Configure model providers and API keys in DeepSeek Harness
DeepSeek Harness configures model providers under Settings → Models, with built-in provider ids such as anthropic, openai, moonshotai and zai; API keys go to $DSH_HOME/.credentials.yaml, while the providers block lives in cordis.patch.yml. This walks through where to configure, where things are stored, and how to fix the common errors.
Where to configure DeepSeek Harness model providers: built-in ids and Settings → Models
DeepSeek Harness configures model providers under Settings → Models, where built-in ids include anthropic, openai, moonshotai and zai; pick one, then add a key and a model name (source). Work through these steps:
- Open the settings panel — go to Settings → Models to see the built-in provider list. Expected: common ids such as
anthropic,openai,moonshotaiandzaiare selectable without adding anything from scratch. - Pick a provider id — with a built-in id you only add a model name; only self-hosted or third-party compatible services need a
baseURLand anapiprotocol. Expected:apiis one ofopenai-completions,openai-responsesoranthropic-messages. - Fill in the model name — enter the model to use under that provider. Expected: the name must match what the provider actually exposes, otherwise the request fails with
UNKNOWN_MODEL. - Save and verify — send one request after saving. Expected: a normal response means the provider works; changes apply on the next request without a restart.
Where DeepSeek Harness stores keys: .credentials.yaml and the providers block
DeepSeek Harness stores API keys in $DSH_HOME/.credentials.yaml (written when you save once in the UI), while structured provider settings go into the providers block of $DSH_HOME/profiles/<profile>/cordis.patch.yml (source). When you need to write structured settings by hand, use these fields:
providers— a block keyed by provider id that declares the connection and model information.apiKeyEnv— names the environment variable to read the key from, useful when you do not want plaintext in the file.baseURLandapi— the address and protocol of a custom service; the protocol decides the request body format.models/modelOverrides—modelslists the models a provider supports, whilemodelOverridesoverrides the parameters of just one model.input/defaultInput— declare input modalities, which is where image capability settings live.reasoning/reasoningEfforts— control reasoning tiers; an unsupported tier raisesUNSUPPORTED_REASONING_EFFORT.compat— compatibility switches includingthinkingFormat,supportsDeveloperRoleandmaxTokensField, used to adapt to differing API flavors.
# $DSH_HOME/profiles/<profile>/cordis.patch.yml (structure sketch)
providers:
openai:
apiKeyEnv: OPENAI_API_KEY
baseURL: https://api.openai.com/v1
api: openai-completions
models:
- gpt-4o
Keys live in the credential file and structured switches in the patch file — keeping the two apart is the default design of DeepSeek Harness. When you want DSH plugins for memory or retrieval, browse DSH Plugin Hub, install, then return to the settings page for model setup.

Fixing MISSING_CREDENTIAL, UNKNOWN_MODEL and reasoning errors
MISSING_CREDENTIAL means no usable credential was found, UNKNOWN_MODEL means the model name is not in the models list, and UNSUPPORTED_REASONING_EFFORT means the reasoning tier is not supported — each has a fixed fix (source). Handle them by error code:
- Read the error code first — the message states the code directly. Expected: you know whether it is a credential or a model issue before reinstalling anything.
MISSING_CREDENTIAL— re-save the key under Settings → Models; when usingapiKeyEnv, confirm that variable exists in the environment starting DeepSeek Harness. Expected: the next request succeeds after saving.UNKNOWN_MODEL— verify the model name spelling and case, or add the model to themodelsarray of theprovidersblock. Expected: the error clears once the name matches.UNSUPPORTED_REASONING_EFFORT— drop to areasoningEffortstier the model supports. Expected: requests succeed with a supported tier.- Change not taking effect — confirm the edit is in the profile actually in use. Expected: switching profiles once rules out a wrong-layer write.
DeepSeek Harness model provider limits and cautions
.credentials.yamlis plaintext and sensitive: it holds API keys and the browser session signing key, so never commit it or share screenshots.settings.yamlstores references, not secrets: the key itself lives in.credentials.yaml, so do not hardcode plaintext keys elsewhere.- The
apiprotocol must match the service: pointingopenai-completionsat an anthropic-style endpoint fails, so confirm the interface format first. - Reasoning tiers are model-specific: an unsupported
reasoningEffortsvalue errors out, so check the model docs first. - Configuration is layered: the
providersblock applies to whichever profile holds it; the full merge order is in how DeepSeek Harness merges plugin config.
Once models work, a machine or network change often needs proxy and certificate settings too, covered in setting up a network proxy for DeepSeek Harness.
Sources: Configuring models (official docs), dsh CLI README (official repository)
FAQ
DeepSeek Harness configures model providers under Settings → Models, and the built-in provider ids include anthropic, openai, moonshotai and zai. Pick one, then add an API key and a model name; custom services just need a baseURL and an api protocol.
DeepSeek Harness stores credentials in $DSH_HOME/.credentials.yaml, written whenever you save a key in the UI. It also holds the browser session signing key, so it is plaintext and sensitive — do not hand-edit it and never commit it.
MISSING_CREDENTIAL means the current provider has no usable credential, usually because the key was never saved, the apiKeyEnv variable name does not match, or the change landed in a different profile. Re-save the key under Settings → Models, then confirm the apiKeyEnv variable exists in the environment that starts dsh.
UNKNOWN_MODEL means the model name is not in that provider's models list. Check the spelling and case under Settings → Models, or add the model to the models array in the providers block of cordis.patch.yml.
DeepSeek Harness lists supported models with models, overrides one model's parameters with modelOverrides, declares input modalities with input and defaultInput, and controls reasoning tiers with reasoning and reasoningEfforts. Verify with one request; no restart is needed.
Related Terms
- provider
- A provider is the party that serves models in DeepSeek Harness; each has an id such as anthropic, openai, moonshotai or zai and carries an API key, a baseURL and a model list, matching one entry under Settings → Models.— DeepSeek Harness official docs - Configuring models
- .credentials.yaml
- .credentials.yaml is the user-level credential file of DeepSeek Harness, located under $DSH_HOME, holding provider API keys and the browser session signing key. It is written by the UI rather than by hand and is plaintext and sensitive.— DeepSeek Harness official docs - Configuring models
- MISSING_CREDENTIAL
- MISSING_CREDENTIAL is the error DeepSeek Harness raises when a request finds no usable credential, typically because the key was not saved, the apiKeyEnv variable does not exist, or the edit was written into another profile.— DeepSeek Harness official docs - Configuring models
- UNKNOWN_MODEL
- UNKNOWN_MODEL is the error DeepSeek Harness raises when a model name is not in a provider's models list; fix it by correcting the name or adding the model to the models field of the providers block.— DeepSeek Harness official docs - Configuring models
Sources
- DeepSeek Harness official docs - Configuring models· deepseek-ai
- dsh CLI README· deepseek-ai