dsh-codex-auth-bridge
其他 活跃维护

dsh-codex-auth-bridge

shaomingbo/dsh-codex-auth-bridge

轻量级bun生态工具包,依托Host Cordis能力复用Codex CLI的ChatGPT OAuth登录逻辑,目标平台无需额外开发身份验证模块即可开箱对接账号体系。

0
Stars 标星
0
Forks 分支
0
Watchers 关注
0
Open Issues
JavaScript
主要语言
MIT
开源协议
20 KB
仓库大小
1 个月前
最后推送
一键安装扩展 / 插件指令
dsh plugin --profile web add github:shaomingbo/dsh-codex-auth-bridge
git clone https://github.com/shaomingbo/dsh-codex-auth-bridge.git
git clone git@github.com:shaomingbo/dsh-codex-auth-bridge.git
README.md main

dsh-codex-auth-bridge

Reuse the Codex CLI's ChatGPT OAuth login in DeepSeek Harness (DSH).

The package is a Host Cordis bundle. It reads Codex's auth.json, keeps the OAuth token fresh through pi-ai's native openai-codex OAuth implementation, synchronizes the access token into DSH's credential service, and configures pi-ai's built-in openai-codex model route.

It does not contain, upload, or commit any token.

Requirements

  • Node.js 22.19 or later
  • A DSH installation using the dsh-llm-pi-ai adapter
  • Codex logged in with ChatGPT (~/.codex/auth.json contains auth_mode: "chatgpt")

Install

Run this on each device after logging in with Codex:

npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0

The installer:

  1. adds this package to ~/.dsh/profiles/web/package.json;
  2. adds dsh-codex-auth-bridge to that profile's dsh.profile.bundles list;
  3. runs pnpm install in the profile.

Restart dsh web afterward. The model picker will include the models exposed by pi-ai's installed openai-codex catalog.

Use another profile or source when needed:

npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0 --profile web
node ./bin/install.js --source file:../../packages/dsh-codex-auth-bridge

How it works

At startup, every ten minutes, and immediately before an openai-codex LLM stream:

  1. read ${CODEX_HOME:-~/.codex}/auth.json;
  2. decode the access-token expiry;
  3. refresh an expired or soon-to-expire token through @earendil-works/pi-ai;
  4. atomically write rotated tokens back to Codex's auth.json;
  5. store the current access token under OPENAI_CODEX_ACCESS_TOKEN using DSH's credential service.

The bundle also configures this composition base:

llm-pi-ai:
  providers:
    openai-codex:
      apiKeyEnv: OPENAI_CODEX_ACCESS_TOKEN

Because api is intentionally omitted, dsh-llm-pi-ai reuses pi-ai's provider-native openai-codex-responses transport instead of treating the ChatGPT backend as a generic OpenAI endpoint.

Environment overrides

Variable Default Purpose
DSH_CODEX_AUTH_PATH ${CODEX_HOME:-~/.codex}/auth.json Exact Codex auth file
DSH_CODEX_CREDENTIAL_REF OPENAI_CODEX_ACCESS_TOKEN DSH credential reference
DSH_CODEX_PROVIDER_ID openai-codex Provider route preflighted before requests
DSH_CODEX_REFRESH_MARGIN_MS 300000 Refresh margin before JWT expiry
DSH_CODEX_SYNC_INTERVAL_MS 600000 Background synchronization interval

If you override DSH_CODEX_CREDENTIAL_REF, also update apiKeyEnv in the bundle or your DSH settings.

Security notes

  • Codex's auth.json contains a rotating refresh token and must remain private.
  • DSH's local credential provider writes the synchronized access token to $DSH_HOME/.credentials.yaml, normally with mode 0600.
  • The plugin never logs token values.
  • A compare-before-write check avoids overwriting a newer refresh token if Codex refreshes concurrently.

Development

npm install
npm test
npm run check

License

MIT