Back to directory

dsh-authinone

Curated pickMaintenance: Active

stormycry-cryp/dsh-authinone

Self-contained DeepSeek Harness (DSH) plugin for Provider/Auth login, model switching, image fallback, token/cost analytics, and same-port Web restart. Useful? A star helps.

View on GitHub
$ dsh plugin add dsh-authinone

104

stars

0

forks

JavaScript

Language

MIT

License

2026-08-14

Created

2026-08-15

Last push

MIT-licensed, self-contained DSH plugin: one bootstrap command installs Provider/Auth login, model switching, vision fallback and token/cost analytics into DSH's native Models and Usage settings, then restarts Web on its original port.

DSH integration

Native runtime

Author-claimed

Safety audit

Unaudited

Last verified

2026-08-27

License

MIT

01What can it help you accomplish?

  • Sign in with OpenAI Codex or Kimi Code, or opt into a labeled compatibility flow, directly inside DSH

    Browser OAuth (state + S256 PKCE + loopback) for OpenAI Codex; RFC 8628 device-flow authorization link for Kimi Code; credentials written through DSH Host credentials, never into the browser

    Developers who want Provider account login (Codex / Kimi) and compatibility flows inside DeepSeek Harness

  • Manage API-key and custom OpenAI-compatible Providers, and switch the future-session default model

    DSH's native Provider cards stay the only place to add/edit/remove an API-key Provider; AuthInOne adds a connection/default-route projection, an Add Auth login action, and an Add Plan / API Key action

    Operators who manage API keys, custom Base URLs, headers and default model routing inside DSH

  • Get cross-session token usage and auditable cost analytics inside DSH's native Usage settings

    KPI, heatmap, model, Provider, bucket and cost projections rebuilt from real DSH session logs; successful auxiliary calls appear separately as Vision-assist calls and Vision-assist Token

    Teams that need reconstructable Provider/model/tool token usage and auditable calculated cost

02How to install into DeepSeek Harness

Prerequisites

  • A running standard DSH Host — the bootstrap discovers the single listener at `http://127.0.0.1:3080/` and verifies that it is a standard DSH Host
  • A standard DSH launcher: an installed `dsh` executable or an explicit/inferred DSH source root; automatic listener verification currently supports macOS and Linux and requires `lsof`
  • No patched DSH core, manual profile edit, second Web instance, or temporary port is required

Installation steps

  1. 01

    Install or upgrade the immutable tag with the package-owned bootstrap: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 install --profile web`

  2. 02

    For a non-default loopback port, provide the exact current URL: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 install --profile web --url http://127.0.0.1:3090/`

  3. 03

    When DSH runs from a source checkout, make it explicit: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 install --profile web --source-root /path/to/deepseek-harness`

Verify the integration

  • Inspect the detached handoff after the URL returns: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 status --profile web`
  • The install command returns before the old Host stops; the browser may disconnect briefly, then the same URL must return

Rollback

  • Remove the plugin through the same self-contained path: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 uninstall --profile web`

03DSH integration and capability boundaries

DSH integrationNative runtime

Self-contained bootstrap via the official dsh CLI — installs through the `dsh plugin` add path, then replaces the DSH Host on the same URL; Auth/Provider, Usage and cost analytics live inside DSH's native Models and Usage settings

  • Provider account login (OAuth / device flow)

    OpenAI Codex / Kimi Code / xAI Grok / Anthropic / GitHub Copilot / Command Code / Cursor / Google Antigravity / Kiro accounts→Credentials written through DSH credentials before the model adapter registers; refresh/logout unregister the route; the browser never receives the stored credential

    xAI Grok, Anthropic, GitHub Copilot, Command Code, Cursor, Google Antigravity and Kiro are explicitly marked Experimental compatibilityQwen account OAuth is discontinued and unavailable
  • API-key and custom OpenAI-compatible Provider management

    API keys, custom Base URLs, request headers, protocol choice and model mappings→Native DSH Provider cards preserved; AuthInOne adds a connection/default-route projection, Add Auth login and Add Plan / API Key actions above the native add-Provider buttons

    Custom OpenAI-compatible Base URL, headers and model mapping are a native DSH capability, not replaced by the plugin
  • Vision fallback for text-only main models

    DSH version-one raster image attachments: PNG, JPEG, WebP and GIF→When the main model explicitly omits image capability, a separately configured vision model describes images and the text is recorded as durable DSH messages with plugin provenance; resume and fork reuse the recorded result

    Vision fallback is off by default under Settings → ModelsAudio, video, PDF, image generation, browser object URLs, host paths and plugin-owned base64 storage are not accepted
  • Cross-session usage and cost analytics

    Token activity, model usage, Provider and cost data rebuilt from DSH session logs→KPI, heatmap points, rankings, Token buckets and cost projections driven by shared Time / Provider / output-price filters; Vision-assist calls and Token shown separately

    Missing prices remain unknown or unpriced — never a forged zero or another Provider's price
  • Same-port Web restart

    A running standard DSH Host (single listener at http://127.0.0.1:3080/)→Installs through the official DSH plugin add command, then replaces that Host on the same URL; the install command returns before the old Host stops and the same URL must return

    The browser may disconnect briefly during the replacementIt never falls back to another port
  • Plan / API presets

    OpenAI, xAI, Gemini, Anthropic, Kimi Code subscription keys, GLM Coding Plan, and ModelStudio/Qwen Coding Plan→Presets write credentials through DSH; GLM and Qwen vendor restrictions remain visible

    API keys are a separate connection method and never count as account Auth

04Who is it for? When not to use it?

Good for

  • Developers who want Provider account login (Codex / Kimi) and compatibility flows inside DeepSeek Harness
  • Operators who manage API keys, custom Base URLs, headers and default model routing inside DSH
  • Teams that need reconstructable Provider/model/tool token usage and auditable calculated cost

Not for

  • The exact compatibility target is official DSH `47f9438` and the current release is Alpha `v0.2.0-alpha.4`. Unknown or new DSH owner artifacts fail the install loudly; a changed or native-seam host fails with `AUTH_IN_ONE_COMPAT_UNSUPPORTED_DSH` instead of being silently replaced or double-registered.
  • Automatic listener verification currently supports macOS and Linux and requires `lsof`; the bootstrap only supports a credential-free loopback HTTP origin and a standard DSH launcher, and it never falls back to another port.
  • Seven compatibility account flows (xAI Grok, Anthropic, GitHub Copilot, Command Code, Cursor, Google Antigravity, Kiro) are explicitly Experimental compatibility, and Qwen account OAuth is discontinued. The project is not an official DeepSeek, OpenAI, or model-provider product and does not imply endorsement.

05Compatibility, maintenance and safety notes

  • The exact compatibility target is official DSH `47f9438` and the current release is Alpha `v0.2.0-alpha.4`. Unknown or new DSH owner artifacts fail the install loudly; a changed or native-seam host fails with `AUTH_IN_ONE_COMPAT_UNSUPPORTED_DSH` instead of being silently replaced or double-registered.
  • Automatic listener verification currently supports macOS and Linux and requires `lsof`; the bootstrap only supports a credential-free loopback HTTP origin and a standard DSH launcher, and it never falls back to another port.
  • Seven compatibility account flows (xAI Grok, Anthropic, GitHub Copilot, Command Code, Cursor, Google Antigravity, Kiro) are explicitly Experimental compatibility, and Qwen account OAuth is discontinued. The project is not an official DeepSeek, OpenAI, or model-provider product and does not imply endorsement.
  • Vision fallback accepts exactly DSH's version-one raster formats (PNG, JPEG, WebP, GIF) and not audio, video, PDF, image generation, browser object URLs, host paths or plugin-owned base64 storage; the plugin does not infer vision support when an adapter publishes no modality metadata.
2026-08-142026-08-15Not specified by the author

MIT · Alpha v0.2.0-alpha.4 · community-maintained and not a DeepSeek or OpenAI product (compatibility target: official DSH `47f9438`)

06Frequently asked questions

How do I install dsh-AuthInOne?

Run the package-owned bootstrap: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 install --profile web`. It validates the running standard DSH Host, calls the official `dsh plugin` add path, then replaces that Host on the same URL. It requires no patched DSH core, manual profile edit, second Web instance, or temporary port.

Which DSH versions are supported?

The exact compatibility target is official DSH `47f9438`, and the current release is Alpha `v0.2.0-alpha.4`. Unknown or new DSH owner artifacts fail the install loudly, and a changed or native-seam host fails with `AUTH_IN_ONE_COMPAT_UNSUPPORTED_DSH` instead of being silently replaced or double-registered.

Which Provider logins does it support?

OpenAI Codex uses browser OAuth with state, S256 PKCE and a loopback callback; Kimi Code opens an RFC 8628 device-flow authorization link. xAI Grok, Anthropic, GitHub Copilot, Command Code, Cursor, Google Antigravity and Kiro are explicitly marked Experimental compatibility, and Qwen account OAuth is discontinued.

What does the vision fallback accept?

For a main model that explicitly declares text-only input, a separately configured vision model describes images. It accepts exactly DSH's version-one raster formats — PNG, JPEG, WebP and GIF — and is off by default under Settings → Models. Audio, video, PDF and image generation are not accepted.

Does it store credentials or read my files?

OAuth verifier, authorization code, device code, access token and refresh token stay on the DSH Host; the plugin never imports `~/.codex/auth.json`, cookies, browser storage, OTPs or another product's credentials, and creates no separate database. To remove it, run `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 uninstall --profile web`.

08Data and sources

  • Author-claimedgithub.com190ecc2d834b…

    dsh-AuthInOne is a DeepSeek Harness plugin for Provider login, API and custom OpenAI-compatible Provider setup, model sw…

  • Author-claimedgithub.com190ecc2d834b…

    the self-contained bootstrap uses the official DSH plugin CLI and returns Web on its original port

  • Author-claimedgithub.com190ecc2d834b…

    It validates the running standard DSH Host, calls the official `dsh plugin` add path, then replaces that Host on the sam…

This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-08-27. Found an error? Submit a correction.

🏆

Best DeepSeek Harness Plugins

Twelve plugins worth installing first — picked from the whole catalog, across every category.

DSH Plugins is an independent community directory of DeepSeek Harness plugins. Not affiliated with or endorsed by DeepSeek. Third-party plugins are not security-audited — review the source before installing.

New DeepSeek Harness plugins, weekly. No spam.