accpowered/dsh-credential-manager ↗★ 1
dsh-credential-manager
为Harness提供命名用户凭据:模型工具、密钥隔离、环境变量与设置页。 适合需集中管理模型可用凭据的用户;提供工具与设置界面,安装需允许构建。
安装
$
npx -p @deepseek-ai/dsh dsh plugin --profile web add github:accpowered/dsh-credential-manager说明文档
阅读完整 README ↗Configuration
Both host rows work with zero configuration; every knob carries a schema default. To tune, restate the row in your profile's cordis.patch.yml (a patch replaces the row's whole config):
- id: credential-manager
name: dsh-credential-manager
config:
maxNoteBytes: 8192 # UTF-8 byte cap for one user/LLM note field
- id: tool-credential-manager
name: dsh-credential-manager/tools
config:
promptOrder: 116 # ordering weight of the system-prompt policy section
To mount only the service and the settings page (no model-facing tools), delete the tool-credential-manager row from the bundle patch.
Usage
- In a conversation, when the model needs a credential it calls
credential_createwith a name only (never a value) and asks you to fill it in. - Open Settings → Credentials, find the placeholder, and enter the secret value (write-only; it is never read back into any page or transcript).
- The model uses the value through the listed
DSH_CM_variable inbash/pwshcommands:curl -H "Authorization: Bearer $DSH_CM_MYAPI" .... credential_readexists as a deliberate last-resort escape hatch for non-shell use; the harness instructs the model to prefer the variable path.
Expired credentials keep working (the expiry day is informational) but are flagged in the page and in credential_list so the model can tell you to rotate them.