dsh-full-remote: An Authenticated Reverse Proxy Plugin for DeepSeek Harness

juanwang-buaa/dsh-full-remote

Integrations & ConnectionsVerified
Listed on 2026-08-17
Page last updated 2026-10-04

dsh-full-remote provides an authenticated reverse proxy gateway for DeepSeek Harness, enabling mobile QR access, per-device sessions, and Host/Origin rewrite for secure remote access.

dsh-full-remote is a remote access plugin for DeepSeek Harness that places an authenticated reverse proxy in front of the Harness Web server, enabling the Web UI to be used through a public tunnel or from a local network device while keeping privileged APIs like settings, credentials, and directory browsing available. It solves the problem that DeepSeek Harness only accepts loopback requests, causing privileged endpoints to return 403 when accessed via a generic tunnel. The plugin rewrites Host/Origin headers and provides its own access-control layer to replace the original trust check. Core capabilities include token/device-session authentication, header rewriting, HTTP/SSE/WebSocket forwarding, and an optional Cloudflare quick tunnel.

How to Install

install
npmdsh plugin --profile web add dsh-full-remote
Category
Integrations & Connections
Platform
DSH Plugin
Author
juanwang-buaa
Distribution
Plugin

dsh-full-remote Key Features

Mobile QR remote accessPer-device session managementHost/Origin rewriteCredentials and settings protection
Listed on dsh-plugin.org

dsh-full-remote Repo Summary

What Does It Do?

dsh-full-remote is a DSH plugin for DeepSeek Harness that places an authenticated reverse proxy in front of the Harness Web server, enabling the Web UI to be used through a public tunnel or from a local network device while keeping privileged APIs like settings, credentials, and directory browsing available. It solves the problem that DeepSeek Harness only accepts loopback requests, causing privileged endpoints to return 403 when accessed via a generic tunnel. The plugin rewrites Host/Origin headers and provides its own access-control layer to replace the original trust check. Core capabilities include token/device-session authentication, header rewriting, HTTP/SSE/WebSocket forwarding, and an optional Cloudflare quick tunnel.

Core Features

  • Authenticated reverse proxy: requests are accepted only with an access token, a one-time invite, or a valid device session; unauthenticated requests never reach the backend.
  • Host/Origin rewrite: rewrites headers to loopback so privileged APIs pass Harness's trust check.
  • Multi-protocol forwarding: supports HTTP, SSE, and WebSocket; compressible HTTP responses (HTML/JS/CSS/JSON/SVG, ≥1 KB) may be gzipped, while SSE and WebSocket are not.
  • Settings panel: start/stop the proxy, change listen address, rotate token, and manage device sessions under Settings → Reverse proxy.
  • Optional Cloudflare quick tunnel: generates a one-time QR invite that never contains the standing access token.
  • Tunnel compatibility: works with SSH, frp, ngrok, Tailscale, cloudflared, or any managed tunnel pointing at the local endpoint.

How to Use This Plugin?

After enabling the plugin in DSH, go to Settings → Reverse proxy, press Start proxy to launch the local proxy, then press Start Cloudflare quick tunnel to generate a QR code and scan it with your phone. For a controlled network, point an existing SSH, frp, ngrok, Tailscale, or cloudflared tunnel at the proxy target shown in the panel. To adjust behavior, change the listen address, rotate the token, or manage device sessions in the settings panel.

This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: juanwang-buaa/dsh-full-remote. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.

Install, update, and uninstall this plugin in the Plugin Market of DeepSeek Harness's DSH Plugin Hub

DSH Plugin FAQ