f4ah6o/dsh-SIWC--packages-chatgpt ↗★ 0

@f12o/dsh-siwc

ChatGPT subscription inference through OpenAI Sign in with ChatGPT for DeepSeek Harness 通过本地浏览器登录共享ChatGPT订阅额度,适合已有订阅且不想用API Key的用户。

패키지
@f12o/dsh-siwc
호환성
미검증
Harness peer 범위
0.2.0-rc.2 || 0.2.1-alpha.1
Cordis peer 범위
~4.0.4 || ~4.0.5-alpha.1
버전
0.1.0-alpha.2
최근 업데이트
2026. 10. 9.

설치

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:f4ah6o/dsh-SIWC#47d50d240345e4b2853b5433aaefd06f2b9f3e68&path:packages/chatgpt

description: "Add local ChatGPT subscription inference and account controls to DeepSeek Harness profiles." kind: "package-bundle"

@f12o/dsh-siwc

English | 日本語 | 中文

Summary

Add ChatGPT subscription models to a DeepSeek Harness profile without a separate API key. Sign in through OpenAI in a browser on the same PC; the Host keeps account grants in the DSH Credentials store, while Web and Desktop show redacted account controls. Base-backed profiles already provide the required services.

Table of Contents


Use this package

Install from npm

After npm publishes prerelease version 0.1.0-alpha.2, add the bundle to every profile that will use ChatGPT:

dsh plugin --profile web add @f12o/dsh-siwc@0.1.0-alpha.2
dsh plugin --profile headless add @f12o/dsh-siwc@0.1.0-alpha.2
dsh plugin --profile desktop add @f12o/dsh-siwc@0.1.0-alpha.2

For Desktop CLI installs, launch the application once to create its profile, then fully quit it before running package commands. Use that release's bundled dsh CLI, not a different dsh on PATH. The current fork places its CLI at resources/runtime/cli/bin/dsh (dsh.cmd on Windows); confirm the path for your installed release. You can also use Desktop's Plugin Manager after profile setup. Reopen Desktop after CLI package operations.

If a profile already has the former @f4ah6o/dsh-chatgpt package, remove it from that same profile before adding this package:

dsh plugin --profile 
 remove @f4ah6o/dsh-chatgpt
dsh plugin --profile 
 add @f12o/dsh-siwc@0.1.0-alpha.2

The former and current package names use the same provider identity, Remote namespace, and credential IDs. Keep the same $DSH_HOME to preserve the credential store; a valid saved grant remains usable without signing in again, while an expired or revoked grant may require sign-in. For Desktop, use its bundled CLI with Desktop closed for both commands.

Install a local Pack

To install from a checkout, pack the standalone plugin and add its tarball to a profile:

pnpm --dir packages/chatgpt pack
dsh plugin --profile web add /path/to/deepseek-harness-plugin/packages/chatgpt/f12o-dsh-siwc-0.1.0-alpha.2.tgz
dsh plugin --profile headless add /path/to/deepseek-harness-plugin/packages/chatgpt/f12o-dsh-siwc-0.1.0-alpha.2.tgz
dsh plugin --profile desktop add /path/to/deepseek-harness-plugin/packages/chatgpt/f12o-dsh-siwc-0.1.0-alpha.2.tgz

The bundle inserts the ChatGPT plugin row; remove it with dsh plugin --profile remove @f12o/dsh-siwc. Its Host APIs were tested with DSH 0.2.0-rc.2 and 0.2.1-alpha.1; other DSH API versions are not covered.

The Host needs DSH Credentials, Authorization, and LLM services. The shipped web, desktop, headless, and sdk profiles include them through dsh-base. The bundle also inserts a startup check. When the DSH launcher signals readiness, the check reports missing services for an enabled ChatGPT Host row and aborts startup; it skips a disabled or deleted Host row. The standalone sdk-minimal profile omits Credentials and Authorization. Add matching provider packages to that profile, then add their rows to its cordis.patch.yml:

pnpm --dir "${DSH_HOME:-$HOME/.dsh}/profiles/sdk-minimal" add @deepseek-ai/dsh-authorization@0.2.0-rc.2 @deepseek-ai/dsh-credentials-local@0.2.0-rc.2

Use 0.2.1-alpha.1 for both packages when the DSH installation is 0.2.1-alpha.1; do not mix the two DSH API lines. Add these rows after installing the ChatGPT bundle:

- insert:
    - id: authorization
      name: '@deepseek-ai/dsh-authorization'
    - id: credentials
      name: '@deepseek-ai/dsh-credentials-local'

The bundle does not replace provider rows in base-backed profiles.

Sign in on the local machine

Web and Desktop users can open Settings → ChatGPT, add one or more accounts, and choose which account the profile uses. The OAuth callback listens only on loopback at 127.0.0.1; complete sign-in in a browser on the same PC. Remote-hosted browsers and cloud sign-in are unsupported. The Host persists a stable urn:uuid: identifier and reuses it for sign-in. The flow uses OpenAI’s Sign in with ChatGPT registration and does not require a Codex CLI installation.

The OAuth request asks for openid, profile, email, offline_access, resource.invoke, and chatgpt.tokens.use.direct. If a new registration verifies the ChatGPT identity but does not grant every required permission or a renewable token, the Host retains only its issued client ID and verified subject/email as needs-sign-in; it stores no token and does not expose models. An incomplete reauthorization leaves the previous connected grant intact. Registrations are distinct by issued client ID and verified subject, not by email.

For a CLI-only run, set authorizeOnStart in an invocation overlay. The profile prints a one-time URL and waits for the local loopback callback before continuing:

cat > /tmp/chatgpt-login.patch.yml 
Implementation details — click to expand

The bundle mounts a Host OAuth/account service, a profile-startup check, a typed Remote namespace, and a lazy Client factory. The Host owns loopback callbacks, dynamic registration identity, serialized token refresh, model catalog admission, and the OpenAI Responses adapter. The check uses the DSH launcher's readiness signal and public Loader entries to validate only an enabled ChatGPT Host row. Remote values contain account status, catalog metadata, and sanitized login progress only. A request pins one account, access token, model configuration, and timeout before it enters the Responses stream.

OpenAI receives the current request’s instructions, conversation messages, image inputs, and function schemas. Requests use `store: false` and stream the full conversation. The package does not upload Session export files; model inference still sends the current request contents to OpenAI and is separate from DSH's session-log upload setting.

-----

## Further Exploration

- [OpenAI SIWC sign-in](https://developers.openai.com/siwc/token-sharing-open-source/sign-in) — dynamic client registration, browser authorization, and callbacks.
- [OpenAI SIWC models and inference](https://developers.openai.com/siwc/token-sharing-open-source/models-and-inference) — catalog and Responses requests.
- [OpenAI SIWC limitations](https://developers.openai.com/siwc/token-sharing-open-source/preview-limitations) — preview-only API restrictions.

-----

## Model Experience

### ChatGPT subscription request

#### What the model sees

The adapter sends the system instructions as the Responses `instructions` field, maps the complete DSH message history into Responses input, includes selected image bytes, and supplies function definitions through the supported `additional_tools` developer item. OpenAI receives these request contents for inference.

#### Token effect

Conversation history, image inputs, function schemas, and tool results contribute to each request. The seeded context window is 1,050,000 tokens. DSH `maxTokens` options are rejected for ordinary generation, as are `temperature` and `stop`; session-title and compaction calls omit `max_output_tokens`, so the DSH title limit of 64 and compaction limit of 65,536 are not guaranteed by this adapter.

#### KV Cache effect

OpenAI receives the full request history on each call; the adapter does not send `previous_response_id`. Responses use `store: false` and explicitly request encrypted reasoning content. The adapter builds local replay history from SDK-replayable `response.output_item.done` events ordered by output index, falling back to terminal `response.output` only when no item-complete events arrived. If a response contains an item the installed SDK cannot replay, the request fails with a diagnostic containing only item type names.

## Known Limitations

- **Local browser required for sign-in** — the OAuth redirect must reach a callback on the same PC. Saved grants can serve later local headless and SDK requests.
- **Responses API parameters are restricted** — ordinary `maxTokens`, `temperature`, and `stop` are unsupported. Auxiliary title and compaction output caps are omitted, not enforced.
- **Model metadata can lag OpenAI’s catalog** — new slugs need a positive `contextWindow` override before the provider exposes them to inference. The account catalog still controls availability and order.
- **Plan limits are account-owned** — when OpenAI rejects inference at the plan limit, use the **Manage usage** action to open [ChatGPT usage settings](https://chatgpt.com/settings/usage).
- **Same-home sign-out is shared** — profiles using one `$DSH_HOME` share account grants; signing out in one removes the saved tokens for all of them.
- **Windows Desktop is unverified** — this prerelease has not been tested with Windows Desktop. A prior attempt with official DSH `0.2.0-rc.2` reported an `authenticatedUrl` startup error after plugin installation, but did not identify the installed plugin artifact. That report does not establish whether this prerelease is affected.