sandbase-harness
sandbaseai
Local-first, self-hosted AI agent runtime and MCP bridge with sandboxed sessions, memory, credentials, audit/replay, and a local Console.
feibi-mochi/deepseek-harness-control-center
DeepSeek Harness control center for balance, usage, peak/off-peak pricing, encrypted multi-account switching, health checks, reminders, recharge, and session controls. / 余额、用量、峰谷计费、加密多账户、健康检查、提醒、充值与会话控制
PROJECT TOPICS
INSTALL REFERENCE
dsh plugin --profile web add github:feibi-mochi/deepseek-harness-control-center
该命令指向仓库当前默认分支;尚无绑定当前 commit 的完整验证结果。
PROJECT README
DeepSeek Harness monitoring, alerts, recharge, and session control center.
Balance ¥5.89 · Session ¥0.72 · Official 18.8M | Third-party 800K · ↗ Recharge
English · 简体中文 · Install · Compatibility · Changelog
A local-first companion that keeps account status, per-conversation usage, completion reminders, official recharge, flexible layout, and host-gated session controls beside the DSH composer.
Version: v0.3.13.
If DeepSeek Harness Control Center helps you, please consider leaving a ⭐ Star. Thank you!
The wallet UI is currently primarily Chinese and does not yet follow the host language setting (#32). DeepSeek balances come from the official API; cost accounting is a local estimate.
余额 ¥5.89 · 本场 ¥0.72 · 官 18.8M | 三方 800K · ↗充
deepseek-v4-flash-vision-exp is priced like V4 Flash; image tokens reported by the Harness are included with text tokens.v4-flash, v4-pro, and v4-flash-vision-exp. Weekday peak windows are 09:00–12:00 and 14:00–18:00 Beijing time. After Friday 18:00 the card previews “weekend all-day off-peak”; Saturday and Sunday name the current all-day off-peak rule; Monday before 09:00 shows the time remaining to enter peak. Optional notifications treat Friday 18:00 through Monday 09:00 as one continuous off-peak period.vision-toolkit- variants—replaces DeepSeek balance, recharge, and peak pricing with plan-window summaries; unrelated providers show only their own session tokens, and DeepSeek V4 restores the wallet and peak clock.--dsw-alias-* variables with safe fallback colors, so light and dark themes both render correctly; the panel closes when you click outside and flips open-direction near screen edges.credentials.set('DEEPSEEK_API_KEY', ...)), and since the llm-deepseek provider route resolves that reference per request, the very next LLM call is billed with the new account — no restart needed.$DSH_HOME/storages/accounts.json: Windows uses the current user's DPAPI; other platforms use an owner-only AES-GCM key file. An encrypted .bak recovers a missing, corrupt, or undecryptable primary file; if neither copy can be read, writes are locked instead of overwriting account data. The UI only shows masked keys.本约 $x, converted from the CNY price table using a fixed estimate of 7.25 CNY per USD (neither a live exchange rate nor the official USD tariff); CNY accounts show 本场 ¥x. These are local estimates, not an official invoice.DEEPSEEK_API_KEY is supplied by the launching environment, switching is refused with a clear error (the credentials provider rejects shadowed writes) — unset it in your shell to enable switching.DeepSeek Harness Wallet is for users who want to check balances during a conversation, compare model costs, or manage multiple accounts. A chip beside the composer shows the selected model’s balance, remaining plan quota, or token usage; open it for details or detach it into a floating panel. Settings brings together encrypted accounts, low-balance and completion reminders, a usage heatmap, and fixed or time-of-use prices for third-party APIs. DeepSeek balances and Z.ai quotas come from their respective APIs. Costs are estimated locally from host-reported usage, helping you track consumption without replacing provider invoices.
From npm:
dsh plugin --profile web add deepseek-harness-wallet
or from GitHub main:
dsh plugin --profile web add github:feibi-mochi/deepseek-harness-control-center
Restart dsh web, then hard-refresh the page.
dsh plugin --profile web update deepseek-harness-wallet
dsh plugin --profile web remove deepseek-harness-wallet
The package was renamed from
dsh-wallettodeepseek-harness-walletin 0.1.1. If you installed the old name, remove it withdsh plugin --profile web remove dsh-walletfirst.
See 0.3.13 compatibility evidence. The official 0.1.5-alpha.1 host does not provide this plugin’s permanent-delete capability, so that switch stays disabled; the old source integration patch is not a drop-in update.
The client contains no operating-system-specific feature branch; it checks the Web and host capabilities it needs. That makes the same code portable, but portable code is not the same as real-device verification:
| Verification level | Coverage |
|---|---|
| Current local verification | Windows + Node 24.18.1 + DSH 0.1.5-alpha.1; keyless Web UI and isolated lifecycle checks. No live paid-API acceptance |
| Exact host coverage | 0.1.5-alpha.1 checked for this update; earlier 0.1.2-alpha.3/alpha.4/alpha.5/rc.1 evidence belongs to previous wallet releases. Other releases remain unverified |
| Automated compatibility checks | Browser notification failure, in-page fallback, cross-tab fallback, storage fallback, CSS-scale fallback, and synchronous/asynchronous desktop adapters |
| Capability-compatible targets | Current Chrome, Edge, and Firefox on Windows/macOS/Linux; Safari on macOS; Electron/Tauri-style DSH wrappers that provide the requirements below |
The last row describes intended compatibility, not a claim that every browser/OS/wrapper combination was physically tested. If system notifications are unavailable or denied, reminders fall back to an in-page notice; if Web Locks are unavailable, a renewable local-storage lease coordinates reminder ownership across tabs. CSS zoom also has a transform fallback. Core wallet data, controls, dragging, docking, scaling, and visibility settings use these shared paths rather than an OS name check.
Electron, Tauri, and other DSH desktop wrappers can run the wallet when they expose the normal DSH Web plugin loader, slots, wallet HTTP endpoints, DOM, and fetch. A wrapper that restricts native notifications, persistent storage, or external links may define one optional adapter before the plugin bundle loads:
window.__DSH_WALLET_ADAPTER__ = {
// All fields are optional. Keep storage synchronous and localStorage-compatible.
storage: { getItem, setItem, removeItem },
notify({ title, body, tag, requireInteraction, onClick, onClose }) {
// May return a notification-like handle, Promise, or nothing.
// Call the supplied onClick/onClose callbacks for native events.
},
requestNotificationPermission() { return 'granted' },
openExternal(url) { return true },
capabilities: { permanentDelete: true },
}
notify() may return a notification-like handle, a Promise for one, or nothing for fire-and-forget native APIs. The payload also includes onClick / onClose callbacks so Electron IPC, Tauri notification actions, and other desktop bridges can return events without copying wallet logic; returning false asks the wallet to use its browser fallback. requestNotificationPermission() is optional for hosts such as Tauri and macOS that require a native permission request. Returning false from openExternal() likewise asks the wallet to try the browser fallback. Declare permanentDelete only when the host actually implements the wallet preference and session-menu action; compatible hosts advertise it automatically, while unsupported hosts show a disabled control instead of a switch that has no effect. Platform adaptations are intentionally confined to createCompatibilityAdapter() in src/client/core.js, so an Agent can add a new wrapper without editing wallet accounting or UI logic.
For buildable DSH hosts, the npm package and repository include a versioned Agent-assisted permanent-delete integration kit with a Chinese guide, complete Agent prompt, read-only preflight, compatibility manifest, upstream notice, and an exact-baseline reference patch. The patch is not a universal installer: a different DSH commit must be inspected and adapted by semantics, and closed or non-rebuildable desktop applications remain unsupported.
Permanent session deletion is implemented by the host, not the wallet. Its switch remains disabled on the official 0.1.5-alpha.1 host. For a source integration, see the guide and Agent adaptation prompt; the old reference patch is not a drop-in update for newer hosts.
Client development now uses five readable files under src/client/ and a committed lib/client.js artifact; run npm ci, npm run build:client, and npm run check:client after source edits. Installation runs no build scripts. Exact-version smoke checks are documented in 0.3.10 compatibility evidence.
| Item | Behavior |
|---|---|
| Token accounting | Listens to the llm/stream event and buckets per session and provider: deepseek-official plus explicitly opted-in wrapper routes use the official bucket; other providers stay third-party; each usage event also locks its contemporaneous official price, so multiple sessions and pricing windows never mix. |
| Balance | The wallet plugin itself sends the active key directly only to the official /user/balance endpoint. When multi-account switching is enabled, the selected key is also written into the DSH credentials seam; DSH may then use it for subsequent model requests. |
| Accounts | Keys live encrypted in $DSH_HOME/storages/accounts.json, with an encrypted accounts.json.bak fallback for a missing, corrupt, or undecryptable primary. Windows uses current-user DPAPI; other platforms use an owner-only AES-GCM key file, so move accounts.json, .bak, and .key together. If neither copy can be read, account writes fail closed. |
| Usage ledger | Local events and custom third-party price rules live in $DSH_HOME/storages/wallet.json with a wallet.json.bak recovery copy. Missing/corrupt primaries recover automatically; if neither copy is readable, wallet writes fail closed. Up to 365 days and 20,000 events of session/provider/model/token metadata and official locked cost are kept—never prompts, tool arguments, response bodies, or API keys. Third-party estimates are recalculated from the current custom rule and each retained event's occurrence time; aggregate usage without a retained timestamp safely falls back to the base rate. |
| Local settings | Layout, scale, visibility, reminder, and panel settings stay in browser-compatible local storage. |
| Permanent deletion | Opt-in and host-gated. The wallet never advertises the action unless the host implements the matching session deletion path. |
| Model surface | No tools registered, no prompt injection, zero token cost. |
| Recharge | The URL is hardcoded to the official https://platform.deepseek.com/top_up and is not user-configurable (anti-phishing). |
CNY per 1M tokens, curated from official announcements (cache writes are not billed):
Historical deepseek-chat and deepseek-reasoner records retain their original flat-rate table; this is not a claim that those legacy model names remain currently available. Each usage event is priced when it arrives; upgrading from 0.1.2 migrates legacy counters once using the then-current rate. Costs are estimates; the API-returned balance is authoritative.
CLASSIFICATION EVIDENCE
系统优先读取 GitHub Topics,再与站内分类词典和词根规则比对。当前命中: notifications、account-monitoring、balance-monitor、cost-tracking、session-management、token-tracking。