Skip to content

dsh-gatemux-login

Verified

@gatemux/dsh-gatemux-login · v1.0.4 · MIT

Sign in with GateMux for DeepSeek Harness: users pay from their own GateMux balance.

Install

dsh plugin add @gatemux/dsh-gatemux-login

Confirm the layer applied with dsh --profile default --dump-config — see the install guide.

Source

Published to npm without a public repository. Inspect the package contents before installing.

Creators

Readme

GateMux Sign-In for DeepSeek Harness

Sign in to the DeepSeek Harness desktop app with your own GateMux account. Model requests are then billed to your GateMux balance instead of to the application's server key.

What this plugin does

It is a DeepSeek Harness bundle. Installing it changes three things about the composed profile:

  • Adds a GateMux account service that signs you in through GateMux's OAuth 2.0 redirect flow (authorization code with PKCE S256).
  • Registers a model route, provider id gatemux-account, that authenticates every request with your own credential and advertises the models the endpoint reports it serves.
  • Turns off the shipped vendor account route (deepseek-account and llm-deepseek-account) so there is one account provider instead of two.

It also sets the default model to gatemux/deepseek-v4-flash. See Changing the default model if you would rather keep another default.

Requirements

  • DeepSeek Harness desktop app, 0.1.7.x or 0.2.x. The plugin declares @deepseek-ai/dsh-* peer dependencies across both lines. A different DSH release is rejected at install time; installing anyway needs a version exemption, which risks crashes and data loss.
  • A GateMux account.

No install scripts are run: installation does not execute any build step, and the app never asks you to approve package scripts for this plugin.

Install

In the desktop app:

  1. Open 插件 (Plugins) in the left sidebar.
  2. Click 添加插件 (Add plugin).
  3. Enter @gatemux/dsh-gatemux-login and click 安装 (Install).
  4. When it reports 已安装 (Installed), click 立即启用 (Enable now).
  5. Restart the app. The desktop profile is a startup profile, so the new bundle is composed at launch, not applied live.

The plugin manager writes the dependency and adds the bundle to the profile's dsh.profile.bundles itself. You do not edit any configuration by hand.

From the CLI, for a non-desktop profile:

dsh plugin --profile <name> add @gatemux/dsh-gatemux-login

The desktop profile is managed exclusively by the Electron application and cannot be installed into from the CLI.

Sign in

Send a message. Until you are signed in, the GateMux route reports:

ACCOUNT_SIGN_IN_REQUIRED: Sign in with GateMux to use the GateMux model route.
Model requests are billed to your own GateMux balance.

Sign in from the app's account settings. Authorization opens in your browser and returns to the app. The tab itself is left on a confirmation page — GateMux serves no hosted completion page, so there is nothing else to show there — and it never auto-closes; you can close it once the app is signed in.

Models

Once you are signed in, the route reads what the endpoint serves from https://rest.gatemux.ai/v1/models and advertises every entry whose protocols include anthropic-messages. An entry served over any other protocol is left out, because every request this route makes speaks the Messages protocol: a model that speaks only openai-completions would fail on every request, so offering it in the model selector would be offering a choice that cannot work.

Context window, output cap, display name, and image input come from the listing.

Fallback catalog

The bundle's patch layer also declares two models, which the route advertises before you sign in and keeps when a listing read fails:

Model id Context Input
gatemux/deepseek-v4-flash 1,000,000 text, image
gatemux/deepseek-v4-pro 1,000,000 text

A failed read is logged as a warning and leaves the last catalog that was read successfully in force, so a listing outage never empties the model selector or drops the provider from it. Before the first successful read, the declared catalog above is what the route advertises.

For a model the endpoint also lists, every field the declaration states wins and the endpoint fills the rest. gatemux/deepseek-v4-flash therefore keeps the declared 1,000,000-token context window and image input while taking its output cap from the endpoint. A declared model the endpoint does not list is still advertised.

Changing the default model

The bundle sets the default model in its own patch layer. A profile's own cordis.patch.yml is applied after every bundle layer, so it wins. Selecting another model in the app writes exactly that override for you; to set it by hand, add to $DSH_HOME/profiles/<name>/cordis.patch.yml:

- id: agent-default-model
  name: "@deepseek-ai/dsh-agent-default-model"
  config:
    provider: some-other-provider
    model: some-other-model
    reasoningEffort: high

A patch name is a guard, not a rename: it must match the addressed row's current module or the patch is skipped.

Troubleshooting

What you see Meaning
ACCOUNT_SIGN_IN_REQUIRED No credential yet. Sign in.
ACCOUNT_TOKEN_INVALID The credential was revoked, expired, or suspended. It has been discarded; sign in again.
ACCOUNT_QUOTA_EXCEEDED Your GateMux balance or spend cap is exhausted. Top up.
ip_not_allowed (HTTP 403) Your network is not in the GateMux application's trusted egress IP allowlist. Contact the plugin operator. Re-authorizing will not fix it.
scope_denied, model_not_allowed (HTTP 403) The application registration does not permit this request. Contact the plugin operator.
Install refused for peer dependencies Your DSH version is outside 0.1.7.x and 0.2.x.

403 errors are reported as authorization faults, not retried: they are configuration problems on the application's side.

Credentials and privacy

Your GateMux credential is stored locally at $DSH_HOME/.credentials.yaml under the key gatemux/account, with file mode 0600. It never leaves your machine except as the Authorization: Bearer header on requests to https://rest.gatemux.ai.

Refresh tokens rotate on every refresh, and the rotated value is persisted immediately; a reused rotated refresh token is treated as credential leakage. If a token exchange returns invalid_grant, that authorization code is voided on the server and is not retried.

License

MIT