DeepSeek Harness allows running a local Web UI for agent development. By default, local services are limited to the computer. To access these interfaces on a phone, network tunneling or specific network configuration is required. The DSH plugin ecosystem provides a mechanism that makes local services visible to paired phones through an outbound Relay connection.
Plugin Information¶
- Name:
april-jk/dsh-mobile-plugin - Maintainer: april-jk
- License: MIT
- Core Value: Access the local DSH Web UI from a paired phone via an outbound Relay connection.
Installation¶
This plugin can be installed via the npm registry or a GitHub Release. Using a GitHub tag is recommended to ensure integrity.
- Run the following command to install the plugin (using the web profile as an example):
npx @deepseek-ai/dsh plugin --profile web add "github:april-jk/dsh-mobile-plugin#v0.1.9"
- Start DeepSeek Harness Web:
npx @deepseek-ai/dsh web
It can also be installed by downloading the .tgz package directly from a GitHub Release:
npx @deepseek-ai/dsh plugin --profile web add "https://github.com/april-jk/dsh-mobile-plugin/releases/download/v0.1.9/april-jk-dsh-mobile-0.1.9.tgz"
Pairing a Phone¶
After installation, a connection needs to be established on the phone.
- In the local DSH Web UI, go to Settings > Remote Access.
- Use the iPhone camera or the DSH Mobile app on your phone to scan the QR code on the screen.
- Note: The QR code’s URL fragment contains a one-time code and encryption key, which is more secure than a plain six-digit numeric code. If the QR code has expired or the device may have been compromised, you should pair again.
Removing a pairing can be done from the settings page in the Web UI, or by using the command-line tool dsh-mobile unpair when the Web UI is unavailable.
Network and Data Behavior¶
- Connection Mode: The DSH process binds to
127.0.0.1:3080, and the plugin does not create public listeners. The computer initiates an outbound connection to the Relay server (defaulthttps://relay.dshmobile.online). - Encryption: HTTP, SSE, and WebSocket payloads are encrypted end-to-end with AES-256-GCM between the mobile Companion and the local plugin. The Relay server only forwards sealed frames.
- Token Storage: Relay device tokens are stored in the local file
~/.dsh-remote/config.jsonand are not sent to the phone client. - Data Logging: The Relay server logs the bound phone metadata and access time, but does not persist DSH request or response bodies.
Dedicated Command-Line Tool¶
After installation, the dsh-mobile command is available as a fallback CLI tool. It supports the following operations:
dsh-mobile start: start the connectiondsh-mobile pair: pair a devicedsh-mobile unpair: unpair a devicedsh-mobile status: view statusdsh-mobile check-update/update: check for and update the plugin (local operations)
Notes¶
- Environment Requirements: Node.js 18 or later is required, and the DeepSeek Harness version is
0.1.0-rc.6. - Security: Version 0.1.9 uses a pre-shared key preconfigured via QR and does not provide forward secrecy. If the QR code or endpoint may have been compromised, unpair immediately and pair again.
- Private Relay: If you need to use a private Relay server, set the environment variable
DSH_RELAYwhen starting DSH. - Permissions: The plugin runs with the permissions of the current DSH process. Review the source code and license before installation.