accpowered/dsh-credential-manager ↗★ 1

dsh-credential-manager

为Harness提供命名用户凭据:模型工具、密钥隔离、环境变量与设置页。 适合需集中管理模型可用凭据的用户;提供工具与设置界面,安装需允许构建。

包名
dsh-credential-manager
兼容性
待验证
Harness 依赖范围
^0.0.1-rc.1
Cordis 依赖范围
^4.0.1
版本
0.1.0
许可证
MIT
最近更新
2026年8月20日

安装

$npx -p @deepseek-ai/dsh dsh plugin --profile web add github:accpowered/dsh-credential-manager

Configuration

Both host rows work with zero configuration; every knob carries a schema default. To tune, restate the row in your profile's cordis.patch.yml (a patch replaces the row's whole config):

- id: credential-manager
  name: dsh-credential-manager
  config:
    maxNoteBytes: 8192        # UTF-8 byte cap for one user/LLM note field

- id: tool-credential-manager
  name: dsh-credential-manager/tools
  config:
    promptOrder: 116          # ordering weight of the system-prompt policy section

To mount only the service and the settings page (no model-facing tools), delete the tool-credential-manager row from the bundle patch.

Usage

  1. In a conversation, when the model needs a credential it calls credential_create with a name only (never a value) and asks you to fill it in.
  2. Open Settings → Credentials, find the placeholder, and enter the secret value (write-only; it is never read back into any page or transcript).
  3. The model uses the value through the listed DSH_CM_ variable in bash/pwsh commands: curl -H "Authorization: Bearer $DSH_CM_MYAPI" ....
  4. credential_read exists as a deliberate last-resort escape hatch for non-shell use; the harness instructs the model to prefer the variable path.

Expired credentials keep working (the expiry day is informational) but are flagged in the page and in credential_list so the model can tell you to rotate them.