Tencent-ADP-dsh-plugin
Tencent Cloud ADP plugin for DeepSeek Harness
- Stars
- 1
- Language
- TypeScript
- Created
- Aug 17, 2026
- Updated
- Aug 19, 2026
Introduction
@tencent/dsh-adp
Tencent Cloud ADP as a DeepSeek Harness plugin bundle.
This plugin connects a DSH profile to Tencent Cloud ADP: gateway models (Hunyuan and friends), Hunyuan AI web search, the API/MCP plugin marketplace, the skill plaza, and ADP apps as ask tools. It is not ADP Worker.
Install
git clone https://github.com/TencentCloudADP/Tencent-ADP-dsh-plugin.git
cd Tencent-ADP-dsh-plugin
dsh plugin --profile web add .
# or a packed tarball: dsh plugin --profile web add ./tencent-dsh-adp-0.1.0.tgz
dsh web
Then open Settings → Plugins → Tencent Cloud ADP and fill in credentials (next section). Install issues (stale plugin name, pnpm build approval): docs/pitfalls.md.
Configure
ADP has three credential planes. The patch stores reference names (ADP_API_KEY, …); values live in $DSH_HOME/.credentials.yaml or the environment.
Official ADP API docs cover control-plane AKSK and AppKey SSE chat. They do not document the OpenAI-shaped model gateway this plugin also uses. Endpoints and key sources: API overview. Planes and error codes: docs/credentials.md.

| Plane | Reference | Official source | If missing |
|---|---|---|---|
Gateway sk- | ADP_API_KEY | Model-gateway API key (undocumented; see docs/credentials.md) | LLM / search / plugin calls fail with MISSING_CREDENTIAL |
| SecretId / SecretKey | ADP_SECRET_ID / ADP_SECRET_KEY | Public cloud: CAM API keys. Independent site: ADP console Key Management | Model / plugin / app catalogs stay empty |
| Per-app AppKey | e.g. ADP_APP_KEY_DEMO | App publish → API management or app Invoke (SSE) | The matching ask tool is not registered |
1. Open ADP
Register and complete real-name verification, then open the product (product overview). First login creates one enterprise and a default workspace; that workspace is not the string default_space this plugin ships in the patch (workspace overview).
| Site | Console | Control host | Agent SSE |
|---|---|---|---|
| Independent site | adp.tencent.com | capi.adp.tencent.com | https://adp.tencent.com/adp/v2/chat |
| Public cloud | adp.cloud.tencent.com | adp.tencentcloudapi.com | https://wss.lke.cloud.tencent.com/adp/v2/chat |
Both sites complete against https://api.adp.cloud.tencent.com/chat/completions (no /v1). There is no api.adp.tencent.com.
2. Get SecretId / SecretKey
Public cloud — CAM AKID… key (36 characters):
- Open CAM → API Key Management.
- Create a key if the list is empty (root account access keys). Copy SecretId and SecretKey at creation time; SecretKey is shown only once after 2023-11-30.
- Sub-accounts need ADP (formerly Large Model Knowledge Engine) read/write on the CAM role (FAQ). Collaborator accounts are not supported (122569).
Independent site — ADP console key (~26 characters, not AKID):
- Sign in at adp.tencent.com.
- Open Key Management and copy SecretId / SecretKey (API overview · independent site).
That pair signs control-plane calls (DescribeModelList, DescribeSpaceList, marketplace). It is not ADP_API_KEY.
3. Get the gateway sk- (ADP_API_KEY)
Create or copy an API key that authenticates POST https://api.adp.cloud.tencent.com/chat/completions (usually starts with sk-). Use this for Hunyuan / DeepSeek completions, Hunyuan search, and API/MCP plugin HTTP. Independent-site console AKSK cannot replace it.
4. Optional: AppKey
Needed only for adp_ask / adp_ask_<slug> (SSE to a published app), not for picking adp:Hunyuan/hy3.
- Publish the app.
- Open App Publish → Service Status → API Management, or App Management → Invoke, and copy AppKey (104209, 105560).
5. Fill the DSH card
- Run
dsh webon loopback (127.0.0.1). Credential writes are loopback-only. - Settings → Plugins → Tencent Cloud ADP.
- Choose Independent site or Public cloud.
- Paste SecretId / SecretKey (and the gateway
sk-). Save. Values go throughcredentials.setinto$DSH_HOME/.credentials.yaml. - After AKSK is stored, the card lists workspaces from
DescribeSpaceList. Pick one. Public-cloud app and plugin calls need a real SpaceId; the patch defaultdefault_spaceis not a workspace on most accounts (control-plane4510004). If the list is empty, paste a SpaceId from the ADP console (workspaces). - Paste AppKey if you will use ask tools. Save again.
OneID on the card opens the ADP console in a new tab. It does not write any credentials.
A Claw-style “build the app entirely via API” walkthrough (CreateSpace → CreateApp → CreateAgent → CreateRelease → chat) is 133869. That path is AppKey SSE, not this plugin’s gateway adapter.
What you get
adp-core, llm-adp, web-adp, plugins-adp, skills-adp, agents-adp, and control-adp start with the plugin:

- Select
adp:Hunyuan/hy3(or another gateway model) and complete a tool-using turn. How catalog vs completions are wired: docs/seams.md. web_searchthrough Hunyuan AI search when this provider is selected (China-centric index).- Enable an API or MCP marketplace plugin via
adp_plugin_list/adp_plugin_enable, orenabledPluginIds. Public-cloud plugin/app calls need the workspace chosen above. - Generated media links (~24h COS) are saved into the workspace as
saved_files. - Skill plaza as a
ctx.skillsprovider (entries without download URLs stay inlistonly). adp_provision_agent— CreateApp → CreateAgent → CreateRelease → FieldMask AppKey →adp_ask_<slug>.adp_ask/adp_ask_<slug>— SSE ask; not a DSH subagent.adp_list_actions/adp_callwithallowMutatingfor App/Agent/Release CRUD. Mutating calls require approval.
Documentation
- docs/credentials.md — where each key comes from and what breaks without it
- docs/seams.md — contracts between this plugin and DSH
- docs/pitfalls.md — known traps
- docs/verification.md — manual checklist
Verify
pnpm test # simulated HTTP; no secrets; CI gate
pnpm test:live # real account; skips when env is absent
Contributing
Issues and pull requests are welcome on GitHub. Run pnpm test before opening a PR.
License
MIT. Copyright (C) 2026 Tencent. See LICENSE.txt for the text and third-party notices (eventsource-parser, fflate).