FernanDAlumin/dsh-codex-subs-plugin

An experimental DeepSeek Harness adapter that uses ChatGPT OAuth to access a Cod

dsh-codex-subs-plugin is an experimental primary-model adapter for DeepSeek Harness that uses ChatGPT OAuth to route the primary LLM through an account's Codex subscription instead of an OpenAI Platform API key. It runs a browser PKCE + state flow with a 127.0.0.1-only callback (or a headless device-code flow), stores the access/refresh token and account id independently, translates DSH GenerateOptions into a Responses request sent only to chatgpt.com/backend-api/codex/responses, and translates the Responses SSE stream back into DSH StreamChunk -- preserving encrypted reasoning and tool replay state under store:false. It does not read or copy credentials from Codex CLI or OpenCode, does not convert a subscription into an API key, and refuses to follow redirects automatically, redacting network errors. Helper commands dsh-codex-subs status and ... doctor report local auth/installation/proxy/endpoint state without making a network request or printing tokens.

Coding & Development ★ 1 updated 2026-08-14 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile headless add .

Requirements: Node.js ^22.19.0 or >=24.0.0, pnpm, and an installed dsh CLI. From the repo root the README runs pnpm install, pnpm run check, then dsh plugin --profile headless add .. The bundle is non-invasive: it only registers the codex-subscription provider and does not replace DSH's existing default model. Do not confuse the npm name dsh-codex-subs-plugin (not published; empty on the registry 2026-09-30) with this package -- install from the repository. The README also documents dsh plugin --profile headless exec dsh-codex-subs login for login and ... logout to delete the local credential.

Compatibility

Node.js ^22.19.0 or >=24.0.0, pnpm, and an installed dsh CLI. Experimental: it depends on compatibility surfaces OpenAI does not document as stable (the auth.openai.com device-code endpoints, the ChatGPT-Account-Id header, and chatgpt.com/backend-api/codex), so server-side changes may break it, and a subscription does not provide unlimited usage. Credentials are stored independently at $DSH_CODEX_SUBS_AUTH_FILE or $DSH_HOME/codex-subs/auth.json or ~/.dsh/codex-subs/auth.json with atomic writes and 0600 permissions. If you only need Codex as a subagent, the README recommends DSH's built-in @deepseek-ai/dsh-subagent-codex instead.

Details

Recent updates

The README documents the OAuth + device-code login flows, the required settings.yaml default-model block (provider codex-subscription, model, reasoningEffort), the proxy environment (HTTP_PROXY / HTTPS_PROXY / NO_PROXY with lowercase precedence; ALL_PROXY is ignored), the unsupported_country_region_territory troubleshooting path, the plugin config row (llm-codex-subscription with config keys provider/displayName/reasoningEffort/textVerbosity/streamIdleTimeoutMs plus optional authFile and models, and no baseURL/endpoint setting), the implemented feature list (atomic refresh-token rotation, single-flight refresh, forced one safe replay after the first 401), and a development verification flow.

FAQ

How do I install dsh-codex-subs-plugin?
Per the README: from the repo root run pnpm install, pnpm run check, then dsh plugin --profile headless add .. It needs Node.js ^22.19.0 or >=24.0.0, pnpm, and an installed dsh CLI. The npm name dsh-codex-subs-plugin is not published, so install from the repository.
Does it use my API key?
No -- the README states it uses ChatGPT OAuth (PKCE browser flow or a headless device-code flow) and sends requests only to the fixed chatgpt.com/backend-api/codex endpoint. It does not read or copy credentials from Codex CLI or OpenCode and does not convert a subscription into an API key.
How do I verify the routing works?
The README's real runtime verification is dsh --profile headless "Reply with exactly: codex-subscription-ok", which reads the effective default model and sends a request through the adapter; a successful reply jointly verifies runtime routing, OAuth, networking, and server-side access (it consumes subscription usage).

Alternatives

Letter2025/dsh-model-failover · LiangYin233/dsh-provider-model-configurator · jiay98528-dev/dsh-model-sync

More plugins in Coding & Development

Browse more in Coding & Development

Guides for Coding & Development plugins