI GrokDevice-code (default); PKCE 127.0.0.1:56121; b1a00492-073a-47ea-816f-4c329264a828openai-responsesapi.x.ai/v1/responses
GLM · Z.ai (global)ZCode CLI poll provider: zai; mint id.secret; client_P8X5CMWmlaRO9gyO-KSqtganthropic-messagesapi.z.ai/api/anthropic (Completions leftover …/coding/paas/v4)
GLM · BigModel (China)Same CLI poll, provider: bigmodel; poll JWT is the bearer; client zcodeanthropic-messagesopen.bigmodel.cn/api/anthropic (Completions leftover …/coding/paas/v4)
AWS KiroSocial PKCE app.kiro.dev (3128…53153) / Builder ID / IdC / Entra / ksk_openai-completionsq.<region>.amazonaws.com GenerateAssistantResponse
Google AntigravityGoogle OAuth localhost:51121; paste-callback; 1071006060591-…apps.googleusercontent.comopenai-completionsdaily-cloudcode-pa.googleapis.com/v1internal:streamGenerateContent
CursorPKCE poll cursor.com/loginDeepControl; or Import local Cursoropenai-completionsConnect agentn.us.api5.cursor.sh AgentService/Run
Ollama CloudPaste API key / import OLLAMA_API_KEYopenai-completionshttps://ollama.com/v1/chat/completions
Kimi Code PlanDevice-code (no PKCE); import ~/.kimi-code/credentials/kimi-code.json; optional KIMI_API_KEYopenai-completionshttps://api.kimi.com/coding/v1/chat/completions
GitHub CopilotDevice-code (no PKCE); import ~/.config/github-copilot/hosts.json; optional GITHUB_TOKENopenai-completionshttps://api.githubcopilot.com/chat/completions (tid= session)
Devin AgentPKCE 127.0.0.1:59653; import ~/.local/share/devin/credentials.toml; paste devin-session-token$…openai-completionsConnect server.codeium.com ApiServerService/GetChatMessage
ClineWorkOS device-code (no PKCE); import ~/.cline/data/settings/providers.jsonopenai-completionshttps://api.cline.bot/api/v1/chat/completions
PathFamily
------
~/.codex/auth.jsonCodex
~/.grok/auth.json, ~/.hermes/auth.jsonGrok
~/.zcode/v2/config.json (also older cli/config.json / config.json)GLM
~/.kiro/credentials.json; credentials.json (kiro.rs CWD); ~/.aws/sso/cache/kiro-auth-token.jsonKiro
Settings paste: kami / JSON / CSV / Social refresh / ksk_…Kiro
~/.gemini/antigravity-cli/antigravity-oauth-token; ~/.cli-proxy-api/antigravity-*.jsonAntigravity
macOS Keychain cursor-access-token / cursor-refresh-token; IDE state.vscdb (current OS user only); CURSOR_ACCESS_TOKENCursor
OLLAMA_API_KEY env (not ~/.ollama/id_ed25519.pub)Ollama Cloud
~/.kimi-code/credentials/kimi-code.json; read-only ~/.kimi/credentials/kimi-code.json; KIMI_API_KEYKimi
~/.config/github-copilot/hosts.json; OpenCode ~/.local/share/opencode/auth.json; COPILOT_GITHUB_TOKEN / GITHUB_TOKEN / GH_TOKENCopilot
~/.local/share/devin/credentials.toml ($XDG_DATA_HOME/devin/; Windows %LOCALAPPDATA%\devin\); DEVIN_API_KEY / WINDSURF_API_KEYDevin
~/.cline/data/settings/providers.jsonCline

Tokens: <profile>/data/dsh-plugin-oauth-subs/auth.json (0600). Models: models.json beside it.

How it works

PlaneRole
SettingsOAuth login / import / logout, then model sync
llm-pi-aiDSH call plane; routes to the loopback proxy
Loopbackhttp://127.0.0.1:8318/{codex,grok}/v1/responses, /glm/v1/messages (Completions leftover /glm/v1/chat/completions until the next sync), /{kiro,antigravity,cursor,ollama,kimi,copilot,devin,cline}/v1/chat/completions
UpstreamRefreshed subscription bearer

Not a second LLM adapter. After Settings closes, DSH still calls the loopback proxy. Bind is loopback-only; local credential is DSH_OAUTH_SUBS_API_KEY. GLM 150% Coding Plan boost is identity (ZCode Desktop UA), not a protocol claim. Stack and module tree: AGENTS.md. Reference hops (official CLI + community reverse): docs/oauth.md.

Cache

Acceptance on the full session-772f7f3a-… SkillStar turn (oauth-codex / gpt-5.6-terra-fast, 211 calls, 71 min):

2026-08-26 incidentAfter 0.0.14 affinity headers
Weighted cache hit27.4%95.6%
Prefix reuse (median)—99.6%
Affinity misses47 / 90 zero-cache0
Prefix rewrites—1 adapter rebuild + 9 compaction
TRANSPORT faults290

Codex cache hit Codex affinity misses and TRANSPORT

Remaining uncached tokens are almost all new tool output (delta) plus expected prefix rewrites: leaving plan mode (step 55, 169k) and DSH compaction (330k); the next call after each rewrite reused ~99%. Healthy: weighted hit ≥ 80%, zero affinity misses, no TRANSPORT. Compaction / request/header rebuild zeros do not fail the session. Details: docs/error.md.

Diagnose

npm run analyze -- path/to/session.jsonl
node --experimental-strip-types scripts/analyze-session.ts --json path/to/session.jsonl
node --experimental-strip-types scripts/analyze-session.ts --fail-below 80 path/to/session.jsonl

The analyzer labels each call cold_start / delta / compaction / rebuild / affinity_miss so a compacted session is not flagged as a shard regression. Import as dsh-plugin-oauth-subs/analyze-session.

Fast / models / reasoning

Login and chat use official client identity; UA / fingerprint live in each src/oauth/<id>/README.md. The repos those fingerprints were copied from are listed in docs/oauth.md. Settings → Models: per-family checkboxes (default all on except 900K). Reasoning is set in the Harness session menu, not Settings → Models. Fast and 900K spend quota faster.

FamilyFastWindowThinking
Codex GPT-6 Astra / GPT-5.6 Sol / Terra / LunaYes. -fast → Priority (service_tier: "priority" + x-codex-routing-hint; store: false)258K default; -900k (872K)low / medium / high / xhigh / max
Other Codex5.4 / 5.5 Yes; Mini / Spark No (empty service_tiers; leftover *-fast peeled locally)GPT-5.4 -900k (1M)low–xhigh (no minimal)
GrokNo. 2026-08-30: 83.34 vs 82.80 tok/s (0.994). Older ids reject the field—4.6: low / medium / high / xhigh (unset = high); 4.5: no xhigh
GLM——5.3 / Flash: low / high / max (default max; no medium; disabled 400s). Turbo: on, no depth. Flash is the only GLM image row
Kiro——GPT-5.6: off / low / medium / high / xhigh / max (off → wire none). Opus 5 / 4.8 / 4.7 and Sonnet 5 add xhigh; 4.6 family to max; Haiku / OSS: none. Catalog: kiro.dev/docs/models (no Auto)
Ollama CloudNoLive GET /api/tags (static 20-row Cloud snapshot fallback). Context from POST /api/show model_info.<family>.context_length. No quota barsoff / low / medium / high / max (off → wire none)
KimiNoLive GET /coding/v1/models (static kimi-for-coding / highspeed / k3, 256k/32k). Prefix-hash cacheoff / minimal / low / medium / high / xhigh / max → thinking.effort
CopilotNoLive GET {api}/models (static GPT / Claude / Gemini / Grok floor). Prefix-hash + X-Interaction-Idlive reasoning_effort when the catalog advertises it
DevinYes. -fast is a real backend variant (not Codex Priority), never through

Codex Priority echo created=auto / completed=default is not a confirmation (openai/codex#14204). 2026-08-26 Luna: 88.3 vs 57.5 tok/s (1.54×); 2026-08-30 interleaved mean 1.33× (1.90 then 0.93). Throughput-only; TTFT and cache unchanged.

Quota

SubscriptionEndpointDisplay
ChatGPT Codexchatgpt.com/backend-api/wham/usagePlan badge (Plus / Pro / Team …) plus 5-hour + weekly windows, remaining percent and reset time
ChatGPT Codex reset…/wham/rate-limit-reset-credits + /consumeBanked weekly-window reset credits and expiry; one confirm button per credit on the Codex card
xAI Grokcli-chat-proxy.grok.com/v1/billing?format=credits plus /v1/user?include=subscriptionPlan badge (SuperGrok / X Premium+ …) plus period usage, prepaid balance, product split
Zhipu GLMapi.z.ai or open.bigmodel.cn monitor/usage/quota/limitPlan badge (Lite / Pro / Max) plus Coding Plan credit windows; host follows the active account
Google Antigravitydaily-cloudcode-pa loadCodeAssist + fetchAvailableModels (prod only on 5xx / transport)Plan badge (Pro / Ultra / Free / Standard) plus SkillStar model-group remaining bars and reset time
Cursorapi2.cursor.sh DashboardService/GetCurrentPeriodUsagePlan badge (Free / Pro / Pro+ / Ultra …) plus cycle remaining percent
Kimi Codeapi.kimi.com/coding/v1/usages + /mePlan badge from /me.user_level_name plus remaining bars; no invented reset times
GitHub Copilotapi.github.com/copilot_internal/userPlan badge (Free / Pro / Pro+ / Business / Enterprise) plus Premium remaining percent
Devinserver.codeium.com SeatManagementService/GetUserStatusPlan badge (Pro / Max / Teams / Enterprise / Free / Trial) plus daily + weekly remaining bars when the tier exposes them
Clineapi.cline.bot /users/me + /users/{id}/balance (micro-USD) + /users/me/plan; ClinePass adds /plan/usage-limitsPlan badge plus prepaid credit balance ($x.xx); ClinePass adds 5-hour / weekly / monthly bars. Credit accounts have no window bars

Refresh about once a minute, or Refresh quota. Bars: hsl(remaining × 1.2, 78%, 38%). Codex pro → Pro 20x / $200, prolite → Pro 5x / $100. Plus/Pro may bank weekly resets — one confirm button per credit on the Codex card (Harness risk dialog, then POST …/consume with { redeem_request_id } + idempotencyKey). That spend refreshes the weekly window. Grok has no equivalent. Ollama Cloud has no documented quota JSON (/api/quota 404); the card stays idle with no bars.

Options

OptionDefaultNotes
port8318Loopback proxy port
provideroauthllm-pi-ai route prefix (oauth-codex / oauth-grok / oauth-glm / oauth-antigravity)
dataDirprofile data dirauth.json, models.json, and proxy-key
grokLogindevicedevice or pkce
proxyUrlsettings / envOutbound HTTP(S) proxy for model / quota / login hops
cursorProxy—Cursor upstream proxy (http:// or socks5://) for region-gated models

Develop

npm test
npm run analyze -- path/to/session.jsonl

See CONTRIBUTING.md.

applyFastMode
Live GetCliModelConfigs (46 families; static fallback)
Mapped to backend chat_model_uid per family (defaultUid); thinking / fast / 1m become picker rows
ClineNoLive GET /ai/cline/recommended-models (static feed snapshot fallback)off / minimal / low / medium / high / xhigh / max → reasoning_effort (max→xhigh; no off)