dsh-web-startup-auth: Secure Remote Web Startup and Login Authentication for DeepSeek Harness

gdwhisper/dsh-web-startup-auth

Integrations & ConnectionsVerified
Listed on 2026-08-23
Page last updated 2026-10-04

A DSH plugin enabling remote web launch with username/password auth for secure browser access.

dsh-web-startup-auth is a remote web startup and authentication plugin for DeepSeek Harness. It replaces the original launcher's hard rejection of --host 0.0.0.0, allowing dsh web to securely expose the browser interface on LAN or non-loopback interfaces. The plugin provides a login/registration page, session authentication, API protection, and settings panel integration. Local access is passwordless, while remote access requires credentials. It solves the problem of unauthenticated remote access and exposed sensitive APIs. Maintained by GDWhisper under the MIT license.

How to Install

install
npmdsh plugin --profile web add dsh-web-startup-auth
Category
Integrations & Connections
Platform
DSH Plugin
Author
gdwhisper
Distribution
Plugin

dsh-web-startup-auth Key Features

Remote launchLogin/register pageSession authAPI protectionAuth tab in settings
Listed on dsh-plugin.org

dsh-web-startup-auth Repo Summary

What Does It Do?

dsh-web-startup-auth is a DSH plugin for DeepSeek Harness that enables remote web startup with username/password authentication. It replaces the original launcher's hard rejection of --host 0.0.0.0, allowing dsh web to securely expose the browser interface on LAN or non-loopback interfaces. It solves the problem of unauthenticated remote access and exposed sensitive APIs by providing a login/registration page, session authentication, API protection, and settings panel integration. Maintained by GDWhisper under the MIT license, last updated in 2026-08.

Core Features

  • Remote startup: supports --host 0.0.0.0, replacing the original launcher's hard rejection.
  • Login/registration page: first remote access guides setting up admin credentials, then shows login page, matching DSH style.
  • Passwordless local access: authentication is skipped only when both TCP peer address and Host header are loopback, so local access needs no login.
  • Session authentication: issues signed cookie (dsh_sid, valid 14 days, HttpOnly + SameSite=Lax).
  • API protection: all registered routes (except /api/auth/* and /login) require a valid session, otherwise return 401.
  • Settings panel "Authentication" tab: provides logout and change password actions.

How to Use This Plugin?

After enabling it in DSH, start dsh web --host 0.0.0.0 and visit http://<server-ip>:/ in a browser. On first remote access, you'll be redirected to /login to set up admin credentials; after registration, you're automatically logged in and enter the main interface. Local access via http://127.0.0.1:/ requires no login. To log out or change password, use the "Authentication" tab in the settings panel, or call /api/auth/logout to clear the session. If you forget your password, run dsh --profile web auth-reset on the server to interactively set a new one; the reset rotates the session key and invalidates all sessions.

This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: gdwhisper/dsh-web-startup-auth. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.

Install, update, and uninstall this plugin in the Plugin Market of DeepSeek Harness's DSH Plugin Hub

DSH Plugin FAQ