Independent AI intelligence Two editions daily · ET
Fervor AI

Analysis · October 4, 2026 · repo

dsh-our-free-modelOpenCode ZenDeepSeek Harnessprivacyagent-securityagent-harness

dsh-our-free-model Shows What Free Keyless AI Models Actually Cost

A trending plugin gives DeepSeek Harness free model access with no login and no API key. The price is written in the gateway's privacy notes, model by model.

The pitch fits in one line of the README: "no login, no sign-up, no API key, nothing else." Install a plugin, and your agent harness gets a dropdown of models you pay nothing for and never registered to use.

That line put zouyuxuan122/dsh-our-free-model on Trendshift's board this weekend, and version 1.4.4 shipped on October 4. It is MIT-licensed, has about 1,100 stars, and is more candid about its own mechanics than most projects twice its size.

Which makes it a good case study. The plugin tells you exactly where your prompts go. The question it leaves to you is what the place they go does with them.

What the plugin does

DeepSeek Harness, or dsh, is a plugin host for Node.js agent apps, with CLI and desktop variants. This plugin adds one provider to it. Install it with:

dsh plugin --profile web add /absolute/path/to/dsh-our-free-model

From then on, the plugin lists models from a single upstream, OpenCode's Zen gateway at https://opencode.ai/zen/v1/. The English README says plainly that there is "one source, nothing else," with no third-party relay in between. It authenticates with a literal Authorization: Bearer public header. That is the whole trick: a shared, public credential in place of your own key.

The plugin probes models continuously and sorts them into two groups, models your network can reach and models blocked for your region, which it keeps visible with the reason they failed. Among the models it surfaces, the README names Muse Spark 1.3 and MiMo V2.6.

On the plumbing, it does several things well. Its forward port binds only to loopback and rejects other addresses with an HTTP 400. Metrics, settings and usage logs stay in a local DSH_HOME/our-free-model/ folder. It ships no telemetry. A 429 is no longer retried three times in the same turn, which is polite to a shared free tier.

It also makes some outbound calls you might not expect. To sort models by region, it looks up your IP through api.ipify.org, ipinfo.io and ipapi.co. Announcements and upgrades come from GitHub raw and the jsDelivr CDN. None of that is hidden; all of it is worth knowing before you install.

Where the cost actually lives

Here is the part that matters. Every prompt, every tool result and every image your agent sends through this plugin goes to OpenCode Zen as a normal API request. So the terms that govern your data are Zen's, and the README says so: using it to reach free tiers "is subject to those providers' own terms."

Zen's documentation is clear about those terms, and they are not uniform. The default is good: "Our providers follow a zero-retention policy and do not use your data for model training." Then come the exceptions, and two of them sit on the free list:

  • Fledge Alpha Free: "During its free period, collected data may be used to improve the model."
  • Muse Spark 1.3 Contributor Free: permission is granted "to use your prompts and completions to train future Meta models."

Read that second one twice in the context of an agent. A coding agent's prompts are not chat questions. They are your source files, your stack traces, your config, the output of every tool call the agent made, and sometimes whatever secret sat in an environment file the agent decided to read. If the model behind your dropdown is the Contributor variant, that whole stream is, by the provider's own terms, training data.

The model names make this easy to miss. "Muse Spark 1.3" in a dropdown and "Muse Spark 1.3 Contributor Free" in a privacy table are the same family, and the word that tells you the deal, Contributor, is the one that falls off in a short label.

The account you skipped

There is a second layer. Zen's docs describe the normal way in: sign up, add billing details, and get an API key. The plugin skips that and sends a shared public bearer instead. Zen's docs do not say whether that path is meant for third-party clients, and the plugin does not claim it is. Its README says it is "not affiliated with, endorsed by, or sponsored by any model provider," and it tells you to check the providers' terms "before deploying anywhere beyond your own machine."

That is honest, and it is also a warning. A free path you did not sign up for is a free path nobody promised you. The plugin already documents 429s for quota and 403s for blocked regions. The README's line "Free, with no usage cap" sits beside those same 429 notes, which tells you the real cap is whatever the gateway decides on a given afternoon. If Zen closes the public path tomorrow, the plugin's dropdown empties and nobody owes you an explanation.

Skipping the account also means skipping the agreement. With a key, you accept terms, and you can choose which models to call based on them. Without one, the terms still apply to your data. You just never looked at them.

Put this into practice

If you want to try free models in an agent harness, you can do it sensibly. Here is the low-friction version.

1. Read the free-model list before you pick. Open Zen's docs and match every model you might select against its data note. Default to the zero-retention ones. Treat any model marked as training on prompts as a public channel.

2. Never point a free model at a real repository. Use it on throwaway code, public projects or synthetic tasks. If the agent can read .env files, credentials or customer data, a training-eligible model should not be in the loop at all.

3. Pin the model, not the dropdown. The plugin reorders and regroups models as availability changes. If your harness can pin a specific model ID, do that, so a probe cycle cannot swap you onto a model with different terms.

4. Expect it to break. Build your agent so a 429 or an empty model list falls back to a provider you pay for. Free tiers behind shared credentials are for experiments, not for anything that has to finish.

5. Decide whether the IP lookups are acceptable. Three geolocation services see your address on install and probe. On a personal laptop that may be fine. On a company network, check with whoever owns egress policy.

6. If you like the models, get a key. Zen offers the same gateway with your own account and billing. That puts you inside the agreement and gives you a stable path.

Honest limitations

I have not run the plugin. Its own testing was on Windows, against specific DeepSeek Harness builds, and everything here about its behavior comes from its README and the verification done for this week's briefing.

Zen's model list and privacy notes are a snapshot. Free models come and go, and terms can change. Check the page on the day you choose, not this article.

I do not know how OpenCode treats the public bearer. It may be an intended anonymous tier, or it may be something they will close. The docs I read do not say, so I have not claimed either.

And the training clauses belong to specific models, not the gateway as a whole. Most of Zen's free list falls under the zero-retention default. The risk is that you will not know which one you are using unless you check.

Free is a price, not an absence of one

There is nothing sneaky about this repo. It is open about the gateway, the shared credential, the IP lookups and the terms it does not control, which is more than most "free AI" offers manage. The cost sits in a table on someone else's documentation page, and an agent is the worst possible client to send there without reading it, because an agent sends everything it touches.

So use the plugin the way its own README suggests: on your machine, for experiments, with your eyes open. Before you wire any keyless model into a workflow that reads real code, spend five minutes with the privacy notes. You are agreeing to them either way.

Sources: dsh-our-free-model README, OpenCode Zen docs, Trendshift.


Medium metadata

  • Title: dsh-our-free-model Shows What Free Keyless AI Models Actually Cost
  • Subtitle: A trending plugin gives DeepSeek Harness free model access with no login and no API key. The price is written in the gateway's privacy notes, model by model.
  • Tags: AI Agents, Privacy, Open Source, LLM, Software Development
  • Reading time: about 8 minutes
  • Canonical: import from the fervorai.dev URL