DSH Plugins
返回列表
🧩

dsh-grok-build-auth-bridge

admin-security 更新于 2026.08.25

在终端中运行以下命令:

dsh plugin install shaomingbo/dsh-grok-build-auth-bridge

将以下提示词粘贴到 DeepSeek Harness 对话框中:

在终端中运行 dsh plugin install shaomingbo/dsh-grok-build-auth-bridge 即可安装,源码见 https://github.com/shaomingbo/dsh-grok-build-auth-bridge ,安装后需确保已登录 Grok Build CLI 并重启 dsh web。

插件介绍

The hardest part of using a Grok Build subscription inside DeepSeek Harness (DSH) is the authentication gap. Grok's refresh token, file locking, and race-safety are all sealed inside the official CLI, while DSH's credential service only understands tokens it manages itself. dsh-grok-build-auth-bridge is a thin Cordis bundle that closes that gap in three moves: read the first-party xAI OAuth session from the local auth.json, delegate the actual token refresh to the official grok binary when the short-lived access token is about to expire, and write only the access token into DSH's credential store. The bridge never reads, writes, or uploads a refresh token, and it never touches ~/.grok/auth.json.

It also auto-registers a grok-build provider route in DSH (grok-4.6, OpenAI Responses protocol, pointing at cli-chat-proxy.grok.com) and attaches the subscription-proxy headers the official client expects: X-XAI-Token-Auth, model override, client mode, and the locally installed Grok version. A background loop checks token validity every ten minutes and again right before each grok-build streaming request, triggering a refresh through the official CLI so Grok's own locked, race-safe rotation is preserved. File-permission checks (chmod 600) and credential isolation mean that even if auth.json were exposed, the leaked access token would expire within minutes.

This plugin is aimed at developers who already route multiple LLM providers through DSH and hold a Grok Build subscription. There is no separate proxy to deploy and no token to copy by hand: once the plugin is installed and the CLI is logged in, Grok models appear alongside your existing providers in DSH's model list, ready for both chat and agentic workloads.

使用场景

  • 在 DSH 中直接调用 Grok Build 订阅模型,无需手动复制令牌
  • 多模型服务商环境下统一接入 Grok 4.6,与其他供应商并列使用
  • 自动完成令牌刷新与代理头注入,免部署独立代理服务

适合人员

  • 已持有 Grok Build 订阅的开发者
  • 在 DSH 中管理多模型服务商的工程师
  • 希望减少手动凭证维护的 AI 应用开发者