Skip to main content

dsh-codex-connect

34Stars7Forks3Issues0Watchers

Use OpenAI Codex models in DSH via ChatGPT OAuth, with optional independent search, image understanding, and image generation capabilities.

Evidence5/5methodologySourceInstallMaintenanceDSH versionSecurity scan
Machine-auditedInstall commandRepo verifieddsh-plugin topicLicenseREADMEAI wiki
Language
TypeScript
License
Apache-2.0
Branch
main
chatgptcodexdeepseek-harnessdshdsh-plugingpt-image-2oauth

Install

cmdweb profile
$ dsh plugin --profile web add dsh-codex-connect

Run the command above in your terminal to install this plugin via the dsh CLI. You can switch Profile in the top-right corner. New to dsh? Read the beginner tutorial

Install via your agent

Install the DeepSeek Harness plugin franksong2702/dsh-codex-connect for me: review the repository at https://github.com/franksong2702/dsh-codex-connect first, then run the install command and verify the plugin loads successfully.

Paste this instruction to the DSH Web GUI assistant — it will install and verify for you.

One-Line Pitch

Enables users in DeepSeek Harness to log in with ChatGPT subscription and use OpenAI Codex models (including independent search, image reading, and image generation) as an LLM option without replacing the default model or global search routing.

Core Features

  • Log in with a ChatGPT OAuth account in Settings → Plugins → Plugin configuration → Codex Connect card; credentials are stored separately in $DSH_HOME/.openai-codex-auth.json, not shared with Codex CLI/Desktop
  • Use Codex models under the OpenAI Codex category in the model selector, while preserving Harness native streaming output, tool calls, reasoning replay, conversation compression, and permission approvals
  • Enable optional independent web search to register Codex as a search provider, but it will not automatically take over the profile's global search routing
  • Enable optional view_image tool to allow vision-enabled Codex models to read local files and public web images (DNS resolution and jump targets are fully verified and locked to public addresses)
  • Enable optional codex_connect_image_generate tool to invoke GPT Image generation, with images directly saved as DSH attachments and displayed in the conversation
  • Provide a standalone dsh-codex-connect CLI for login/logout, status, doctor, history migration, and on-demand browser origin allowance

Technical Implementation

  • Language: TypeScript (ESM, bundled with tsdown)
  • Key Dependencies: @deepseek-ai/cordis (plugin registration and fiber injection), @earendil-works/[email protected] (OpenAI Codex provider and OAuth flow), @deepseek-ai/dsh-llm-pi-ai (reusing common Adapter), @deepseek-ai/dsh-settings (settings-section editing)
  • Architecture Pattern: Inject llm-openai-codex line via cordis.patch.yml (all 3 capabilities default to false); Host-side apply() registers OAuth store, Transport, Adapter, and configurable Provider in one go; capabilities are dynamically mounted/unmounted via ctx.effect + reconcileXxx() in onChange of installSettingsSection for the three fiber groups: search / view_image / image_generate; Browser-side injects card via slots at settings.plugin.item and Fast Mode toggle with quota indicator at conversation.input.right
  • Entry Files: src/index.ts (Host plugin main, name = "llm-openai-codex", inject = ["llm"]), src/client/index.tsx (Browser-side, name = "dsh-codex-connect-client"), src/bin.ts (standalone CLI: doctor | login | logout | status | migrate-history | trust-origin, etc.)

Use Cases

Users who already pay for ChatGPT Plus/Pro and want to use Codex as an optional LLM in DSH; those who want Codex models but don't want to give up Harness's conversation persistence, compression, sub-agents, tool approvals, attachments, MCP, and skills. Codex Connect also serves as a smooth migration path from the old dsh-codex while preserving the three optional capability groups: search/image reading/image generation.

Prerequisites & Compatibility

DependencyMinimum VersionDescription
DeepSeek Harness Plugin API0.1.0-rc.7A group of @deepseek-ai/dsh-* packages must be upgraded together, see compatibility.json
@earendil-works/pi-ai0.82.1OpenAI Codex provider upstream, must be upgraded in sync with DSH packages
Node.js^22.19.0 || >=24.0.0Declared in package.json#engines
PlatformmacOS / Windows / LinuxmacOS and Linux enforce owner-only permissions on OAuth files (chmod 600), Windows automatically skips this check
Native Modules—None (only depends on built-in modules like node:http / node:https / node:net.BlockList)

Installation

dsh plugin --profile web add github:franksong2702/dsh-codex-connect

Configuration Options

ConfigTypeDescriptionDefault
enableSearchbooleanRegister Codex as an independent web search provider; not auto-selected as global searchfalse
enableImageToolbooleanEnable view_image tool: allow vision models to read local files and public web imagesfalse
enableImageGenerationbooleanEnable codex_connect_image_generate tool: generate images via GPT Image, results saved as DSH attachmentsfalse
searchModelstringCodex model ID for independent searchgpt-5.6-sol
searchModecached / indexed / liveSearch mode: use OpenAI cache / index / live fetchcached
searchContextSizelow / medium / highContext size returned by search APImedium
searchMaxOutputTokenspositive integerMax output tokens for search API10000

FAQ

Q: After installing Codex Connect, will the previously configured default model and search be changed?

A: No. cordis.patch.yml only inserts one line llm-openai-codex, and all 3 capabilities default to false. Profile's agent-default-model and web.searchProvider only take effect when you explicitly write them.

Q: Where are OAuth credentials stored? Are they the same as Codex CLI/Desktop?

A: Credentials are stored in $DSH_HOME/.openai-codex-auth.json (default ~/.dsh). This is a separate file and will not read or modify ~/.codex/auth.json; to migrate accounts to another machine, simply go through ChatGPT authorization again on the target machine.

Q: Is an OpenAI Platform API key required?

A: No. Codex Connect only uses the ChatGPT subscription's OAuth bearer token. Private OpenAI Platform credentials are neither read nor proxied—pricing, rate limits, and quotas are all based on the ChatGPT subscription.

Q: What information should not be pasted into issues, logs, or config files?

A: Do not paste any OAuth authorization URLs, device codes, refresh/access tokens, or account IDs; when encountering issues, just paste the sanitized output from dsh-codex-connect doctor --json.

Q: After upgrading DSH to 0.1.0-rc.7, the Codex search history from Alpha 4.10 can't be read. What to do?

A: First run dsh plugin --profile web exec dsh-codex-connect migrate-history --json to scan; after seeing hit events, stop all DSH processes that might write to that session root, then run with --apply --confirm-stopped --json to actually fix; a backup named .pre-codex-search-history-migration will be created in the same directory before fixing.

Q: Will doctor/status commands output secrets?

A: No. doctor only reads lstat metadata and outputs sanitized JSON with schema v1 (includes credential file status, capability switches, compatibility state, provider conflicts, prompts), no absolute paths or OAuth fields are printed; status --json only reports signed-in / signed-out.

Q: If I also have the old dsh-codex package installed, what happens?

A: Startup will be rejected due to provider ID conflict (Harness doesn't allow two adapters to register openai-codex), and you'll be prompted to either uninstall the conflicting party or remove the extra llm-openai-codex line from the profile before installing Codex Connect.

Getting Started Difficulty

Beginner — After installation, simply go to the settings card and click Sign in with ChatGPT once, then pick an openai-codex model in the model selector to use it; capabilities are disabled by default, so existing configuration is hardly affected.

Known Issues & Limitations

  • Codex endpoint doesn't enforce Responses API's max_output_tokens, so the server-side token limit for Harness compression summaries cannot be applied on this route (README.md:186)
  • POSIX platforms enforce strict owner-only validation on OAuth files; modes readable by group/others will be rejected on startup, need to run chmod 600 first (src/store.ts:32-50)
  • History fix command only supports dry-run on Windows; --apply mode is actively rejected at code level (src/history-migration.ts:295-297)
  • view_image remote URLs enforce public network verification: each redirect target must be re-resolved and the socket pinned to the verified address, otherwise rejected; local loopback, private networks, link-local, and cloud metadata endpoints are all unreachable (src/public-http.ts:59-103 / src/public-http.ts:167-173)
  • Uninstalling this package won't automatically delete OAuth credentials; must explicitly run dsh-codex-connect logout, otherwise $DSH_HOME/.openai-codex-auth.json will be retained (README.md:179)
  • After enabling independent search tool, it won't write plugin private required events in Session, so telemetry cannot be preserved across independent @deepseek-ai/dsh-session instances; but Harness's own web Tool records still normally fall into history (docs/design.md:19)

Read the usage guide →

Install steps, key points, FAQ and compatibility for this plugin — auto-derived from indexed fields.

Listing badge

Listed on deepseek-plugin.org
[![Listed on deepseek-plugin.org](https://img.shields.io/badge/listed_on-deepseek--plugin.org-007EC6)](https://deepseek-plugin.org/plugins/franksong2702/dsh-codex-connect)

Paste this markdown into your GitHub README to link back to this listing. The badge only states the listing — not a security endorsement.

← Back to plugin directory