dsh-remote: A Remote Access Security Plugin for DeepSeek Harness

xgone/dsh-remote

Integrations & ConnectionsVerified
Listed on 2026-08-20
Page last updated 2026-10-04

Secure remote access for DeepSeek Harness: account/password auth, MFA (TOTP) gate, role-based access, and in-browser directory picker, enabling safe external exposure of dsh web.

dsh-remote is a remote access security plugin built for DeepSeek Harness, adding account/password authentication and MFA (TOTP) two-factor verification to the DSH web interface, enabling secure remote use of full features from external browsers. It solves the problem of DSH's privileged APIs being locked to loopback and the lack of an authentication layer for remote deployments. Core capabilities include a login gate, role-based permissions, MFA, remote directory selection, and multilingual/theme support.

How to Install

install
npmdsh plugin --profile web add @xgone/dsh-remote
Category
Integrations & Connections
Platform
DSH Plugin
Author
xgone
Distribution
Plugin

dsh-remote Key Features

Password authMFA two-factorRole-based accessIn-browser pickeri18n support
Listed on dsh-plugin.org

dsh-remote Repo Summary

What Does It Do?

dsh-remote is a DSH plugin for DeepSeek Harness that adds account/password authentication and MFA (TOTP) two-factor verification to the DSH web interface, enabling secure remote access from external browsers. It solves the problem of DSH's privileged APIs being locked to loopback and the lack of an authentication layer for remote deployments. The plugin also replaces the native directory picker with an in-browser dialog. Core capabilities include a login gate, role-based permissions, MFA, remote directory selection, and multilingual/theme support.

Core Features

  • Complete login gate: unauthenticated access to any path redirects to a self-contained login page; /api and WebSocket require valid session cookies.
  • Secure sessions and password storage: HMAC-SHA256 signed HttpOnly cookies, scrypt-hashed passwords, and rate limiting on failed logins (IP+username).
  • MFA two-factor verification: compatible with standard authenticators like Google Authenticator, supports QR code binding, backup codes, and admin recovery.
  • Role-based access: admin-only mode by default; can be disabled to enable admin/user/guest method-level permissions.
  • Remote directory picker: replaces the native OS dialog with an in-browser two-pane directory browser with breadcrumbs and folder creation.
  • Multilingual and theme following: UI supports Chinese and English, automatically follows DSH's language and light/dark theme settings.

How to Use This Plugin?

After enabling the plugin in DSH and restarting dsh web, the first visit enters a bootstrap mode where only the local machine can create the initial admin account. Once set up, external browsers accessing via a reverse proxy will see a login page requiring credentials and, if MFA is enabled, a time-based one-time code. After login, users can use all features including workspace selection and adding workspaces. When the session expires, a full-screen re-login overlay appears. Admins can manage accounts, reset passwords, and enable or disable MFA from the settings page.

This page is an independent rewrite of the plugin's official README — for authoritative documentation and the latest changes, refer to the source: xgone/dsh-remote. The plugin is third-party code that runs on your machine once installed; inclusion does not imply endorsement — please review the source before installing.

Install, update, and uninstall this plugin in the Plugin Market of DeepSeek Harness's DSH Plugin Hub

DSH Plugin FAQ