DSH Hub

duhu2000/qcc-mcp-oauth

qcc-dsh-mcp-oauth

BundleWorkflow1 GitHub stars· updated 2026-08-19

qcc-dsh-mcp-oauth is a community DeepSeek Harness plugin. Read the repository README before installing.

Install

npx @deepseek-ai/dsh plugin --profile web add qcc-dsh-mcp-oauth

Restart `dsh web` after install. Bundle APIs can change during the developer preview.

README badge

qcc-dsh-mcp-oauth DSH Hub badge
[![DSH Hub](https://dshhub.dev/badge/qcc-mcp-oauth.svg)](https://dshhub.dev/plugins/qcc-mcp-oauth)

Paste this into your README. The star count updates with every catalog sync.

From the README

Excerpt from duhu2000/qcc-mcp-oauth, cleaned of badges and images.

企查查 MCP OAuth 插件(DeepSeek Harness)

One-click OAuth connect to 企查查 (Qichacha) MCP services inside DeepSeek Harness. 在 DeepSeek Harness 中一键 OAuth 授权接入企查查 MCP 数据(工商 / 风险 / 知产 / 经营 / 董监高)。

功能 / Features

  • 🔑 一键 OAuth 连接Authorization Code + PKCE(S256),动态注册客户端(无 client_secret),自动打开浏览器跳转企查查授权页,loopback 回调自动完成
  • 🌐 一次授权、全 Server 可用:一份 access_token / refresh_token 覆盖企查查 MCP 企业数据 SERVER(company / risk / ipr / operation / history / executive,共 6 个);history(历史信息)需企业认证,插件按 token 实际授权范围动态挂载——企业认证账号 6 个、个人账号 5 个
  • 🔄 自动刷新:access_token 过期前自动 refresh(token 轮换),失败才需要重新授权
  • 💾 安全持久化:token 存储于 DSH 存储域(~/.dsh/storages,目录 0700),重启 Host 自动恢复连接
  • 🛠 对话即管理:内置 qcc_oauth_connect / qcc_oauth_status / qcc_oauth_disconnect 三个工具
  • 🚪 一键断开:调用 OAuth revoke 撤销 refresh_token 并停用 MCP 工具

安装 / Install

前置:DeepSeek Harness(dsh CLI,web profile),Node ≥ 20。

🤖 让 Agent 安装(最省事,推荐给不熟悉命令行的用户)

把下面的链接直接发给你的 DeepSeek Harness 对话(推荐先在 dshmarket 插件市场搜索「企查查」一键安装;市场直装失败时,同样把链接发给 Agent 即可代为安装):

帮我安装这个插件 https://github.com/duhu2000/qcc-mcp-oauth

Agent 会按本 README 执行以下命令(你也可以自己跑):

# 方式一:一键脚本(自动安装 + 注册 bundle + 提示重启)
bash <(curl -fsSL https://raw.githubusercontent.com/duhu2000/qcc-mcp-oauth/main/install.sh)

# 方式二:手动两步
dsh plugin --profile web add qcc-dsh-mcp-oauth   # 安装依赖并自动注册 bundle
# 重启 dsh web

说明:安装时的 peer dependencies 警告可忽略——@deepseek-ai/* 等对等依赖由 DSH web profile 自带(host 依赖),无需另行安装;安装完成后必须重启 dsh web 才能生效。

方式 A:npm 安装

# 1. 安装插件到 profile(声明了 dsh.bundle 的包会被 dsh plugin add 自动注册到 bundles)
dsh plugin --profile web add qcc-dsh-mcp-oauth

# 2. 重启 dsh web

若未自动注册:手动在 ~/.dsh/profiles/web/package.json 的 dsh.profile.bundles 追加 "qcc-dsh-mcp-oauth"(与 @deepseek-ai/dsh-base@deepseek-ai/dsh-web-app 并列),再重启。

方式 B:GitHub 直装

dsh plugin --profile web add github:duhu2000/qcc-mcp-oauth
# 再重启 dsh web

方式 C:源码 / 本地调试

git clone https://github.com/duhu2000/qcc-mcp-oauth.git
cd qcc-mcp-oauth
dsh plugin --profile web add "link:$(pwd)"      # 或 pnpm add "file:$(pwd)"
# 再重启 dsh web

插件包内自带 cordis.patch.yml(bundle patch);dsh plugin add 自动完成依赖安装与 bundles 注册,插件行自动合入,无需手改任何文件。

使用 / Usage

重启后,插件会自动发起 OAuth 授权(默认开启,激活且无有效授权时自动打开企查查授权页);如未自动触发,在对话中输入:

你说效果
"连接企查查"触发 qcc_oauth_connect:自动打开浏览器跳转企查查授权页,登录授权后自动完成连接
"查一下企查查连接状态"触发 qcc_oauth_status:显示授权状态、token 过期时间、覆盖的 MCP Server
"断开企查查"触发 qcc_oauth_disconnect:撤销 refresh_token、清除本地授权、停用工具

连接成功后,以下工具直接可用(示例):

  • mcp__qcc-company__get_company_registration_info / get_actual_controller / ...
  • mcp__qcc-risk__get_company_risk_scan / get_dishonest_info / ...
  • mcp__qcc-ipr__*mcp__qcc-operation__*mcp__qcc-executive__*

原理 / How it works

严格遵循《企查查MCP OAuth 接入文档》(Authorization Code + PKCE,公开接口版):

  1. 发现 MCP Protected Resource Metadata → 2. 发现 OAuth Server Metadata(endpoint 全部动态读取,不硬编码)
  2. 动态注册客户端(client_id,90 天自动续期)→ 4. 打开授权页(scope=mcp:tools
  3. loopback 回调校验 state → 6. 授权码 + code_verifier 换 token
  4. 解析 token 实际授权的 resource(JWT claim),通过 ctx.loader 为授权的 @deepseek-ai/dsh-mcp-client 条目注入 Bearer header(企业认证 6 个 / 个人 5 个)→ 8. 过期前自动刷新(轮换)

详见 docs/OAUTH-IMPLEMENTATION.md

配置 / Configuration

插件行位于 ~/.dsh/profiles/web/cordis.patch.yml(bundle 合入后可见):

Related plugins