jianghuife/dsh-open-auth-plugin

dsh-open-auth connects every chat provider currently built into pi-ai and provides one OAuth/API-key login CLI for DeepSeek Harness. It registers provider routes such as OpenAI Codex, Kimi Code, Anthropic and OpenRouter so subscriptions (ChatGPT Plus/Pro via the Codex flow, Kimi Code, GitHub Copilot-style accounts) can authenticate DSH model requests. The plugin and CLI share one permission-protected credential file (0600, atomic replace, cross-process lock during writes/refreshes) at ~/Library/Application Support/dsh-open-auth/auth.json (macOS), $XDG_CONFIG_HOME/dsh-open-auth/auth.json (Linux) or %APPDATA%/dsh-open-auth/auth.json (Windows). It deliberately does not maintain a duplicate provider allowlist — pi-ai's builtinModels() is the single source of truth, so upgrading pi-ai automatically exposes newly built-in providers.

Web UI Enhancements ★ 0 updated 2026-08-14 ✅ runtime-tested
View on GitHub ↗

Install

dsh plugin --profile web add dsh-open-auth

npm dsh-open-auth 0.1.1 verified 2026-09-04 (repository field → github.com/jianghuife/dsh-open-auth-plugin; npm name differs from repo name). Requires Node.js 22.19+. Install: dsh plugin --profile web add dsh-open-auth, then sign in, e.g. dsh plugin --profile web exec dsh-open-auth login openai-codex. A plain-Node alternative is npm install dsh-open-auth.

Compatibility

DeepSeek Harness LLM seam (llm-pi-ai) with Node 22.19+; do not load another LLM plugin that owns the same provider routes (duplicate-route rejection).

Details

Recent updates

Credentials are stored in a shared 0600 file, not an OS keychain — never commit or share it; it is not encrypted at rest.

FAQ

Which providers can I sign in to?
Every chat provider pi-ai currently builds in — OpenAI Codex, Kimi Code, Anthropic, OpenRouter and more — via one CLI: dsh plugin --profile web exec dsh-open-auth login <provider>.
Does this turn ChatGPT into an API key?
No. The openai-codex provider uses the OpenAI Codex OAuth flow and ChatGPT backend implemented by pi-ai; availability and limits stay subject to your OpenAI account and service terms.
Where are credentials stored?
In a shared credential file created with mode 0600 and replaced atomically. It is not an operating-system keychain and has no additional encryption.

Alternatives

DamonBao/dsh-codex-provider-plugin · franksong2702/dsh-codex-connect · Player-MINEPIG/dsh-llm-codex-oauth

More plugins in Web UI Enhancements

Browse more in Web UI Enhancements

Guides for Web UI Enhancements plugins