pi-ai's auth model reaches this adapter through three translations, all of which live here: a CredentialStore over the harness credential records, an AuthContext over the credential plane and the host filesystem, and one authorization flow per installed provider that ships a login. The seams they consume name nothing from pi-ai, so a second adapter family can arrive with a different auth model and share them. Every collection is now built with the store and the context rather than with nothing, which is what makes a signed-in provider stay signed in across the collection rebuild a configuration change causes. With a posture that works, the configurable-provider directory no longer withholds OAuth-only routes and `openai-codex` is offered again; the predicate that withheld it is gone. The credential plane stays optional. Reads answer "nothing stored" without a credentials service because such a composition genuinely holds no credential, while writes refuse by name — a login whose grant evaporated would report success and then fail every request. Flow registration is scoped to the authorization seam, so a headless or ACP composition mounts with no sign-in and everything else unchanged. Two fixes found while wiring this up: pre-release credential fixtures in the llm suites still used the flat document the record work replaced, and a flow that ignores its cancellation signal would have held its key for the life of the process — withdrawal now settles the attempt either way.
DeepSeek Harness
English | 中文
DeepSeek Harness (dsh) is an open-source agent harness developed by DeepSeek AI.
It uses an architecture where everything is a plugin, and is powered by Cordis, whose design is described in A Programming Paradigm for Spatiotemporal Composability.
Developer preview
DeepSeek Harness is currently in developer preview and is iterating rapidly. THERE WILL BE COMPATIBILITY-BREAKING CHANGES.
Run
Run from npm
Install Node.js, then run:
npx @deepseek-ai/dsh web
The command starts the Web UI at http://127.0.0.1:3080 by default and opens it in the default browser for a local launch. An SSH launch only prints the host URL because the SSH client or editor owns the local forwarded address. Pass --no-open to run the server without opening a browser. See Web UI guide.
Run from source
To run from a repository checkout:
git clone https://github.com/deepseek-ai/deepseek-harness.git
cd deepseek-harness
pnpm install
pnpm run build
pnpm dsh web
pnpm run build prepares the repository artifacts. pnpm dsh web uses those built artifacts without rebuilding.
Community and support
- Feel free to submit feedback or bug reports through GitHub Discussions.
- Add the
dsh-plugintopic to your plugin repository for discoverability. - Join DeepSeek Harness Discord community.
Contributing
See CONTRIBUTING.md.
Development
Start with the development guide and architecture documentation.
For agents, follow AGENTS.md.
License
Third-party dependencies and their licenses are disclosed in THIRD_PARTY_NOTICES.md.