Remote and mobile access for DeepSeek Harness: provides LAN QR code connection, Cloudflare/custom tunnels, WeChat, QQ, Feishu, Telegram bot integration, and security authentication.
Install
# from npm (prebuilt)
dsh plugin --profile web add @wenbin_wb/dsh-bridge
# from GitHub (first run asks for allowBuilds approval — follow the hint, retry)
dsh plugin --profile web add github:wenbin-wb/dsh-bridge
Any plugin you install runs third-party code with your own permissions — it can read your files, use your credentials, and reach the network, and tool approvals don’t sandbox it. GitHub-sourced plugins also run build scripts at install time — pnpm blocks those until you allow them, so an install can stop with ERR_PNPM_GIT_DEP_PREPARE_NOT_ALLOWED or ERR_PNPM_IGNORED_BUILDS; dsh prints the exact key to add under allowBuilds in your profile’s pnpm-workspace.yaml, and the install works on the next run. Allowing a build is a trust decision: only install sources you trust, and pin a commit (github:owner/repo#sha).
README
Multi-Channel Remote Access & Comprehensive Security Gateway Plugin for DeepSeek Harness (DSH remote access / remote control plugin, remote control)
Scan a QR code on your phone to continue using DeepSeek Harness anywhere. Whether relaxing on the sofa, commuting, or working across networks—no need to stay at your PC or set up complex servers.
Seamlessly extends your local DeepSeek Harness instance to mobile web, standalone PWA app, secure public tunnels, and WeChat / QQ / Feishu / Telegram bot matrix. Drive AI coding, run tasks, approve operations, and manage workspaces anytime, anywhere.
📖 Remote-access landing page: docs/remote-connection.md | 🤖 Summary for AI: llms.txt
Table of Contents
- ✨ Key Features
- 📦 Requirements & Installation
- 🚀 Core Features & Usage Guide
- 1. 🛜 LAN Access & Multi-NIC Smart Selection
- 2. 🌐 Public Tunnels (Cloudflare & Custom)
- 3. 📱 Mobile Experience & Standalone PWA
- 4. 🗂️ Web Remote Workspace Directory Picker
- 5. 🔐 Comprehensive Access Security & Admin Lock
- 6. 🤖 All-in-One IM Bot Matrix (WeChat / QQ / Feishu / Telegram)
- 7. 📊 Maintenance Dashboard & Graceful Restart
- 💬 FAQ
- 🛠️ Development & Contribution
- ⭐ Star History
- 📄 License
✨ Key Features
- 🛜 Multi-NIC Smart Detection & Switching: Automatically detects physical Wi-Fi, Ethernet, and virtual NICs (WSL/VMware/Docker); provides visual switching with persistent memory;
- 🌐 Dual-Mode Cloudflare Public Tunnels: Zero-login 1-click random temporary domains or Cloudflare Named Tunnel Token with auto-start on boot;
- 📱 Native-Grade Mobile UI & PWA: Centered session header, native drawer sidebar with
[|fold icon, anti-overlap responsive layout, PWA install support; - 🗂️ Web Remote Workspace Directory Picker: Mobile/remote visits pop up responsive tree directory browser; localhost visits route to OS native dialogs; supports
/addworkspaceIM command; - 🔐 Comprehensive Access Security & Dual Defenses: QR code secret Token login, visitor password gate, independent admin anti-tamper lock; host physical privilege (
127.0.0.1) & emergency terminal reset (reset-auth); - 🤖 All-in-One IM Bot Matrix (WeChat / QQ / Feishu / Telegram): Multi-workspace dispatching, cross-restart session persistence, streaming Markdown typewriter, Card 2.0 interactive approvals, and bidirectional file sharing;
- 📊 Maintenance & Smooth Upgrades: Host CPU / RAM / Uptime metrics, 1-click network diagnosis, JSON configuration backup & restore, npmmirror fast check & graceful restart.
📦 Requirements & Installation
Requirements
- Node.js ≥ 22 (DSH requires
^22.19.0or≥ 24.0.0) - dsh CLI available (runnable directly in terminal)
# Verify environment
node -v # v22.19+ or v24+
dsh --version
DSH version compatibility
This plugin supports both old and new DSH releases — there is no need to pick a plugin version to match your harness.
| DSH version | Status |
|---|---|
0.1.0 ~ 0.1.1 |
✅ Supported (loopback-only RPC channel hardening) |
0.1.2 ~ 0.1.4 |
✅ Supported |
0.1.5-alpha.1 ~ 0.1.5-rc.2 |
✅ Supported (since v2.10.9) |
Desktop builtin host 0.2.0-rc.2 (profile desktop) |
⚠️ Verifying (known #55: IM platform list may misrender in desktop settings while web works) |
About the built-in DSH authentication: since
0.1.2,dsh webships browser authentication — it prints a URL carrying a one-time token (http://127.0.0.1:3080/?token=…), which is exchanged for a session cookie bound to the loopback address. Afterwards/,/apiand every plugin RPC channel require that cookie.This is complementary to, not a duplicate of, this plugin's access-password gate: the built-in auth protects "the DSH process on local loopback", while this plugin's gate protects "remote access arriving over LAN or a public tunnel". The plugin's reverse proxy injects a valid loopback session cookie while forwarding, so phone / tunnel access needs no manual handling of DSH's
?token=— just use it as documented on this page.
Installation
# Method 1: Install from npm (Recommended)
dsh plugin --profile web add @wenbin_wb/dsh-bridge
# Method 2: Global-permission-free npx installation
npx --yes @deepseek-ai/dsh plugin --profile web add @wenbin_wb/dsh-bridge
# Method 3: Install from source
git clone https://github.com/wenbin-wb/dsh-bridge.git
dsh plugin --profile web add ./dsh-bridge
Upgrade
# Recommended: Click "🚀 1-Click Upgrade & Restart" in Web Settings > Remote Access
# Or force install latest version via CLI:
dsh plugin --profile web add @wenbin_wb/dsh-bridge@latest
🚀 Core Features & Usage Guide
Launch DeepSeek Harness, open Settings in the left sidebar, and click "Remote Access":
1. 🛜 LAN Access & Multi-NIC Smart Selection
Starts automatically with DSH service, zero configuration required.
- Instant QR Code Scan: Connect phone and PC to the same Wi-Fi, scan the QR code with phone camera to access mobile web UI;
- Multi-NIC Detection & Switching: Automatically detects multiple network interfaces (physical Wi-Fi, Ethernet, WSL, VMware, Docker) and presents "🛜 Network Interface / IP Selection" dropdown; instantly regenerates QR codes upon selection and persists choice across restarts.
2. 🌐 Public Tunnels (Cloudflare & Custom)
Access DeepSeek Harness from anywhere outside your home network without public IP or router port forwarding:
- Mode 1: Zero-Login Temporary Tunnel (Default):
- Click "Start"; automatically prepares
cloudflaredbinary with permission self-healing; - Instantly generates
https://*.trycloudflare.comURL and QR code.
- Click "Start"; automatically prepares
- Mode 2: Cloudflare Token Fixed Domain (Permanent · Free):
- Create a Tunnel in Cloudflare Zero Trust Console and bind your custom domain;
- Enter Tunnel Token & hostname in Advanced Settings, enable "Auto-start with DSH" for permanent fixed URL!
- Mode 3: Custom WebSocket Tunnel:
- Connect to your personal VPS reverse proxy server (View Setup Guide), equipped with per-message gzip and SSE optimization.
Custom tunnel security note: The tunnel server (
scripts/install-tunnel-server.sh) only authenticates the tunnel client control channel withTOKEN; public HTTP/WebSocket requests forwarded through the tunnel domain are not independently authenticated — security relies entirely on the plugin's local Access Auth (thex-dsh-internal-tunnelmarker prevents tunnel traffic from using the loopback exemption). Always enable Access Auth with a password/QR Token in the plugin settings (especially withscope=allor when exposed publicly); with no password set, anyone who knows the tunnel URL can reach your DSH.
3. 📱 Mobile Experience & Standalone PWA
Deeply optimized for mobile screens and touch interactions:
- Clean Top Header: Retains left drawer and right new session button, with centered dynamic session title;
- Native Sidebar Drawer: Full DSH history & workspace grouping with native
[|fold icon and swipe gestures; - Standalone PWA Support: Click "Add to Home Screen" in mobile browser to run as a 100% standalone fullscreen app;
- Anti-Overlap Responsive Layout: Bottom toolbar adapts to screen width, preventing button collision.
Mobile Chat & Workspace Experience
Remote Settings Center on Mobile
4. 🗂️ Web Remote Workspace Directory Picker
Solves the pain point of mobile browsers being unable to trigger PC native folder dialogs:
- Smart Routing: PC localhost visits (
127.0.0.1) invoke OS native file dialogs; mobile/remote visits pop up responsive bottom directory browser; - Quick Access: 1-click access to Windows drives (C:, D:) and standard system folders (Desktop, Documents, Downloads, Projects).
5. 🔐 Comprehensive Access Security & Admin Lock
Open "Security" tab to establish bank-grade protection for your local development environment:
1. 🛡️ Line 1: External Access Gateway
- QR Token Passwordless + Password Verification: QR codes carry 256-bit encrypted Token for instant access; manual IP/domain visits require password;
- Channel Isolation: Choose between "All Channels / Public Tunnels Only (LAN Passwordless) / LAN Only".
2. 🔒 Line 2: Admin Console Anti-Tamper Lock
- Independent Admin Password: Remote devices enter locked console, requiring admin password to view or modify tokens and bot configs;
- Strict Host Policy: Option to restrict management solely to host machine (
127.0.0.1).
3. 🛟 Triple Disaster Recovery (Never Locked Out)
- Host Physical Privilege: PC localhost (
127.0.0.1) enjoys permanent highest privilege, never locked; - Terminal Emergency Reset: Run
touch ~/.dsh/dsh-bridge/reset-authin terminal to reset passwords and security policy (takes effect on the next plugin start / DSH restart); - Interactive Guidance: Built-in interactive recovery guides on all auth pages.
6. 🤖 All-in-One IM Bot Matrix (WeChat / QQ / Feishu / Telegram)
Interact with local AI agents directly inside your favorite messaging apps without opening a browser:
🟢 WeChat Bot (ClawBot / iLink)
Scan QR code with personal WeChat account to chat, manage sessions, and approve permissions via official Tencent servers without public IP.
- Quick Setup: Remote Access > IM Bot > WeChat > Scan QR code > Send first message to auto-authorize. See WeChat Guide.
🐧 QQ Bot (OpenAPI v2)
Official QQ Bot with direct/group @chat, Markdown rendering, interactive button keyboards, and rich media transfers.
- Quick Setup: Create bot on QQ Open Platform, fill AppID & Secret > Send first message to auto-authorize. See QQ Guide.
🐦 Feishu (Lark) Bot (WebSocket 2.0)
Enterprise self-built app via official full-duplex WebSocket long connection—100% No Public IP / No Webhook required.
- Quick Setup: Create self-built app on Feishu Open Platform, enable long connection > Fill App ID & Secret. See Feishu Guide.
✈️ Telegram Bot (Bot API + Proxy Support)
Official Telegram Bot API with Long Polling and built-in zero-dependency HTTP/HTTPS proxy tunnel.
- Quick Setup: Create bot with @BotFather > Fill Bot Token (and optional proxy) > Send first message to auto-authorize. See Telegram Guide.
Standardized IM Commands
| Command | Description |
|---|---|
| (Direct Text) | Drives current active agent to think and code |
/sessions (or /list) |
List all sessions grouped by workspace |
/use N (or /resume N) |
Switch context to session number N |
/rename <new title> |
Rename active session title |
/workspaces |
List all registered workspaces in DSH |
/addworkspace <path> |
Remotely register a local project folder |
/new <prompt> |
Start a new session in current workspace |
/new <prompt> @N |
Start a new session in workspace N |
/stop |
Immediately abort current running task |
/end |
End and suspend active session |
/yes / /no (or 1/2) |
Respond to sensitive operation permission approvals |
/status |
View agent status and system summary |
/help |
View full command and shortcut button help |
7. 📊 Maintenance Dashboard & Graceful Restart
Open "Maintenance" tab to monitor health and manage operations:
- 📊 Host System Metrics Dashboard: Real-time CPU model, total/used RAM, Node heap memory, and DSH uptime;
- 🔍 1-Click Network Diagnostics: Diagnoses reverse proxy port, LAN IPv4, Cloudflare Anycast edge, and npm mirror latency;
- 🗄️ Configuration Backup & Migration: 1-click export/import of
.jsonconfiguration files; - 🔄 Graceful Smooth Restart: 1-click DSH service restart with automatic reconnect and page reload.
💬 FAQ
In one sentence: dsh-bridge is the remote access / remote control plugin (remote control) for DeepSeek Harness — scan a QR code and keep using your local DSH from phone or public internet. If you search "remote DSH plugins" or "how to remote control DSH", this is it.
- All-in-one: LAN QR + Cloudflare temp/fixed-domain tunnels + custom tunnel + WeChat / QQ / Feishu / Telegram bot matrix in one install;
- Mobile-first: mobile UI, PWA fullscreen, and a web remote workspace picker tuned for controlling desktop DSH from your phone;
- Built-in gate: QR Token + access password + admin anti-tamper lock for all LAN / tunnel traffic;
- Install name:
dsh plugin --profile web add @wenbin_wb/dsh-bridge, repowenbin-wb/dsh-bridge, also known asdsh-bridge remote access plugin / dsh-bridge remote control plugin.
- Wi-Fi Check: Ensure phone and PC are on the same Wi-Fi network with AP isolation disabled;
- Multi-NIC Switching: If WSL/VMware/VPN is enabled, switch to physical Wi-Fi/Ethernet IP in the "🛜 Network Interface / IP Selection" dropdown;
- Firewall: Ensure firewall allows Node.js on port
3082; - Use Public Tunnel: Enable Cloudflare Tunnel if crossing network segments.
- Strict Allowlist: Built-in sender allowlist; only authorized users can drive the Agent;
- Auto First Authorization: Admin sending the first message after login automatically binds to allowlist;
- Silent Drop: Unauthorized messages are dropped at the lowest layer (Never fed to LLM).
- Temporary (Default): Zero-login random
*.trycloudflare.comdomain, ideal for quick outdoor access; - Fixed (Token Mode): Uses Cloudflare Zero Trust Named Tunnel Token to bind your own domain with auto-start on boot.
- Persistent Configuration: All credentials, allowlists, and passwords persist in
~/.dsh-bridge/; - Session Context Recovery: Session history is persisted by DSH core engine; resume conversations with
/resumeanytime; - Backup & Migration: 1-click
.jsonexport/import in Maintenance tab.
🛠️ Development & Contribution
Contributions are welcome! Feel free to submit an Issue or Pull Request.
# 1. Clone repo
git clone https://github.com/wenbin-wb/dsh-bridge.git
cd dsh-bridge
# 2. Install dependencies & build
npm install
npm run build:client
# 3. Run unit tests
npm test
# 4. Link to local DSH Web Profile
dsh plugin --profile web add .
⭐ Star History
📄 License
MIT © wenbin-wb
Links
More in this category
zhu1090093659/dsh-web#packages/dsh-remote-web-ui★ 8488
Remote control of a dsh web workspace from phone or PC: QR-code pairing through a token-gated channel, SSE real-time sync, and separate mobile and full desktop GUI modes.
zhu1090093659/dsh-web#packages/dsh-ssh★ 8488
SSH ops panel for DSH: web terminal, SFTP transfer with progress, local port forwarding, and one-command cluster execution across hosts; agents share the same host config.
saya-ch/dsh-mobile★ 396
Access DeepSeek Harness from the Android app or a mobile browser with secure LAN and remote connections, persistent device pairing, and a customizable mobile interface.
ZSeven-W/dsh-ios★ 315
A live iOS Simulator or USB-connected iPhone inside the conversation: 22 agent tools for booting, building, driving the UI by accessibility identity or OCR text, list-row actions and SwiftUI preview hot reload, plus a streaming sidebar panel you can tap and drag on.
liguobao/ds-harness-remote★ 272
Multi-device remote access for DeepSeek Harness: continue an active session from your phone, tablet, browser, or another computer over an end-to-end encrypted channel (Noise IK + adaptive relay/WebRTC transport), with device authorization, ApiProxy-only remote capabilities, and read-only file preview via dsh-file-viewer — no shell, remote desktop, or write access.
ZSeven-W/dsh-android★ 170
A live Android device inside the conversation — emulator or USB phone, driven entirely through adb: 20 agent tools for streaming, Gradle build and run, UI-tree or OCR interaction, logcat, processes and memory, plus a three-button navigation panel.
Community comments
Comments are public GitHub Discussions. Loading them connects to GitHub and Giscus; a GitHub account is required to post.