macOS Keychain credential provider that replaces the local-file provider and uses a signed, notarized universal helper.
Install
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:fieldnote-ops/keyringseam
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
KeyringSeam is an independently maintained macOS credential provider for the DeepSeek Harness ctx.credentials seam. The 0.2.0-rc.1 candidate replaces the legacy file-Keychain helper with a Developer ID-signed, notarized Broker app that stores managed values in a private Data Protection Keychain access group and asks for explicit device-owner authentication before get, set, or unset.
Release status:
v0.2.0-rc.1is a public release candidate. Local Agent-isolation acceptance, DSH consumer boot, Apple notarization, stapling, Gatekeeper, quarantined native/Intel launches, and public archive hash verification have passed. The 3-machine/24-hour external acceptance round is intentionally deferred; independent security review and independent-user adoption are not claimed. The published v0.1.3 tag remains the legacy storage-only release and must not be described as Agent isolation.
KeyringSeam is an independent, AI-assisted open-source project by FIELD NOTE. It is not affiliated with, sponsored by, or endorsed by DeepSeek or Apple. DeepSeek Harness is named only to describe compatibility; macOS and Keychain are Apple trademarks.
Proof at a glance
| Surface | Verified behavior |
|---|---|
| Broker boundary | Persistent stdin/stdout framing, empty child environment, no secret-bearing argv, bounded requests/responses, serialized operations, and lifecycle disposal. |
| Keychain policy | Private exact access group TU8DF2JWHF.org.fieldnote.keyringseam.broker, Data Protection Keychain, device-only item protection, and explicit device-owner authentication for every secret-bearing operation. |
| Same-user attacks | Independent Security.framework reader returns errSecMissingEntitlement (-34018); /usr/bin/security cannot find the item; a copied raw Broker is rejected; canceled direct invocation returns -128 with no value. |
| Binary provenance | Universal arm64 + x86_64 Developer ID Application signature, Hardened Runtime, secure timestamp, embedded profile, accepted Apple notarization 8941cae5-75a5-4f1c-bdfb-998d1ce578c3, staple, Gatekeeper, and quarantine launch checks. |
| Harness integration | Isolated DSH 0.1.0-rc.6 plugin add, composed profile replacement, Web boot HTTP 200, and a DSH bash-tool attempt that failed closed without returning a value. |
Independent security review and independent-user adoption are not claimed.
Install the public release candidate
dsh is not a system-global command. Install the pinned preview CLI and pnpm in the environment where you will run Harness:
npm install --global pnpm @deepseek-ai/dsh@0.1.0-rc.6
dsh --version
pnpm --version
Install the pinned public release candidate. Use a disposable credential for the first run and review the generated profile diff before using a production credential:
dsh plugin --profile web add github:fieldnote-ops/keyringseam#v0.2.0-rc.1
The previous v0.1.3 command remains available for rollback and is explicitly legacy storage-only:
dsh plugin --profile web add github:fieldnote-ops/keyringseam#v0.1.3
Security design
- The provider launches one fixed, signed Broker app per provider lifetime over anonymous pipes. It passes no host environment and no command-line arguments to the Broker.
- Every
get,set, andunsetperforms an explicit device-owner authentication. Cancellation, timeout, missing entitlements, invalid signatures, locked Keychain, malformed frames, and native failure return errors; there is no plaintext or legacy-helper fallback. - The Broker targets macOS 13 or newer and contains Apple Silicon and Intel slices. Consumer machines do not need Swift, Xcode, or Apple command-line developer tools at runtime.
- Environment values remain read-only and highest priority. Project and user
.envfallbacks remain below the managed Keychain source. - A user who approves an unexpected authentication prompt, a compromised macOS account, debugger access to the trusted Harness host, and the trusted host itself remain outside the boundary.
Maintainer verification
npm ci
npm run check
node scripts/broker-architecture-smoke.mjs native
node scripts/broker-architecture-smoke.mjs x86_64
Building a new Broker requires the exact Developer ID identity and the approved provisioning profile:
KEYRINGSEAM_SIGN_IDENTITY='Developer ID Application: Legal Name (TEAMID)' \
KEYRINGSEAM_PROVISIONING_PROFILE='/absolute/path/to/profile.provisionprofile' \
npm run build:broker
The signed app is notarized with the locally stored keyringseam-notary profile through scripts/notarize-broker.sh. Never bypass secure timestamps or staple validation.
See Agent isolation design and SECURITY.md for the threat model, acceptance boundary, migration policy, and evidence limits.
Links
More in this category
V1ki/dsh-plugin-subscriptions★ 399
Use ChatGPT (Codex), Claude, and Grok subscriptions as DeepSeek Harness LLM providers, with Settings login, model catalogs, usage, plus image_generate, video_generate, and x_search tools.
Mars-Sea/dsh-commandcode-provider★ 341
Unofficial Command Code LLM provider: registers a `commandcode` route with a live model catalog and reasoning-effort support.
corrinehu/dsh-workbuddy-connect★ 222
Brings the models in the WorkBuddy desktop app straight into DeepSeek Harness — zero configuration in the DSH chat.
cv-superding/dsh-deepseek-web-login★ 178
Adds a deepseek-web provider that uses chat.deepseek.com web models in DSH, with browser login capture, PoW request signing, SSE streaming, and prompting-based tool calls.
volcengine/ark-cli#ark-plan-api★ 139
Registers Ark Agent Plan, Coding Plan and postpaid model routes in the native DSH model picker.
franksong2702/dsh-codex-connect★ 125
Connect ChatGPT OAuth and OpenAI Codex models to DeepSeek Harness, with opt-in search and image tools.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.