irisnb/dsh-credentials-keyring2

dsh-credentials-keyring

OS-keychain credentials provider (Windows Credential Manager / macOS Keychain / Linux Secret Service) for the DeepSeek Harness credential seam

AI Analysis

核心用途是将 DSH 的敏感凭据(如 API Key)安全地存储在操作系统的钥匙串中。适合对本地凭据存储安全性有较高要求的 DSH 用户。

Package
dsh-credentials-keyring
Version
0.1.0
License
MIT
Last updated
Aug 16, 2026

Install

This plugin has no verified bundle, or compatibility checks failed. Read the repository notes first. Read the full README ↗

Usage

The provider implements CredentialProvider, so it plugs into the credentials seam and stores one value per credential reference (a POSIX identifier such as DEEPSEEK_API_KEY).

import { Context } from '@deepseek-ai/cordis'
import { KeyringCredentialProvider } from 'dsh-credentials-keyring'

const ctx = new Context()
await ctx.plugin(KeyringCredentialProvider, { service: 'com.your-app.desktop' })

// Consumers then resolve through the seam as usual:
const hit = await ctx.credentials.resolve(credentialRef('DEEPSEEK_API_KEY'))
// { value: 'sk-…', source: 'keyring' } | undefined

Config

FieldDefaultMeaning
servicecom.deepseek.dshKeychain service namespace. Set it to your app's identifier so your secrets never collide with another app's.

Every other value lives in the keychain under (service, account), where account is the credential reference.

Semantics

  • resolve(ref){ value, source: 'keyring' } when stored, undefined when absent or empty.
  • describe(ref){ configured, source?, writable }never the value.
  • set(ref, value) → stores; rejects an empty value (use unset).
  • unset(ref) → deletes; deleting an absent entry is a no-op.
  • set / unset emit credentials/updated after committing, like every provider.