shaomingbo
dsh-codex-auth-bridge
No description
- Stars
- 0
- Language
- JavaScript
- Created
- Aug 15, 2026
- Updated
- Aug 15, 2026
Introduction
dsh-codex-auth-bridge
Reuse the Codex CLI's ChatGPT OAuth login in DeepSeek Harness (DSH).
The package is a Host Cordis bundle. It reads Codex's auth.json, keeps the OAuth token fresh through pi-ai's native openai-codex OAuth implementation, synchronizes the access token into DSH's credential service, and configures pi-ai's built-in openai-codex model route.
It does not contain, upload, or commit any token.
Requirements
- Node.js 22.19 or later
- A DSH installation using the
dsh-llm-pi-aiadapter - Codex logged in with ChatGPT (
~/.codex/auth.jsoncontainsauth_mode: "chatgpt")
Install
Run this on each device after logging in with Codex:
npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0
The installer:
- adds this package to
~/.dsh/profiles/web/package.json; - adds
dsh-codex-auth-bridgeto that profile'sdsh.profile.bundleslist; - runs
pnpm installin the profile.
Restart dsh web afterward. The model picker will include the models exposed by pi-ai's installed openai-codex catalog.
Use another profile or source when needed:
npx --yes github:shaomingbo/dsh-codex-auth-bridge#v0.1.0 --profile web
node ./bin/install.js --source file:../../packages/dsh-codex-auth-bridge
How it works
At startup, every ten minutes, and immediately before an openai-codex LLM stream:
- read
${CODEX_HOME:-~/.codex}/auth.json; - decode the access-token expiry;
- refresh an expired or soon-to-expire token through
@earendil-works/pi-ai; - atomically write rotated tokens back to Codex's
auth.json; - store the current access token under
OPENAI_CODEX_ACCESS_TOKENusing DSH's credential service.
The bundle also configures this composition base:
llm-pi-ai:
providers:
openai-codex:
apiKeyEnv: OPENAI_CODEX_ACCESS_TOKEN
Because api is intentionally omitted, dsh-llm-pi-ai reuses pi-ai's provider-native openai-codex-responses transport instead of treating the ChatGPT backend as a generic OpenAI endpoint.
Environment overrides
| Variable | Default | Purpose |
|---|---|---|
DSH_CODEX_AUTH_PATH | ${CODEX_HOME:-~/.codex}/auth.json | Exact Codex auth file |
DSH_CODEX_CREDENTIAL_REF | OPENAI_CODEX_ACCESS_TOKEN | DSH credential reference |
DSH_CODEX_PROVIDER_ID | openai-codex | Provider route preflighted before requests |
DSH_CODEX_REFRESH_MARGIN_MS | 300000 | Refresh margin before JWT expiry |
DSH_CODEX_SYNC_INTERVAL_MS | 600000 | Background synchronization interval |
If you override DSH_CODEX_CREDENTIAL_REF, also update apiKeyEnv in the bundle or your DSH settings.
Security notes
- Codex's
auth.jsoncontains a rotating refresh token and must remain private. - DSH's local credential provider writes the synchronized access token to
$DSH_HOME/.credentials.yaml, normally with mode0600. - The plugin never logs token values.
- A compare-before-write check avoids overwriting a newer refresh token if Codex refreshes concurrently.
Development
npm install
npm test
npm run check
License
MIT