MIT-licensed, self-contained DSH plugin: one bootstrap command installs Provider/Auth login, model switching, vision fallback and token/cost analytics into DSH's native Models and Usage settings, then restarts Web on its original port.
DSH integration
Native runtime
Author-claimed
Safety audit
Unaudited
Last verified
2026-08-27
License
MIT
01What can it help you accomplish?
Sign in with OpenAI Codex or Kimi Code, or opt into a labeled compatibility flow, directly inside DSH
Browser OAuth (state + S256 PKCE + loopback) for OpenAI Codex; RFC 8628 device-flow authorization link for Kimi Code; credentials written through DSH Host credentials, never into the browser
Developers who want Provider account login (Codex / Kimi) and compatibility flows inside DeepSeek Harness
Manage API-key and custom OpenAI-compatible Providers, and switch the future-session default model
DSH's native Provider cards stay the only place to add/edit/remove an API-key Provider; AuthInOne adds a connection/default-route projection, an Add Auth login action, and an Add Plan / API Key action
Operators who manage API keys, custom Base URLs, headers and default model routing inside DSH
Get cross-session token usage and auditable cost analytics inside DSH's native Usage settings
KPI, heatmap, model, Provider, bucket and cost projections rebuilt from real DSH session logs; successful auxiliary calls appear separately as Vision-assist calls and Vision-assist Token
Teams that need reconstructable Provider/model/tool token usage and auditable calculated cost
02How to install into DeepSeek Harness
Prerequisites
- A running standard DSH Host — the bootstrap discovers the single listener at `http://127.0.0.1:3080/` and verifies that it is a standard DSH Host
- A standard DSH launcher: an installed `dsh` executable or an explicit/inferred DSH source root; automatic listener verification currently supports macOS and Linux and requires `lsof`
- No patched DSH core, manual profile edit, second Web instance, or temporary port is required
Installation steps
- 01
Install or upgrade the immutable tag with the package-owned bootstrap: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 install --profile web`
- 02
For a non-default loopback port, provide the exact current URL: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 install --profile web --url http://127.0.0.1:3090/`
- 03
When DSH runs from a source checkout, make it explicit: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 install --profile web --source-root /path/to/deepseek-harness`
Verify the integration
- Inspect the detached handoff after the URL returns: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 status --profile web`
- The install command returns before the old Host stops; the browser may disconnect briefly, then the same URL must return
Rollback
- Remove the plugin through the same self-contained path: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 uninstall --profile web`
03DSH integration and capability boundaries
Self-contained bootstrap via the official dsh CLI — installs through the `dsh plugin` add path, then replaces the DSH Host on the same URL; Auth/Provider, Usage and cost analytics live inside DSH's native Models and Usage settings
Provider account login (OAuth / device flow)
OpenAI Codex / Kimi Code / xAI Grok / Anthropic / GitHub Copilot / Command Code / Cursor / Google Antigravity / Kiro accounts→Credentials written through DSH credentials before the model adapter registers; refresh/logout unregister the route; the browser never receives the stored credential
xAI Grok, Anthropic, GitHub Copilot, Command Code, Cursor, Google Antigravity and Kiro are explicitly marked Experimental compatibilityQwen account OAuth is discontinued and unavailableAPI-key and custom OpenAI-compatible Provider management
API keys, custom Base URLs, request headers, protocol choice and model mappings→Native DSH Provider cards preserved; AuthInOne adds a connection/default-route projection, Add Auth login and Add Plan / API Key actions above the native add-Provider buttons
Custom OpenAI-compatible Base URL, headers and model mapping are a native DSH capability, not replaced by the pluginVision fallback for text-only main models
DSH version-one raster image attachments: PNG, JPEG, WebP and GIF→When the main model explicitly omits image capability, a separately configured vision model describes images and the text is recorded as durable DSH messages with plugin provenance; resume and fork reuse the recorded result
Vision fallback is off by default under Settings → ModelsAudio, video, PDF, image generation, browser object URLs, host paths and plugin-owned base64 storage are not acceptedCross-session usage and cost analytics
Token activity, model usage, Provider and cost data rebuilt from DSH session logs→KPI, heatmap points, rankings, Token buckets and cost projections driven by shared Time / Provider / output-price filters; Vision-assist calls and Token shown separately
Missing prices remain unknown or unpriced — never a forged zero or another Provider's priceSame-port Web restart
A running standard DSH Host (single listener at http://127.0.0.1:3080/)→Installs through the official DSH plugin add command, then replaces that Host on the same URL; the install command returns before the old Host stops and the same URL must return
The browser may disconnect briefly during the replacementIt never falls back to another portPlan / API presets
OpenAI, xAI, Gemini, Anthropic, Kimi Code subscription keys, GLM Coding Plan, and ModelStudio/Qwen Coding Plan→Presets write credentials through DSH; GLM and Qwen vendor restrictions remain visible
API keys are a separate connection method and never count as account Auth
04Who is it for? When not to use it?
Good for
- Developers who want Provider account login (Codex / Kimi) and compatibility flows inside DeepSeek Harness
- Operators who manage API keys, custom Base URLs, headers and default model routing inside DSH
- Teams that need reconstructable Provider/model/tool token usage and auditable calculated cost
Not for
- The exact compatibility target is official DSH `47f9438` and the current release is Alpha `v0.2.0-alpha.4`. Unknown or new DSH owner artifacts fail the install loudly; a changed or native-seam host fails with `AUTH_IN_ONE_COMPAT_UNSUPPORTED_DSH` instead of being silently replaced or double-registered.
- Automatic listener verification currently supports macOS and Linux and requires `lsof`; the bootstrap only supports a credential-free loopback HTTP origin and a standard DSH launcher, and it never falls back to another port.
- Seven compatibility account flows (xAI Grok, Anthropic, GitHub Copilot, Command Code, Cursor, Google Antigravity, Kiro) are explicitly Experimental compatibility, and Qwen account OAuth is discontinued. The project is not an official DeepSeek, OpenAI, or model-provider product and does not imply endorsement.
05Compatibility, maintenance and safety notes
- The exact compatibility target is official DSH `47f9438` and the current release is Alpha `v0.2.0-alpha.4`. Unknown or new DSH owner artifacts fail the install loudly; a changed or native-seam host fails with `AUTH_IN_ONE_COMPAT_UNSUPPORTED_DSH` instead of being silently replaced or double-registered.
- Automatic listener verification currently supports macOS and Linux and requires `lsof`; the bootstrap only supports a credential-free loopback HTTP origin and a standard DSH launcher, and it never falls back to another port.
- Seven compatibility account flows (xAI Grok, Anthropic, GitHub Copilot, Command Code, Cursor, Google Antigravity, Kiro) are explicitly Experimental compatibility, and Qwen account OAuth is discontinued. The project is not an official DeepSeek, OpenAI, or model-provider product and does not imply endorsement.
- Vision fallback accepts exactly DSH's version-one raster formats (PNG, JPEG, WebP, GIF) and not audio, video, PDF, image generation, browser object URLs, host paths or plugin-owned base64 storage; the plugin does not infer vision support when an adapter publishes no modality metadata.
MIT · Alpha v0.2.0-alpha.4 · community-maintained and not a DeepSeek or OpenAI product (compatibility target: official DSH `47f9438`)
06Frequently asked questions
How do I install dsh-AuthInOne?
Run the package-owned bootstrap: `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 install --profile web`. It validates the running standard DSH Host, calls the official `dsh plugin` add path, then replaces that Host on the same URL. It requires no patched DSH core, manual profile edit, second Web instance, or temporary port.
Which DSH versions are supported?
The exact compatibility target is official DSH `47f9438`, and the current release is Alpha `v0.2.0-alpha.4`. Unknown or new DSH owner artifacts fail the install loudly, and a changed or native-seam host fails with `AUTH_IN_ONE_COMPAT_UNSUPPORTED_DSH` instead of being silently replaced or double-registered.
Which Provider logins does it support?
OpenAI Codex uses browser OAuth with state, S256 PKCE and a loopback callback; Kimi Code opens an RFC 8628 device-flow authorization link. xAI Grok, Anthropic, GitHub Copilot, Command Code, Cursor, Google Antigravity and Kiro are explicitly marked Experimental compatibility, and Qwen account OAuth is discontinued.
What does the vision fallback accept?
For a main model that explicitly declares text-only input, a separately configured vision model describes images. It accepts exactly DSH's version-one raster formats — PNG, JPEG, WebP and GIF — and is off by default under Settings → Models. Audio, video, PDF and image generation are not accepted.
Does it store credentials or read my files?
OAuth verifier, authorization code, device code, access token and refresh token stay on the DSH Host; the plugin never imports `~/.codex/auth.json`, cookies, browser storage, OTPs or another product's credentials, and creates no separate database. To remove it, run `pnpm dlx github:Stormycry-cryp/dsh-AuthInOne#v0.2.0-alpha.4 uninstall --profile web`.
07Related DSH workflows
dsh-routing-suite
by yjh051108
dsh-routing-suite — injector + router-standard kit: install the runtime injector first, then the task-aware reasoning-mode router preset (measured P1-P23).
brooks-lint
by hyhmrright
AI code reviews grounded in 12 classic engineering books — decay risk diagnostics with book citations, severity labels, and 6 analysis modes including full-sweep auto-fix
dsh-plugin-shop
by livxue
The most comprehensive DeepSeek Harness plugin market — refreshed daily, sourced across the Internet, reviewed before publishing.
anolisa
by agentic-os-org
ANOLISA (Agentic Nexus Operating Layer & Interface System Architecture) | Agentic OS with runtime, security, observability, and Tokenless response compression for lower token usage and cost.
08Data and sources
dsh-AuthInOne is a DeepSeek Harness plugin for Provider login, API and custom OpenAI-compatible Provider setup, model sw…
the self-contained bootstrap uses the official DSH plugin CLI and returns Web on its original port
It validates the running standard DSH Host, calls the official `dsh plugin` add path, then replaces that Host on the sam…
This page is generated from the project’s public documentation, repository metadata and a structured parse of DSH Plugins; last verified on 2026-08-27. Found an error? Submit a correction.
Best DeepSeek Harness Plugins
Twelve plugins worth installing first — picked from the whole catalog, across every category.
