accpowered/dsh-credential-manager ↗★ 1

dsh-credential-manager

Named user credentials for DeepSeek Harness: model-facing credential tools, secrets behind the ctx.credentials seam, DSH_CM_* shell variables, and a Settings → Credentials page 适合需集中管理模型可用凭据的用户;提供工具与设置界面,安装需允许构建。

パッケージ
dsh-credential-manager
互換性
未検証
Harness ピア範囲
^0.0.1-rc.1
Cordis ピア範囲
^4.0.1
バージョン
0.1.0
ライセンス
MIT
最終更新
2026/08/20

インストール

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:accpowered/dsh-credential-manager

ドキュメント

README 全文を読む ↗

Configuration

Both host rows work with zero configuration; every knob carries a schema default. To tune, restate the row in your profile's cordis.patch.yml (a patch replaces the row's whole config):

- id: credential-manager
  name: dsh-credential-manager
  config:
    maxNoteBytes: 8192        # UTF-8 byte cap for one user/LLM note field

- id: tool-credential-manager
  name: dsh-credential-manager/tools
  config:
    promptOrder: 116          # ordering weight of the system-prompt policy section

To mount only the service and the settings page (no model-facing tools), delete the tool-credential-manager row from the bundle patch.

Usage

  1. In a conversation, when the model needs a credential it calls credential_create with a name only (never a value) and asks you to fill it in.
  2. Open Settings → Credentials, find the placeholder, and enter the secret value (write-only; it is never read back into any page or transcript).
  3. The model uses the value through the listed DSH_CM_ variable in bash/pwsh commands: curl -H "Authorization: Bearer $DSH_CM_MYAPI" ....
  4. credential_read exists as a deliberate last-resort escape hatch for non-shell use; the harness instructs the model to prefer the variable path.

Expired credentials keep working (the expiry day is informational) but are flagged in the page and in credential_list so the model can tell you to rotate them.