dsh-credential-manager
Manifest validNamed user credentials the model uses by reference: values are entered on a Settings → Credentials page and injected into each shell execution as DSH_CM_* variables instead of being printed into the t
dsh-credential-manager
English | 简体中文
Named user credentials for DeepSeek Harness: let the model use your API keys, tokens, and logins by reference — secret values never enter the conversation.
One credential is one flat record holding exactly one secret value. The model creates empty placeholder records with its credential_create tool; you enter the secret value in Settings → Credentials. Every configured secret is injected into each model shell execution as a DSH_CM_<ID> environment variable, resolved per execution, so the value reaches commands without ever being printed into the transcript.
What you get
| Piece | Kind | Purpose |
|---|---|---|
credential-manager | host service plugin | Metadata sidecar (storage domain), secret values behind the ctx.credentials seam, DSH_CM_* shell-env injection |
tool-credential-manager | host tools plugin | Model-facing tools credential_list / credential_create / credential_read / credential_update_note + a system-prompt policy section |
| Settings → Credentials | web client plugin (dsh.client) | The page where you enter/manage secret values; talks to the host over a self-mounted Typert Remote namespace |
Install
From GitHub (builds on install via its prepare script; pnpm will ask you to allow the build once):
dsh plugin --profile web add github:accpowered/dsh-credential-manager
If pnpm prints an allowBuilds prompt, add the printed key under allowBuilds in the profile's pnpm-workspace.yaml and re-run the add — this is install-time code execution permission, so only allow sources you trust (pinning a commit, github:accpowered/dsh-credential-manager#<sha>, is recommended).
From a local checkout:
dsh plugin --profile web add ./dsh-credential-manager
Restart dsh web (or your profile) and hard-refresh the browser.
How it works with the harness
The bundle patch (cordis.patch.yml) inserts two host rows; the dsh.client declaration makes the web plane serve the settings page automatically:
- insert:
- id: credential-manager
name: dsh-credential-manager
- id: tool-credential-manager
name: dsh-credential-manager/tools
No harness source is modified:
- The tools register into the host tool registry, so every agent preset sees them.
- The settings page mounts its own Typert Remote contribution through the public
ctx.remote.$mountseam — noapi/remotesedit needed. - The host service is a
TypertRemoteService; the gateway discovers its@Remotemethods dynamically (SRC markers), so no code generation step is required to deploy.
Stock-upstream note: the upstream api/remotes forwarded-event allowlist does not include credential-manager/updated, so the settings page does not receive live push invalidations from other surfaces; it still converges through authoritative mutation replies and connection-reset refetches. If you run a harness that forwards the event, the page lights up live automatically.
Configuration
Both host rows work with zero configuration; every knob carries a schema default. To tune, restate the row in your profile's cordis.patch.yml (a patch replaces the row's whole config):
- id: credential-manager
name: dsh-credential-manager
config:
maxNoteBytes: 8192 # UTF-8 byte cap for one user/LLM note field
- id: tool-credential-manager
name: dsh-credential-manager/tools
config:
promptOrder: 116 # ordering weight of the system-prompt policy section
To mount only the service and the settings page (no model-facing tools), delete the tool-credential-manager row from the bundle patch.
Usage
- In a conversation, when the model needs a credential it calls
credential_createwith a name only (never a value) and asks you to fill it in. - Open Settings → Credentials, find the placeholder, and enter the secret value (write-only; it is never read back into any page or transcript).
- The model uses the value through the listed
DSH_CM_<ID>variable inbash/pwshcommands:curl -H "Authorization: Bearer $DSH_CM_MYAPI" .... credential_readexists as a deliberate last-resort escape hatch for non-shell use; the harness instructs the model to prefer the variable path.
Expired credentials keep working (the expiry day is informational) but are flagged in the page and in credential_list so the model can tell you to rotate them.
Uninstall
dsh plugin --profile web remove dsh-credential-manager
The service, tools, system-prompt section, settings page, and Remote namespace all detach with the plugin fiber. Persisted metadata rows (storages/credential_manager.json in the harness home) and stored secret values are left untouched.
Development
pnpm install
pnpm build # tsc declarations + tsdown (node lib + browser client bundle)
pnpm test # vitest: service CRUD / seam confinement / tool mapping
Layout: src/index.ts (host service, default export), src/tools.ts (tools plugin), src/types.ts + src/spec.ts (wire types + storage domain), src/client/ (settings page; remote.ts is the hand-maintained Typert Remote contribution — keep it in sync with the service's @Remote methods).
License
MIT
Comments
Loading…
Similar plugins
外接数据源的门禁、钥匙与台账:把外部数据库/资料库/文献库登记成可检索的 Model Tool,声明每条库允许怎么取数,每次取数留一条只含指纹的台账(凭据值由宿主的 credentials 服务保管)。
★ 0
dsh plugin --profile web add dsh-stashby YYfather
Secure credential vault for DeepSeek Harness: tokens never leave the host — the agent runs gh/npm/npx/node/git with the token injected in the environment. Manage from 设置 → 凭证库 / 市场 → 已安装.
★ 0
MIT
JavaScript
Aug 23, 2026
dsh plugin --profile web add @yyfather/dsh-token-vaultby weibaohui
dsh 插件 · 用户管理:dsh web 登录门禁 + 用户/角色/登录记录/访问记录管理,首个注册者即管理员
★ 1
NOASSERTION
JavaScript
Sep 12, 2026
dsh plugin --profile web add @weibaohui/user-managementby highland0971
Native per-workspace memory on the harness's own seams: facts and a bounded always-on profile on the storage-domain JSON unit, approval-gated writes with `(sessionId, seq)` citations, deterministic re
★ 2
↓ 371/wk
MIT
TypeScript
Oct 1, 2026
dsh plugin --profile web add dsh-native-memoryby sutimee
DSH 命令隔离插件:让agent只能间接使用命令工具,插件内置三种审计方式,防止模型幻觉输错字符,但是命令工具却执行造成严重后果。
★ 0
MIT
JavaScript
Aug 15, 2026
dsh plugin --profile web add @sutang/dsh-command-quarantineby CDeZT
Native DSH foundation bundle that registers a persistent default workspace, provides paged read-only inspection of plugins, skills, memory, sessions, storage, settings, credentials, and DSH_HOME files
★ 0
MIT
JavaScript
Sep 2, 2026
dsh plugin --profile web add better-basicfun