dsh-openai-oauth
Maintenance: Activeadonissheldon/dsh-openai-oauth
Use ChatGPT OAuth and OpenAI Codex models in DeepSeek Harness—no API key or Codex CLI required.
Install
dsh has no central install command — add this plugin’s entry (documented in its README below) to your profile or patch config, then restart.
How installs work6
stars
0
forks
TypeScript
Language
MIT
License
2026-08-16
Created
2026-08-20
Last push
README
dsh-openai-oauth
OpenAI OAuth for DeepSeek Harness
English | 中文
Sign in to ChatGPT from DeepSeek Harness and use available Codex models without an OpenAI API key or Codex CLI. The plugin keeps the standard DSH sessions, tools, permissions, and model selector.
Features
- Browser login with PKCE or Device Code login
- Web settings and a headless login command
- Automatic token refresh
- Codex models in the standard DSH model selector
- Credentials stored locally under the Harness home
Requirements
- DeepSeek Harness
0.1.0-rc.8 - Node.js
^22.19.0or>=24.0.0 pnpmonPATH- A ChatGPT account with Codex access
Version 0.1.0 supports macOS and Linux. Windows support is not included yet.
Install
Install with an Agent (recommended)
Give this address to an Agent and ask it to follow the runbook:
https://raw.githubusercontent.com/AdonisSheldon/dsh-openai-oauth/main/AGENTS.md
When it finishes, you only need to approve any DSH restart and complete the ChatGPT login yourself.
Install with DSH
After the package is published:
dsh plugin --profile web add dsh-openai-oauth@0.1.0
dsh --profile web --dump-config
Install from the current checkout
pnpm install --frozen-lockfile
pnpm run check
pnpm pack
dsh plugin --profile web add ./dsh-openai-oauth-0.1.0.tgz
dsh --profile web --dump-config
Restart a running DSH Web process after installation.
Login and use
- Open Settings → OpenAI OAuth.
- Choose Browser login or Device Code.
- Sign in with a ChatGPT account that has Codex access.
- Open Models and select an
openai-codexmodel.
Browser login waits for a callback on 127.0.0.1:1455. Use Device Code when that port is unavailable or the browser is on another machine.
For a headless profile:
dsh plugin --profile headless add ./dsh-openai-oauth-0.1.0.tgz
dsh plugin --profile headless exec dsh-openai-login
The command asks which login method to use. Non-interactive terminals must pass --browser or --device-code.
Update and uninstall
dsh plugin --profile web update dsh-openai-oauth
dsh plugin --profile web remove dsh-openai-oauth
Restart DSH after installing, updating, or removing the plugin. Login, logout, and token refresh do not require a restart.
Sign out in Settings → OpenAI OAuth before uninstalling if the stored credential should also be deleted. Uninstalling the package otherwise preserves it.
Notes
- This connects a ChatGPT account to the Codex model provider; it does not create an OpenAI API key.
- The Web integration supports only a local DSH Host bound to
127.0.0.1. - Credentials are stored unencrypted at
$DSH_HOME/plugins/dsh-openai-oauth/credentials.json. - Model availability and quota depend on the signed-in account.
- OpenAI may change the Codex OAuth protocol independently of this plugin.
- This is an unofficial community project and is not affiliated with or endorsed by OpenAI or DeepSeek AI.
See SECURITY.md for security reporting and deployment notes.
More in Security & Auth
tencentmeeting-cli
by tencentcloud
Tencent Meeting command-line tool with OAuth2 authorization for meeting, recording and attendance-report management.
dsh-auto-review
by perrylink
Second-model AI auto-review for DeepSeek Harness approval requests: a read-only reviewer subagent returns structured allow/deny verdicts with reasons, fail-closed by default, fully auditable from the session log (approval/asked -> autoReview/verdict -> approval/decided).
dsh-permission-rules
by perrylink
Claude Code-style declarative permission rules for DeepSeek Harness: ordered allow/deny/ask rules with tool-name, argument (glob/regex), and workspace-path matching on the tools/pre-execute waterfall, session-log audit, and HMR reload.
dsh-clawrouter
by blockrunai
A safety gate for DeepSeek Harness: a stronger model reviews dangerous tool calls before they run. Plus vision and 67 models from one wallet, paid per request over x402.
