zmh2000829/dsh-x-connect0

dsh-x-connect

X (Twitter) connector for DeepSeek Harness: OAuth 2.0 credential binding, posting tweets with per-post cost estimation, and reading/summarizing related posts. Ships a settings card in the Web plugin page.

包名
dsh-x-connect
版本
0.1.0
许可证
MIT
最近更新
2026年8月25日

安装

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:zmh2000829/dsh-x-connect

dsh-x-connect

简体中文

An X API v2 connector for DeepSeek Harness. It binds one X account through OAuth 2.0 Authorization Code with PKCE and gives the agent tools to search, read, summarize, and publish posts.

Features

  • Configure and bind an account in Settings → Plugins → X Connect.
  • Test the saved account connection from the settings card.
  • Search recent posts, read a post or a user's timeline, and return structured content for the active DSH model to summarize.
  • Publish posts and replies only after DSH asks the user for one-time approval by default.
  • Refresh OAuth tokens locally and keep an action/cost audit log.
  • Never sends an OAuth client secret: X public-client PKCE needs only a Client ID.

Install

dsh plugin --profile web add dsh-x-connect

Restart dsh web, then open Settings → Plugins → X Connect. For local development, pass the repository's absolute path instead of the package name.

X application setup

  1. Create a project and app in the X Developer Console.
  2. Enable OAuth 2.0 and configure a public/native client with Authorization Code + PKCE.
  3. Register http://127.0.0.1:56130/callback as a callback URI, or enter another loopback HTTP URI with an explicit port in both X and the plugin.
  4. In DSH settings, enter the OAuth 2.0 Client ID and save.
  5. Keep tweet.read, users.read, and offline.access; enable tweet.write for publishing.
  6. Select Generate authorization link, authorize in X, return to DSH, and select Test connection.

The callback listener starts only while an authorization is pending. It is not a permanent web service and is not exposed beyond the local loopback interface.

Agent tools

ToolCapability
x_statusAccount, scopes, callback and estimated usage status
x_connect / x_disconnectBind or remove the local OAuth credential
x_meRead the bound account profile
x_searchSearch recent X posts
x_user_tweetsRead recent posts from an account
x_tweetRead one post by ID or URL
x_postPublish a post or reply after user approval
x_activity_logInspect or, after approval, clear local activity

“Summarize” is intentionally not a second paid LLM integration: read/search tools return the source posts to the DSH model already handling the conversation.

Billing and safety

X API access is pay-per-use and account limits can change. The plugin displays estimates using the documented rates current at release, but the X Developer Console is authoritative. Search/read/post calls may consume credits even when their results are later summarized.

Credentials are written to ~/.dsh/x-connect/credentials.json with mode 0600; they are never returned to the browser card or model. Publishing, model-triggered disconnects, and log deletion use DSH's approval surface and fail closed if no interactive approver is available.

Development

npm ci
npm run check
npm pack --dry-run

See SECURITY.md and CHANGELOG.md.

License

MIT