Preface¶
DeepSeek Harness (DSH) adopts a plugin-based architecture. When connecting DSH instances to third-party platforms (such as SlashX) that follow the slashx.request.v1 and slashx.response.v1 protocols, adapters are usually required. The dsh-plugin-slashx-gateway plugin directly implements this protocol, enabling DSH instances to operate as a spec-compliant gateway service and provide secure, reliable media intake and artifact egress.
Plugin Overview¶
This is a DeepSeek Harness Host Bundle. It exposes Harness instances as SlashX endpoints that follow the slashx.cn protocol, and provides secure media intake and artifact egress for text, images, files, audio/video, citations, cards, and buttons.
Basic Information
* Plugin Name: dsh-plugin-slashx-gateway
* Maintainer: superslash-rico
* Version: 0.1.0
* License: MIT
* Compatibility: DeepSeek Harness >=0.1.0-rc.6 <0.2.0
Core Features¶
The plugin implements the following capabilities:
- Request Processing: Accepts text, images, files (PDF/Office/text/code), and audio/video.
- Response Processing: Supports citations and button clicks, Markdown responses, and rich media responses.
- Asynchronous Callbacks: Supports
extensions.slashxAsync, one-time callback tokens, polling, and cancellation endpoints. - Security Mechanisms: Performs DNS/redirection SSRF checks on URLs and validates Base64 media to prevent security vulnerabilities.
Installation and Enablement¶
Environment Requirements¶
- Node.js 22.19+
- The official Harness
webprofile is required (providesctx.apiProxy). Do not install into aheadlessprofile that lacks ApiProxy.
Installation Steps¶
- Ensure the official DeepSeek Harness package is installed.
- Install the plugin using the web profile:
dsh plugin --profile web add dsh-plugin-slashx-gateway
- Confirm that the plugin has been loaded:
dsh web --dump-config
Configuration¶
Set the environment variables to start the gateway. A random access token of at least 32 characters is required:
export SLASHX_GATEWAY_TOKEN="$(openssl rand -base64 32)"
export SLASHX_GATEWAY_STATE_ROOT="/srv/deepseek-harness/slashx-gateway"
export SLASHX_GATEWAY_PUBLIC_BASE_URL="https://harness.example.com"
dsh web
By default, the gateway listens on 127.0.0.1:3090.
Typical Usage¶
Reverse Proxy Configuration¶
In production, it is recommended to terminate TLS with Caddy or Nginx, expose only the gateway port, and avoid directly exposing the native Harness API.
harness.example.com {
reverse_proxy /slashx-provider/* 127.0.0.1:3090
reverse_proxy /healthz 127.0.0.1:3090
}
SlashX Connection Configuration¶
Create a “Self-hosted HTTP Service” connection on the SlashX platform and point it to the gateway address:
* Endpoint: https://harness.example.com/slashx-provider/v1/run
* Auth: Bearer Token (same as SLASHX_GATEWAY_TOKEN)
* Async callback: Recommended to enable, for long-running tasks or large-file processing
* Timeout: Should be no less than the expected execution time of the gateway for synchronous tasks
Rich Media Response Tool¶
The plugin registers the slashx_deliver tool with Harness. Agents can call this tool to return rich media content.
Parameter Example:
{
"runId": "11111111-1111-4111-8111-111111111111",
"text": "## 分析完成\n报告和预览如下。",
"images": [
{
"localPath": "output/preview.png",
"mimeType": "image/png",
"fileName": "preview.png"
}
],
"attachments": [
{
"localPath": "output/report.pdf",
"mimeType": "application/pdf",
"fileName": "report.pdf",
"attachmentType": "document"
}
],
"citations": [
{
"index": 1,
"title": "数据来源",
"url": "https://example.com/source"
}
],
"cards": [
{
"type": "summary",
"title": "处理结果",
"fields": [{ "label": "状态", "value": "已完成" }]
}
],
"actions": [
{ "label": "继续处理", "kind": "send_message", "value": "继续处理" },
{ "label": "打开来源", "kind": "open_url", "value": "https://example.com/source" }
],
"conversationUpdate": { "title": "文件分析结果", "modeTag": "done" }
}
Applicable Scenarios and Notes¶
- Profile Restriction: The
webprofile must be used, because the plugin depends onctx.apiProxy. - SSE Restriction: The current version (0.1.0) does not support token-by-token text SSE; use asynchronous callbacks for long-running tasks.
- Model Dependency: Media generation and understanding capabilities depend on the actual models and tools installed in Harness.
- Client Capabilities: The plugin honors client-declared capabilities such as
streamandmarkdown; if the client does not support rich components, it degrades to attachments or Markdown. - Restart Behavior: After the gateway restarts, if a run is found with only a
runningrecord, it returnsRUN_OUTCOME_UNCERTAINand does not automatically re-execute. - Billing Attribution: Supports per-run (
flat_per_run) and per-token (pass_through) billing. With per-token billing,reasoningTokensis not added to output tokens to avoid double billing.
Conclusion¶
This plugin provides standard SlashX protocol integration capabilities for DeepSeek Harness, making it suitable for scenarios that require deployment and interaction through the SlashX ecosystem.