Skip to main content

How to use dsh-codex-provider

Connect DSH to OpenAI Codex via device code OAuth, run Codex models using ChatGPT Plus/Pro subscription—no API Key required.

This article is auto-derived from indexed fields (wiki / faq / compatibility_json), not freshly AI-generated.

This article is derived from the plugin's already-indexed fields (wiki / faq / compatibility_json / readme), not freshly generated by AI. Source field is noted at the end of each section.

Quick start

dsh-codex-provider

— source: plugin_wiki.wiki_content

Install & verify

dsh plugin --profile web add dsh-codex-provider

Run the command above in your DSH Web Profile. Then enable the plugin in the plugin list.

— source: plugins.install

Key points

  • 设备码 OAuth 登录:在界面点击“使用 OpenAI 账号登录”,按提示完成设备码授权,无需 API Key
  • 导入 Codex CLI 登录态:直接复用本机 ~/.codex/auth.json 中已有的登录(无需重新授权)
  • 令牌自动刷新:后台定期检查 access token,过期前自动用 refresh token 轮换(refresh_token 也会一并轮换)
  • 供应商管理界面:设置 → 供应商,展示登录状态、账号、套餐(Plus/Pro)、令牌过期时间,支持退出登录
  • 激活内置 Codex 模型:登录后 openai-codex 路由自动激活,模型选择器直接可选

— source: plugin_wiki.readme_en (fallback readme_raw)

FAQ

Do I need an OpenAI API Key?

No. This plugin consumes the ChatGPT Plus/Pro subscription quota (same channel as Codex CLI), login uses device code OAuth, not API Key billing.

I already have the official Codex CLI installed, can I reuse the login?

Yes. On the provider page, click "Import local Codex CLI login state", the plugin will directly read ~/.codex/auth.json, no re-authorization needed.

What if login fails with device code authorization denied?

You need to first enable "Enable device code authorization for Codex" in ChatGPT web "Settings → Account security and login", otherwise the OAuth server will reject device code issuance.

Will tokens auto-refresh?

Yes. The host side checks access token expiration every minute, when less than 10 minutes remain, it automatically refreshes using refresh_token (refresh_token is also rotated).

Where are credentials stored? Is it safe?

access token / refresh token are only written to DSH credential store (OPENAI_CODEX_API_KEY / OPENAI_CODEX_REFRESH_TOKEN), the browser side only receives anonymized account and login status; host process auto-refreshes every minute, original token is not returned to frontend.

Will I get logged out if I log in with Codex CLI at the same time?

They share the same OAuth session. After one side refreshes the token, the other side's old refresh_token may become invalid, in which case just re-run codex login on the Codex CLI side to recover.

Which models are supported?

Determined by the current DSH version and OpenAI account permissions, README examples include gpt-5.4, gpt-5.5, gpt-5.6-* and other built-in openai-codex series in DSH.

How to uninstall?

Just use dsh to remove the plugin, the host side will automatically revoke credentials (unset both credential store keys and remove apiKeyEnv reference in settings), after restart the provider partition will disappear.

— source: plugin_wiki.faq_json

Compatibility

  • DSH: >=0.1.0-rc.6
  • Node: >=22

— source: plugin_wiki.compatibility_json

Pitfalls

Review the upstream repo before installing. This guide is auto-derived from indexed fields and may lag the latest release. If anything contradicts the official docs, treat the upstream source as authoritative.

— source: general rule