Model or dataset
V1ki/dsh-plugin-subscriptions avatar
V1ki/dsh-plugin-subscriptions

Five chat subscriptions, one OAuth login, and one token file

Use ChatGPT (Codex), Claude, and Grok (X Premium) subscriptions as DeepSeek Harness LLM providers — OAuth login in the web UI, no API keys

421 stars66 forksTypeScriptMIT

At a glance

What is it?
A DeepSeek Harness plugin that turns ChatGPT, Claude, Grok, GitHub Copilot and Google Antigravity subscriptions into model providers without API keys, reading live catalogs from four of them, keeping every token in a single 0600 file, and depending on provider endpoints that are not public API surfaces.
Who is it for?
Adopt this plugin if you already pay for a chat subscription and want to drive it from DeepSeek Harness without a second API bill, and if you accept that your provider access depends on endpoints the vendors do not document for third parties. Do not adopt it expecting parity across providers: Claude ships a static model catalog, Copilot exposes no usage numbers, and tool switches only reach sessions created after you save.
Can I use it commercially?
Yes. MIT is a permissive licence: you can use, modify and sell software built on it, as long as you keep its copyright and licence notices.
Is it still maintained?
Yes. The repository last received commits 9 days ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 4, 2026, and from our analysis. They are not legal advice.

Editorial analysis

OAuth in the web UI, and a device flow for Copilot

The plugin's purpose is to remove the API key from the loop. Inside DeepSeek Harness, Settings, then Subscriptions, offers per-provider login and logout, and no key is ever typed.

The login method differs per provider, and that difference is worth knowing before you start. Codex, Grok and Antigravity authenticate through browser OAuth in the dsh web UI. GitHub Copilot uses the OAuth device flow, where you enter a shown code at `github.com/login/device`, which is the flow to expect if you are on a headless machine.

Claude is the interesting case. It imports credentials from an existing Claude Code session when there is one, either from the macOS Keychain or from `~/.claude/.credentials.json`, and falls back to the same browser OAuth flow otherwise. The stated consequence is that the Claude Code CLI is not required, which means you can use a Claude subscription without installing the CLI that normally comes with it.

Only logged-in providers appear in the session model picker, and the lists refresh on login and logout rather than at a fixed interval.

Every token lands in one 0600 file

Tokens live at `~/.dsh/plugins/subscriptions/auth.json`, created with mode 0600, and they refresh automatically.

That single path is the whole security story of the plugin, and it cuts both ways. It is simple to audit, because there is one file to look at, one permission to check and one place to delete when you log out everywhere. It is also a single point of failure, because a process that can read that file can act as you against five different services until the tokens are revoked at the provider.

Nothing in the visible documentation describes an encryption scheme or a keyring integration for that file, so treat it as a credential store and keep it out of backups and synced directories.

The plugin also writes generated images under `~/.dsh/plugins/subscriptions/images/` and returns the paths, which is a second directory to consider if you are managing disk or redaction on the host.

Four catalogs are live, and Claude's is not

Each provider route is named, and the catalog source is part of the contract.

The `codex` route uses the ChatGPT Plus or Pro subscription and reads a live catalog from `chatgpt.com/backend-api/codex/models`. The `grok` route uses X Premium through xAI and reads `api.x.ai/v1/models` for chat models, taking reasoning efforts from the Grok CLI catalog at `cli-chat-proxy.grok.com/v1/models`. The `copilot` route reads `api.githubcopilot.com/models`, covering chat models on both wires with per-model vision flags and reasoning efforts. The `antigravity` route reads Antigravity's own `v1internal:fetchAvailableModels` and issues `generateContent` and `streamGenerateContent` requests with text, image, streaming reasoning and tool-call conversion.

Claude is the exception and it is stated as a static catalog updated with the plugin, listing Opus, Sonnet, Haiku and Fable. So a Claude model released tomorrow is invisible until the plugin is updated, while a Codex or Grok model released tomorrow appears on next login.

Vision-capable models declare text and image input modalities, and image content is translated to each provider's wire format before it is sent.

Worth noting about these endpoints: several of them are CLI or internal surfaces rather than documented public APIs, which is both why they carry subscription access and why they can change without notice.

Copilot's usage card is empty because Copilot has no usage endpoint

Logged-in provider cards report subscription usage per rate-limit window, which the documentation lists as the five-hour session window, the weekly window, and a per-model weekly window where the plan has one. Each shows the used percentage, a progress bar, the reset time, and a Refresh button.

Where the numbers come from differs per provider, and one provider has none.

Codex usage comes from `chatgpt.com/backend-api/wham/usage`, which also reports the plan. Claude usage comes from `api.anthropic.com/api/oauth/usage`. Grok usage comes from the Grok Build CLI proxy's `cli-chat-proxy.grok.com/v1/billing`, described as the source of the CLI's own usage panel, reporting the shared weekly pool and the subscription tier. Antigravity reports plan, credits and per-model quotas from `loadCodeAssist` and `fetchAvailableModels` when those fields are present.

Copilot exposes no usage endpoint, so its card shows no usage section at all. That is a gap you will notice if you are choosing between a Copilot subscription and a Codex one for agent work: the same interface that tells you how much of your Codex plan is left will stay blank for Copilot.

The status bar shows one provider, and its preference lives in the browser

The composer's stats row carries a subscription usage pill showing the used percentage and the reset window for the provider of the session's current model: Codex for a Codex model, Grok for a Grok model, and so on.

It shows at most one provider, and the fallback behaviour is specific. Switching to a non-subscription model keeps the most recent subscription selected in the mounted conversation view, or the pill stays hidden if there is none. That recent-model history is not persisted across page reloads, so the pill can disappear on a refresh even though you were looking at it a minute earlier.

Clicking the pill expands every logged-in provider and account, with the default account starred and the current provider listed first. Antigravity previews only the current model's windows, at most two per account, and the rest sit in a closed disclosure.

Settings, then Subscriptions, then Status-bar quota display, offers Current or most recent subscription only, which is the default, or Hidden. The scope of that preference is spelled out precisely: it is saved in the current browser, applies immediately, survives reloads and synchronises between tabs of the same origin. It does not hide usage details in Settings, change model selection, or change account routing.

Effort comes from the catalog, and one Copilot combination reroutes the wire

Models that advertise reasoning levels get an Effort selector in the same menu, covering Codex models, Grok 4.6 and 4.5, and Copilot's reasoning models. The levels and the defaults come from each provider's live catalog rather than a hardcoded list, which is why a new reasoning model appears with the right options instead of none.

The wire detail is the part that shows the plugin is doing real work. Copilot's `capabilities.supports.reasoning_effort` array is sent as `reasoning_effort` on chat completions and as `reasoning.effort` on the Responses wire, because the two endpoints name the field differently.

There is also a reroute. Models listing both Copilot endpoints, gpt-5.4 and gpt-5-mini among them, normally speak chat completions, but switch to `/responses` when a request combines function tools with an effort, because Copilot rejects that combination on the chat wire. The result is that a tool-using request with an effort set takes a different path than the same request without one, and it works.

Codex models whose catalog advertises the fast tier, which corresponds to the codex CLI's fast mode, get a Speed toggle next to the model selector, Standard or Fast, sent as `service_tier: priority` and scoped to the session. The `/fast` slash command offers the same choice as a popup, and errors with an explanation when the current model has no fast tier.

Tool switches only reach sessions created after you save

Edit model list is where per-provider behaviour is configured, and one of its consequences is the first thing to check when a tool seems missing.

Visibility, default reasoning effort and context are configured together, with shared Save and Cancel actions. Image generation, video generation and X search are separate per-provider switches, and the documentation states that those switches apply only to sessions created after saving. An open session keeps the configuration it was created with, which is a defensible design and a genuine surprise the first time.

The tools themselves are registered when the matching provider is enabled. `web_search` uses Codex's hosted web search through the host's native tool and citation UI, and it registers as one candidate behind the host's `web` seam without claiming it: with no other search provider mounted, DeepSeek Harness auto-selects it, and alongside another one you choose the winner with the host's own `web.searchProvider` setting. Turning Web search off under Codex's provider tools withdraws it and leaves the host's tool to whatever else is registered.

`x_search` returns an answer and citations from xAI's hosted X search. `image_generate` picks its backend with a provider argument, `gpt-image-2` by default through the Codex backend or `grok-imagine-image-2.0` through xAI, falling back to the other when the preferred one is logged out, and its size and quality arguments map onto Grok's aspect_ratio and quality on that path.

Maintenance facts are simple. The licence is MIT, the last push landed on 2026-10-01, and the single release is v0.9.7, titled for DeepSeek Harness 0.2 compatibility. The peer dependency ranges in package.json span release-candidate and alpha host versions up to 0.2.0-rc.2, so the host this plugin targets is itself pre-release.

Editorial conclusion

Adopt this plugin if you already pay for a chat subscription and want to drive it from DeepSeek Harness without a second API bill, and if you accept that your provider access depends on endpoints the vendors do not document for third parties. Do not adopt it expecting parity across providers: Claude ships a static model catalog, Copilot exposes no usage numbers, and tool switches only reach sessions created after you save. Protect ~/.dsh/plugins/subscriptions/auth.json first, since it holds refreshable tokens for all five accounts.

Frequently asked questions

How do I log in to ChatGPT or Grok with dsh-plugin-subscriptions?

Open Settings, then Subscriptions, in the dsh web UI, where each provider has its own login and logout and no API key is involved. Codex, Grok and Antigravity use browser OAuth; Copilot uses the GitHub device flow, where you enter the shown code at github.com/login/device.

Do I need the Claude Code CLI to use the Claude provider?

No. The plugin imports credentials from an existing Claude Code session when there is one, from the macOS Keychain or `~/.claude/.credentials.json`, and otherwise falls back to the same browser OAuth flow the other providers use.

Where are the tokens for these subscriptions stored?

In `~/.dsh/plugins/subscriptions/auth.json` with mode 0600, refreshed automatically. Generated images are written under `~/.dsh/plugins/subscriptions/images/` and their paths are returned to the conversation.

Why does the GitHub Copilot card show no usage?

Because Copilot exposes no usage endpoint. Codex, Claude, Grok and Antigravity each report per-window usage from their own endpoints, so the Copilot card has no usage section at all.

Why did a tool switch not take effect in my open session?

Tool switches apply only to sessions created after you save. Image generation, video generation and X search are configured per provider, and a session keeps the configuration it was created with, so start a new session after changing them.

Official sources

  1. Issues
  2. License: MIT
  3. README
  4. V1ki/dsh-plugin-subscriptions on GitHub
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/v1ki-dsh-plugin-subscriptions.svg)](https://hysenlabs.com/projects/v1ki-dsh-plugin-subscriptions)