DeepSeek Harness
Give DeepSeek Harness (dsh) cross-project and cross-session long-term memory. Once installed, every conversation automatically recalls relevant memories and captures new content, and the model gets the OpenViking tools and the openviking-memory, openviking-skills, and ov-experience-memory skills without any extra setup.
Source: examples/dsh-memory-plugin
Install
DSH shares the installer with the other memory plugins. It asks which harnesses to install and for your OpenViking credentials; every step is idempotent—re-running it is entirely safe.
curl -fsSL https://openviking.ai/install | bash
# AI agents: not sure about running this? The script's header says what it does and how to verify it.The installer puts the plugin into the web profile. To use another profile, pass --dsh-profile <name>: curl -fsSL https://openviking.ai/install | bash -s -- --dsh-profile <name>.
After installation, use the verification steps below to check tool access and cross-session recall.
Manual setup
Configure the connection — write
~/.openviking/ovcli.conf(url,api_key, optionalaccount/user), or setOPENVIKING_URLandOPENVIKING_API_KEY. Using pure local mode (http://127.0.0.1:1933, no authentication)? Skip this—the bundle defaults to the local setup.Add the bundle to a profile:
bashdsh plugin --profile web add @openviking/dsh-memory-plugindsh pluginforwards to pnpm inside the profile directory, so any profile name works;webis the onedshcreates for you on first use.Check that the profile picked it up:
bashdsh --profile web --dump-configThe output should contain an
openviking-memory-runtimeentry.
Don't have
ovcli.confyet? See the Deployment Guide → CLI.To remove it:
dsh plugin --profile web rm @openviking/dsh-memory-plugin.
Verify
Start dsh --profile web and open a conversation. You should see an OpenViking context injection at the top of the session, and the model should have mcp__openviking__* tools available. Ask it about something from an earlier session to confirm recall.
For MCP proxy diagnostics, set OPENVIKING_DEBUG=1 and OPENVIKING_DEBUG_LOG=/tmp/ov-dsh.log before starting DSH, then check that file. Automatic memory callbacks use DSH's own logger. The legacy OV_DEBUG_LOG=/tmp/ov-dsh.log alias is still supported and takes precedence over both canonical settings.
How it works
The bundle runs inside DSH as a Cordis plugin rather than as external hooks, so it follows the session in-process. At session start it injects your OpenViking profile block, an index of available memories, and an <available-skills> catalog of your OpenViking skills. When a model step takes new user input, it searches OpenViking with the text the user typed and appends what it finds to that step as a durable message, so the injection replays with the session and is visible to compaction. Context that DSH or other plugins inject (for example time-context or job notices) and tool results neither trigger recall nor enter the query. It captures user, assistant, and (optionally) tool-result messages straight from DSH's event stream, skipping injected context, and commits to OpenViking once pending tokens cross the threshold, archiving every captured message. Writes that fail land in a pending queue and replay at the next session start.
Each DSH session maps to dsh-<session-id> in OpenViking, and every subagent gets its own session.
The model-facing surface is the OpenViking MCP tool set, reached through the same stdio proxy the other memory integrations use and published under an mcp__openviking__ prefix. Because that proxy runs once per profile, mcp__openviking__remember stores into a short-lived server-side session rather than the current one—automatic capture still records the conversation itself. With OPENVIKING_RECALL_PEER_SCOPE=actor, a fixed OPENVIKING_PEER_ID attributes that profile’s tool calls to one peer; the default all scope omits the actor-peer header. Use separate profiles/processes when workspaces need different tool identities. The bundle also ships three shared skills: openviking-memory, so the model knows when to search, read, and write; openviking-skills, which covers finding, using, creating, sharing, and migrating skills stored in OpenViking; and ov-experience-memory, which retrieves and applies prior task Experience before executable work. Tool results are captured by default (captureToolResults: true), which lets the server link the skill's reads back to the Experience they used; with false the skill only retrieves and applies Experience.
A filesystem tool call whose path is a viking:// URI is blocked with a hint pointing at the right OpenViking tool. For a write or edit under a skill directory such as viking://~/skills/<name>/, that tool is mcp__openviking__add_skill, which creates or replaces a whole skill from its SKILL.md text. A shell command that carries a viking:// URI still runs, and the model gets a notice suggesting the OpenViking tools, which it can ignore when the URI is intentional data.
Configuration
Credentials resolve from OPENVIKING_* environment variables, then ~/.openviking/ovcli.conf, then ~/.openviking/ov.conf — the same chain the Claude Code, Codex, OpenCode, and pi integrations use. The bundle reloads them when those files change.
| Env Var | Default | Description |
|---|---|---|
OPENVIKING_URL / OPENVIKING_BASE_URL | http://127.0.0.1:1933 | Server endpoint |
OPENVIKING_API_KEY / OPENVIKING_BEARER_TOKEN | — | API key (sent as Authorization: Bearer) |
OPENVIKING_ACCOUNT / OPENVIKING_USER | — | Trusted-mode account and user |
OPENVIKING_PEER_ID | — | Explicit actor peer |
OPENVIKING_WORKSPACE_PEER | true | Derive a peer from each session's workspace; 0 sends no peer |
OPENVIKING_RECALL_PEER_SCOPE | all | actor isolates recall to the current workspace |
OPENVIKING_DEBUG | false | Enable MCP proxy debug logging; also requires a log path |
OPENVIKING_DEBUG_LOG | "" | File path for MCP proxy debug logs |
OV_DEBUG_LOG | — | Legacy alias: enables MCP proxy logging and overrides the canonical debug flag and log path |
Behavior knobs live in the profile's Cordis patch entry:
- id: openviking-memory-runtime
config:
recallTokenBudget: 2000
scoreThreshold: 0.35
captureToolResults: true
commitTokenThreshold: 20000syncTurns: false in that block disables automatic capture, commit, and replay of pending writes. Profile injection and recall continue; queued writes remain for a later writing session. This does not revoke the model’s MCP write tools or change server permissions.
peerSource, in that same config block, decides how the workspace peer is derived. The default "git" uses the repository's normalized origin URL (git@github.com:volcengine/OpenViking.git becomes github.com-volcengine-openviking), falling back to the repository root path, so every clone, worktree, and subdirectory of one repository shares a single peer; outside a repository no peer is sent at all, and what is remembered there goes to your user-level space at viking://user/<you>/memories. "cwd" restores the earlier behavior — the working directory with every non-alphanumeric character replaced by - — and "none" sends no peer at all. To give a directory outside a repository its own memory, set OPENVIKING_PEER_ID for it (Give a Directory Its Own Peer).
skillCatalog and skillCatalogTokenBudget, in that same block, control the skill catalog injected at session start. It lists your own skills before those shared with your account under viking://agent/skills, each description cut to about 40 tokens, within its own budget (default 1200 tokens, separate from the profile budget); when not every description fits, it lists names only. skillCatalog: false or a budget of 0 turns it off; the environment spellings are OPENVIKING_SKILL_CATALOG and OPENVIKING_SKILL_CATALOG_TOKEN_BUDGET.
Credentials given in the patch win over the environment. Behavior knobs resolve highest priority first: OPENVIKING_* environment variables, the workspace's .openviking/config.json and config.local.json, ovcli.conf's plugin.dsh, ovcli.conf's plugin, then this patch block. The full list is documented in the bundle README.
Troubleshooting
| Issue | What to check |
|---|---|
| Nothing injected, no OpenViking tools | dsh --profile web --dump-config should list openviking-memory-runtime; re-run the installer or dsh plugin --profile web add … |
| Installed into the wrong profile | The installer defaults to web; re-run it with --dsh-profile <name> |
| DSH reports the bundle is incompatible with this dsh version | The bundle accepts every @deepseek-ai/dsh 0.x release from 0.1.0-rc.6 on (peer range >=0.1.0-rc.6 <1.0.0-0), so this means DSH 1.0 or later; update the bundle, or accept the risk with dsh plugin allow-version. Keep all @deepseek-ai/dsh-* host packages on the same version. |
| Bundle fails to start on a new DSH release | Releases verified so far: 0.1.0-rc.6, 0.1.5-rc.1, 0.1.5-rc.2, 0.1.7-rc.2, 0.2.0-rc.2, 0.2.1-alpha.1. Newer 0.x releases are admitted without prior verification; pin DSH to a verified release and open an issue. |
| Install says the package is "not in the npm registry" | The profile may have a pnpm minimum release age of 24 hours; check its configuration (minimumReleaseAge). Wait it out, or add the exact version to minimumReleaseAgeExclude in the profile's pnpm-workspace.yaml |
| Recall is empty | curl "<your OpenViking URL>/health"; check the endpoint and that the prompt is longer than the minimum query length (3 characters) |
| 401 / 403 from OpenViking | Verify OPENVIKING_API_KEY; for trusted-mode deployments also verify OPENVIKING_ACCOUNT and OPENVIKING_USER |
| Memories from other projects leak in | Set OPENVIKING_RECALL_PEER_SCOPE=actor to limit peer memories to the active peer; user-level memories remain shared |
| Nothing committed after a crash | Commit runs on a token threshold and at teardown; queued writes replay at the next session start |