irisnb/dsh-credentials-keyring2

dsh-credentials-keyring

OS-keychain credentials provider (Windows Credential Manager / macOS Keychain / Linux Secret Service) for the DeepSeek Harness credential seam

AI 分析

核心用途是将 DSH 的敏感凭据(如 API Key)安全地存储在操作系统的钥匙串中。适合对本地凭据存储安全性有较高要求的 DSH 用户。

パッケージ
dsh-credentials-keyring
バージョン
0.1.0
ライセンス
MIT
最終更新
2026/08/16

インストール

検証済み bundle がないか、互換性チェックに失敗しています。先にリポジトリの説明を読んでください。 README 全文を読む ↗

ドキュメント

README 全文を読む ↗

Usage

The provider implements CredentialProvider, so it plugs into the credentials seam and stores one value per credential reference (a POSIX identifier such as DEEPSEEK_API_KEY).

import { Context } from '@deepseek-ai/cordis'
import { KeyringCredentialProvider } from 'dsh-credentials-keyring'

const ctx = new Context()
await ctx.plugin(KeyringCredentialProvider, { service: 'com.your-app.desktop' })

// Consumers then resolve through the seam as usual:
const hit = await ctx.credentials.resolve(credentialRef('DEEPSEEK_API_KEY'))
// { value: 'sk-…', source: 'keyring' } | undefined

Config

FieldDefaultMeaning
servicecom.deepseek.dshKeychain service namespace. Set it to your app's identifier so your secrets never collide with another app's.

Every other value lives in the keychain under (service, account), where account is the credential reference.

Semantics

  • resolve(ref){ value, source: 'keyring' } when stored, undefined when absent or empty.
  • describe(ref){ configured, source?, writable }never the value.
  • set(ref, value) → stores; rejects an empty value (use unset).
  • unset(ref) → deletes; deleting an absent entry is a no-op.
  • set / unset emit credentials/updated after committing, like every provider.