What Is dsh-pocket? Access DeepSeek Harness on Your Phone

GuidePublished 2026-08-30Author: DeepSeek Plugin Market
dsh-pocketmobile accessDeepSeek Harnessguide
dsh-pocket is a DSH plugin for DeepSeek Harness that streams the DSH interface to your phone via a QR code, over LAN or a public cloudflared tunnel.

dsh-pocket is a mobile access plugin in the DeepSeek Harness (DSH Plugin) ecosystem: run dsh web on your computer, scan a QR code with your phone, and you can view and control the same DSH interface in real time — from the LAN or anywhere via a public tunnel, with no remote desktop or SSH required. Based on the official README, this article covers what it is, its core features, installation and enabling, LAN and public QR usage, and common troubleshooting.

What Is dsh-pocket?

dsh-pocket solves the "away from your computer but still want to use DeepSeek Harness" problem: install it, scan a QR code with your phone, and you can see and control the DSH interface on your computer in real time, with both LAN and public access. The positioning and facts below all come from the official README (source):

dsh-pocket is maintained by shaobeichen and open-sourced under the GPL-2.0 license. The use cases are straightforward: an agent is running tasks on your computer on the way home and you want to check its progress from your phone; you are out and want the agent on your computer to look something up or write code, but you have no remote desktop and no SSH. dsh-pocket puts DeepSeek Harness "in your pocket" — one npm package, one settings page, with the phone UI synced to the computer in real time. It installs with zero dependencies, needs no account and no server: LAN mode uses a QR code on the same WiFi, and public mode generates a QR code through a cloudflared tunnel, reachable from a 4G network.

What Are the Core Features of dsh-pocket?

The core capability of dsh-pocket is putting DSH in your phone: instant LAN QR access, public tunnel access from anywhere, an optional fixed domain, independent access passwords, session persistence with real-time sync, plus transfer compression and automatic tunnel recovery. These capabilities all come from the official README (source):

  • Instant LAN QR access: after install, open Settings → Phone Access; a phone on the same WiFi scans the LAN QR code to open instantly. It auto-detects the local IP and picks the Windows physical NIC IP under WSL; LAN access can be toggled off in one click, which immediately invalidates the QR code and link.
  • Public QR access: click "Enable Public Access" → cloudflared tunnel → a public QR code reachable from 4G or any network; the tunnel auto-restarts after a DSH restart.
  • Fixed public domain: optional "Named Tunnel" mode using a Cloudflare Tunnel Token plus your own domain, keeping the public address stable across restarts.
  • Access password protection: public links require an 8-digit password (rotated by default on each enable, customizable to a fixed one); LAN has its own independent 8-digit password (enabled by default, can be turned off for one-click QR connect).
  • Session persistence and real-time sync: after entering the password once, the phone stays logged in (bound to the dsh web process on the computer); streaming output passes through WebSocket with full transparency, bidirectional control, heartbeat keepalive, and auto-reconnect.
  • Transfer compression: large JSON responses are automatically gzip/brotli compressed, reducing a 17MB long session to about 1MB for faster, cheaper mobile loading.

How to Install and Enable dsh-pocket?

Installing dsh-pocket requires a single dsh plugin command into the current profile; after restarting dsh web, a "Phone Access" entry appears in Settings for QR access; update and uninstall also go through the DSH CLI. The commands and facts below all come from the official README (source):

1. Install dsh-pocket: run the install command in the DeepSeek Harness terminal. If dsh: command not found is reported, first install the CLI globally:

bash
npm install -g @deepseek-ai/dsh     # global install; verify with: dsh --version

Then run the install command:

bash
dsh plugin --profile web add dsh-pocket -w

Wait for the command to report a completed install.

2. Restart dsh web and enable: restart dsh web after install so the plugin loads:

bash
npx @deepseek-ai/dsh web

After the restart, open Settings — the "Phone Access" entry appears in the left sidebar (alongside General Settings and Models), and you can scan the QR code to access.

3. Update dsh-pocket: update with the --latest flag (--latest is required across major versions, since a ^0.x range never auto-upgrades to 1.x):

bash
dsh plugin --profile web update dsh-pocket --latest -w

Restart dsh web after the update for it to take effect.

4. Uninstall dsh-pocket: remove the plugin from the current profile:

bash
dsh plugin --profile web remove dsh-pocket

After uninstall, the phone QR links stop working.

Typical dsh-pocket Usage

Typical dsh-pocket usage is "run dsh web on the computer, scan a QR code on the phone": LAN mode suits the same WiFi, public mode suits being away, and a named tunnel suits a stable public address. (source) The four steps below cover daily usage from LAN to a fixed public domain.

1. LAN access: connect your phone to the same WiFi as the computer, open Settings → Phone Access, scan the "LAN" QR code and enter the LAN password; what opens is the DSH interface on your computer, synced in real time (the password is shown in the LAN section — refresh to rotate it or customize a fixed 8-digit one; if you are the only user, you can disable the password for direct connect).

2. Public access: on the Phone Access page, click "Enable Public Access". A security disclaimer pops up each time — check "I have been informed" to continue; wait for the tunnel to establish (cloudflared downloads on first use), then scan the "Public" QR code with your phone and enter the 8-digit password (rotated on each enable by default, customizable to a fixed one). You can then access it anywhere, even from 4G or a corporate network.

3. Configure a fixed public domain: the default quick tunnel address changes on every restart (random prefix); for a stable public address, use a Cloudflare named tunnel: create a Tunnel in Cloudflare Zero Trust (Networks → Tunnels) and copy the Tunnel Token → in the Public Hostname, point your domain (e.g. pocket.example.com) to http://127.0.0.1:3081 → back on the settings public section, switch to "Named Tunnel" mode, paste the token, enter the domain, save, and enable public access — the address stays fixed.

4. Custom port (optional): if the default port 3081 is taken, write "proxyPort": 3082 in $DSH_HOME/dsh-pocket/settings.json and restart dsh web; the CLI mode uses dsh-pocket --port 3082:

bash
dsh-pocket --port 3082

dsh-pocket Troubleshooting

The four most common dsh-pocket issues are public error 1033, no UI change after install, a taken port, and a version stuck at 0.x, fixed respectively by disabling proxy TUN mode, restarting dsh web, killing the old process, and updating with --latest. (source)

1. Public access shows error 1033 (Tunnel error): symptom: opening the public address on the phone reports error 1033; the most common cause is a local proxy/VPN (Clash, Surge, v2ray, sing-box, especially TUN mode) cutting the cloudflared tunnel edge connection. Fix: first only disable TUN mode (turn off the "TUN Mode" switch in Clash); if it still fails, fully quit the proxy software; then add direct rules for argotunnel.com; if the network is still unreachable, switch to phone hotspot + LAN mode, which works the same.

2. Nothing changes after install or update: symptom: the "Phone Access" entry is missing or features look stale; cause: the running process still loads the old code. Fix: you must restart dsh web for the change to take effect.

3. listen EADDRINUSE ... :3081: symptom: startup reports the port is already in use; cause: an old dsh-pocket process still occupies port 3081. Fix: kill the old process holding the port and retry:

bash
lsof -ti :3081 | xargs kill -9

4. Version stuck at 0.x: symptom: a plain update command does not bump the version; cause: the ^0.x dependency range never auto-upgrades to 1.x. Fix: the update command must include --latest (dsh plugin --profile web update dsh-pocket --latest -w).

Use Cases and Notes

dsh-pocket fits every scenario where you need DSH while away from your computer, but it exposes code-executing DSH to the network: public access enforces a disclaimer and an 8-digit password with login rate limiting, and should not be enabled on sensitive networks. (source)

Use cases: checking agent task progress and results on the way home; sending tasks, watching output, and clicking approvals for the agent on your computer while out; keeping the computer in the dorm or office and controlling it from anywhere. Notes:

  1. DSH can execute code on your computer — never share the LAN QR code, URL, or password with others; LAN access is limited to devices on the same network.
  2. Public access pops up a security disclaimer every time and it must be checked (server-enforced and cannot be bypassed); use a strong password, turn it off after use, and avoid it on sensitive networks.
  3. Login rate limiting guards against brute force: 5 consecutive failures from the same IP lock it for 60 seconds; the public check is fail-closed — any unfamiliar domain other than loopback and LAN private addresses (including your own tunnel pointing at the local port) is treated as public and forced to use the public password.
  4. The DSH Desktop advanced mode does not support phone access yet (the phone shows a white screen); switch back to compatibility mode and restart.

dsh-pocket is an open-source project maintained by shaobeichen under the GPL-2.0 license. Plugin details: dsh-pocket plugin details.

This page is an independent guide rewritten from the plugin's official README — for the authoritative documentation and the latest changes, defer to the source: shaobeichen/dsh-pocket. A plugin is third-party code that runs on your machine once installed; inclusion is not an endorsement — review the source before installing.

FAQ

After scanning the LAN QR code with dsh-pocket, the phone asks for a password. How do I disable the LAN password in DSH plugin?

To disable the LAN password, open dsh-pocket's Settings → Phone Access and toggle the 'LAN access password' switch to 'Off'. After that, scanning the QR code on the same WiFi connects directly without a password, but only devices on the same LAN can access; public access always requires a password. Toggle it back on to restore.

The public access password of dsh-pocket changes every time I enable it. How do I set a fixed password?

dsh-pocket lets you set a fixed public password: in the public access section of the settings page, click 'Customize' and enter your desired 8-digit password (uppercase/lowercase letters or digits). After customizing, the public password no longer rotates automatically and stays the same even with a fixed domain, which is easier to remember.

How do I configure a fixed public domain for dsh-pocket? Do I need a Cloudflare account?

Configuring a fixed public domain in dsh-pocket requires a Cloudflare account and your own domain: create a named tunnel in Cloudflare Zero Trust under Networks → Tunnels, copy the Tunnel Token, and point your domain's Public Hostname to the local port. Then switch to 'Named Tunnel' mode in the settings public section, paste the token, enter the domain, save, and enable public access.

dsh-pocket asks me to check the disclaimer for public access, but it still won't enable after checking. Why?

dsh-pocket enforces the public access disclaimer: every time you enable public access, you must check 'I have been informed' to continue; the server enforces this and cannot be bypassed. If it still doesn't enable after checking, verify that cloudflared is installed (it downloads automatically on first enable) or check for error messages on the settings page.

In DeepSeek Harness, dsh-pocket asks for the password again after a while on the phone. How do I stay logged in for a long time?

The dsh-pocket phone login state is tied to the dsh web process on your computer: as long as dsh web does not restart, the phone stays logged in. If you restart or update dsh web, you need to enter the password once more; if a network change drops the connection, the built-in heartbeat and auto-reconnect will try to restore, but you may need to scan the QR code again.

dsh-pocket can't connect via LAN QR code in WSL environment. How to fix it?

dsh-pocket automatically picks the Windows physical NIC IP in WSL, so manual setup is usually unnecessary. If it fails to detect a reachable address (e.g., with Tailscale/VPN), you can manually select a detected IP from the 'LAN address' dropdown on the settings page, and make sure the phone and computer are on the same WiFi.

Related Terms

dsh-pocket
dsh-pocket is a mobile access plugin for DeepSeek Harness (DSH) that lets you view and control the DSH interface on your computer by scanning a QR code with your phone.— dsh-pocket README
LAN access password
The LAN access password is dsh-pocket's independent 8-digit password for same-WiFi QR access, enabled by default and toggleable off in settings for direct connect.— dsh-pocket README
Public QR code
The public QR code is dsh-pocket's public access entry generated through a cloudflared tunnel; scanning it from any network (including 4G) and entering the 8-digit password opens the DSH interface on your computer.— dsh-pocket README
Named tunnel
A named tunnel is dsh-pocket's fixed public address solution, created in Cloudflare Zero Trust and bound to your own domain so the public address stays stable across restarts.— dsh-pocket README
cloudflared
cloudflared is Cloudflare's tunnel client that dsh-pocket uses to establish a public tunnel and generate the public QR code; it is downloaded automatically the first time you enable public access.— dsh-pocket README

Sources

View all articles