@tencent/dsh-adp
Tencent Cloud ADP as a DeepSeek Harness plugin bundle.
English · 中文
This plugin connects a DSH profile to Tencent Cloud ADP: gateway models (Hunyuan and friends), Hunyuan AI web search, the API/MCP plugin marketplace, the skill plaza, and ADP apps as ask tools. It is not ADP Worker.
Install
git clone https://github.com/TencentCloudADP/Tencent-ADP-dsh-plugin.git
cd Tencent-ADP-dsh-plugin
dsh plugin --profile web add .
# or a packed tarball: dsh plugin --profile web add ./tencent-dsh-adp-0.1.0.tgz
dsh web
Then open Settings → Plugins → Tencent Cloud ADP and fill in credentials (next section). Install issues (stale plugin name, pnpm build approval): docs/pitfalls.md.
Configure
ADP has three credential planes. The patch stores reference names (ADP_API_KEY, …); values live in $DSH_HOME/.credentials.yaml or the environment.
Official ADP API docs cover control-plane AKSK and AppKey SSE chat. They do not document the OpenAI-shaped model gateway this plugin also uses. Endpoints and key sources: API overview. Planes and error codes: docs/credentials.md.
Settings → Plugins → Tencent Cloud ADP card
| Plane | Reference | Official source | If missing |
|---|
Gateway sk- | ADP_API_KEY | Model-gateway API key (undocumented; see docs/credentials.md) | LLM / search / plugin calls fail with MISSING_CREDENTIAL |
| SecretId / SecretKey | ADP_SECRET_ID / ADP_SECRET_KEY | Public cloud: CAM API keys. Independent site: ADP console Key Management | Model / plugin / app catalogs stay empty |
| Per-app AppKey | e.g. ADP_APP_KEY_DEMO | App publish → API management or app Invoke (SSE) | The matching ask tool is not registered |
1. Open ADP
Register and complete real-name verification, then open the product (product overview). First login creates one enterprise and a default workspace; that workspace is not the string default_space this plugin ships in the patch (workspace overview).
| Site | Console | Control host | Agent SSE |
|---|
| Independent site | adp.tencent.com | capi.adp.tencent.com | https://adp.tencent.com/adp/v2/chat |
| Public cloud | adp.cloud.tencent.com | adp.tencentcloudapi.com | https://wss.lke.cloud.tencent.com/adp/v2/chat |
Both sites complete against https://api.adp.cloud.tencent.com/chat/completions (no /v1). There is no api.adp.tencent.com.
2. Get SecretId / SecretKey
Public cloud — CAM AKID… key (36 characters):
- Open CAM → API Key Management.
- Create a key if the list is empty (root account access keys). Copy SecretId and SecretKey at creation time; SecretKey is shown only once after 2023-11-30.
- Sub-accounts need ADP (formerly Large Model Knowledge Engine) read/write on the CAM role (FAQ). Collaborator accounts are not supported (122569).
Independent site — ADP console key (~26 characters, not AKID):
- Sign in at adp.tencent.com.
- Open Key Management and copy SecretId / SecretKey (API overview · independent site).
That pair signs control-plane calls (DescribeModelList, DescribeSpaceList, marketplace). It is not ADP_API_KEY.
3. Get the gateway sk- (ADP_API_KEY)
Create or copy an API key that authenticates POST https://api.adp.cloud.tencent.com/chat/completions (usually starts with sk-). Use this for Hunyuan / DeepSeek completions, Hunyuan search, and API/MCP plugin HTTP. Independent-site console AKSK cannot replace it.
4. Optional: AppKey
Needed only for adp_ask / adp_ask_<slug> (SSE to a published app), not for picking adp:Hunyuan/hy3.
- Publish the app.
- Open App Publish → Service Status → API Management, or App Management → Invoke, and copy AppKey (104209, 105560).
5. Fill the DSH card
- Run
dsh web on loopback (127.0.0.1). Credential writes are loopback-only.
- Settings → Plugins → Tencent Cloud ADP.
- Choose Independent site or Public cloud.
- Paste SecretId / SecretKey (and the gateway
sk-). Save. Values go through credentials.set into $DSH_HOME/.credentials.yaml.
- After AKSK is stored, the card lists workspaces from
DescribeSpaceList. Pick one. Public-cloud app and plugin calls need a real SpaceId; the patch default default_space is not a workspace on most accounts (control-plane 4510004). If the list is empty, paste a SpaceId from the ADP console (workspaces).
- Paste AppKey if you will use ask tools. Save again.
OneID on the card opens the ADP console in a new tab. It does not write any credentials.
A Claw-style “build the app entirely via API” walkthrough (CreateSpace → CreateApp → CreateAgent → CreateRelease → chat) is 133869. That path is AppKey SSE, not this plugin’s gateway adapter.
What you get
adp-core, llm-adp, web-adp, plugins-adp, skills-adp, agents-adp, and control-adp start with the plugin:
Model picker — Tencent Cloud ADP group
- Select
adp:Hunyuan/hy3 (or another gateway model) and complete a tool-using turn. How catalog vs completions are wired: docs/seams.md.
web_search through Hunyuan AI search when this provider is selected (China-centric index).
- Enable an API or MCP marketplace plugin via
adp_plugin_list / adp_plugin_enable, or enabledPluginIds. Public-cloud plugin/app calls need the workspace chosen above.
- Generated media links (~24h COS) are saved into the workspace as
saved_files.
- Skill plaza as a
ctx.skills provider (entries without download URLs stay in list only).
adp_provision_agent — CreateApp → CreateAgent → CreateRelease → FieldMask AppKey → adp_ask_<slug>.
adp_ask / adp_ask_<slug> — SSE ask; not a DSH subagent.
adp_list_actions / adp_call with allowMutating for App/Agent/Release CRUD. Mutating calls require approval.
Documentation
Verify
pnpm test # simulated HTTP; no secrets; CI gate
pnpm test:live # real account; skips when env is absent
Contributing
Issues and pull requests are welcome on GitHub. Run pnpm test before opening a PR.
License
MIT. Copyright (C) 2026 Tencent. See LICENSE.txt for the text and third-party notices (eventsource-parser, fflate).