dsh-gatemux-login
Verified@gatemux/dsh-gatemux-login · v1.0.4 · MIT
Sign in with GateMux for DeepSeek Harness: users pay from their own GateMux balance.
Install
dsh plugin add @gatemux/dsh-gatemux-login Confirm the layer applied with dsh --profile default --dump-config — see the install guide.
Source
Published to npm without a public repository. Inspect the package contents before installing.
Creators
Readme
GateMux Sign-In for DeepSeek Harness
Sign in to the DeepSeek Harness desktop app with your own GateMux account. Model requests are then billed to your GateMux balance instead of to the application's server key.
What this plugin does
It is a DeepSeek Harness bundle. Installing it changes three things about the composed profile:
- Adds a GateMux account service that signs you in through GateMux's OAuth 2.0
redirect flow (authorization code with PKCE
S256). - Registers a model route, provider id
gatemux-account, that authenticates every request with your own credential and advertises the models the endpoint reports it serves. - Turns off the shipped vendor account route (
deepseek-accountandllm-deepseek-account) so there is one account provider instead of two.
It also sets the default model to gatemux/deepseek-v4-flash. See
Changing the default model if you would rather
keep another default.
Requirements
- DeepSeek Harness desktop app,
0.1.7.xor0.2.x. The plugin declares@deepseek-ai/dsh-*peer dependencies across both lines. A different DSH release is rejected at install time; installing anyway needs a version exemption, which risks crashes and data loss. - A GateMux account.
No install scripts are run: installation does not execute any build step, and the app never asks you to approve package scripts for this plugin.
Install
In the desktop app:
- Open 插件 (Plugins) in the left sidebar.
- Click 添加插件 (Add plugin).
- Enter
@gatemux/dsh-gatemux-loginand click 安装 (Install). - When it reports 已安装 (Installed), click 立即启用 (Enable now).
- Restart the app. The desktop profile is a startup profile, so the new bundle is composed at launch, not applied live.
The plugin manager writes the dependency and adds the bundle to the profile's
dsh.profile.bundles itself. You do not edit any configuration by hand.
From the CLI, for a non-desktop profile:
dsh plugin --profile <name> add @gatemux/dsh-gatemux-login
The desktop profile is managed exclusively by the Electron application and
cannot be installed into from the CLI.
Sign in
Send a message. Until you are signed in, the GateMux route reports:
ACCOUNT_SIGN_IN_REQUIRED: Sign in with GateMux to use the GateMux model route.
Model requests are billed to your own GateMux balance.
Sign in from the app's account settings. Authorization opens in your browser and returns to the app. The tab itself is left on a confirmation page — GateMux serves no hosted completion page, so there is nothing else to show there — and it never auto-closes; you can close it once the app is signed in.
Models
Once you are signed in, the route reads what the endpoint serves from
https://rest.gatemux.ai/v1/models and advertises every entry whose protocols
include anthropic-messages. An entry served over any other protocol is left
out, because every request this route makes speaks the Messages protocol: a
model that speaks only openai-completions would fail on every request, so
offering it in the model selector would be offering a choice that cannot work.
Context window, output cap, display name, and image input come from the listing.
Fallback catalog
The bundle's patch layer also declares two models, which the route advertises before you sign in and keeps when a listing read fails:
| Model id | Context | Input |
|---|---|---|
gatemux/deepseek-v4-flash |
1,000,000 | text, image |
gatemux/deepseek-v4-pro |
1,000,000 | text |
A failed read is logged as a warning and leaves the last catalog that was read successfully in force, so a listing outage never empties the model selector or drops the provider from it. Before the first successful read, the declared catalog above is what the route advertises.
For a model the endpoint also lists, every field the declaration states wins and
the endpoint fills the rest. gatemux/deepseek-v4-flash therefore keeps the
declared 1,000,000-token context window and image input while taking its output
cap from the endpoint. A declared model the endpoint does not list is still
advertised.
Changing the default model
The bundle sets the default model in its own patch layer. A profile's own
cordis.patch.yml is applied after every bundle layer, so it wins. Selecting
another model in the app writes exactly that override for you; to set it by hand,
add to $DSH_HOME/profiles/<name>/cordis.patch.yml:
- id: agent-default-model
name: "@deepseek-ai/dsh-agent-default-model"
config:
provider: some-other-provider
model: some-other-model
reasoningEffort: high
A patch name is a guard, not a rename: it must match the addressed row's current
module or the patch is skipped.
Troubleshooting
| What you see | Meaning |
|---|---|
ACCOUNT_SIGN_IN_REQUIRED |
No credential yet. Sign in. |
ACCOUNT_TOKEN_INVALID |
The credential was revoked, expired, or suspended. It has been discarded; sign in again. |
ACCOUNT_QUOTA_EXCEEDED |
Your GateMux balance or spend cap is exhausted. Top up. |
ip_not_allowed (HTTP 403) |
Your network is not in the GateMux application's trusted egress IP allowlist. Contact the plugin operator. Re-authorizing will not fix it. |
scope_denied, model_not_allowed (HTTP 403) |
The application registration does not permit this request. Contact the plugin operator. |
| Install refused for peer dependencies | Your DSH version is outside 0.1.7.x and 0.2.x. |
403 errors are reported as authorization faults, not retried: they are configuration problems on the application's side.
Credentials and privacy
Your GateMux credential is stored locally at
$DSH_HOME/.credentials.yaml under the key gatemux/account, with file mode
0600. It never leaves your machine except as the Authorization: Bearer header
on requests to https://rest.gatemux.ai.
Refresh tokens rotate on every refresh, and the rotated value is persisted
immediately; a reused rotated refresh token is treated as credential leakage. If
a token exchange returns invalid_grant, that authorization code is voided on the
server and is not retried.
License
MIT