juanwang-buaa/dsh-full-remote

Token reverse proxy: rewrite Host/Origin, remote recovery settings./credentials./host.listDirectory (universal tunnel will 403); one-time scan code invitation, session by device; npm dsh-full-remote

dsh-full-remote puts an authenticated reverse proxy in front of the DeepSeek Harness Web server, so the Web UI can be used through a public tunnel or from a device on the local network while privileged APIs such as settings, credentials, and directory browsing remain gated. The settings page (Settings → Reverse proxy) provides Start/Stop proxy controls, a copyable tunnel target, a live reachable-URL list, and a backendHost setting for the address the proxy connects to.

Infrastructure & Deployment ★ 19 updated 2026-09-19 — untested
View on GitHub ↗

Install

dsh plugin --profile web add dsh-full-remote

dsh plugin --profile web add dsh-full-remote then dsh --profile web; open http://127.0.0.1:3080, go to Settings → Reverse proxy, press Start proxy, and point a tunnel at the copied target (the README shows cloudflared tunnel --url http://127.0.0.1:3081 and ngrok http 3081 as examples only — the plugin does not execute them). For LAN devices, set the listen address to a LAN IP instead of a tunnel. The package was previously published as dsh-reverse-proxy; that legacy name is deprecated.

Compatibility

DeepSeek Harness plugin (awesome-dsh-plugin listed). Places an authenticated reverse proxy in front of the Harness Web server so the UI works through a public tunnel or LAN device while privileged APIs (settings, credentials, directory browsing) stay protected. Listen address binds 127.0.0.1 by default, LAN IP, or 0.0.0.0; changes persist across restarts with rollback on bind failure.

Details

Recent updates

The current README documents the install flow, Start/Stop proxy controls, listen-address options with rollback on bind failure, the tunnel target and reachable URL reporting, and the deprecated dsh-reverse-proxy legacy name.

FAQ

Is a tunnel required?
No — for devices on the same network, set the listen address to a LAN IP instead of using a tunnel (cloudflared/ngrok are shown as examples only).
Does it expose settings and credentials?
No — the README says the proxy protects privileged APIs such as settings, credentials, and directory browsing behind authentication.
Is this the same as dsh-reverse-proxy?
That was the legacy package name; the README says it is deprecated and dsh-full-remote should be installed for new deployments.

Alternatives

liguobao/deepseek-harness-remote · Yvesgao/dsh-desktop-launcher · happpsee/dsh-desktop-app

More plugins in Infrastructure & Deployment

Browse more in Infrastructure & Deployment

Guides for Infrastructure & Deployment plugins