DeepSeek Harness (DSH) uses a plugin-based architecture. Binding the official Web UI to 0.0.0.0 creates a remote code execution risk, while binding it to 127.0.0.1 prevents phone access. The dsh-ios-control plugin securely exposes the official UI to the LAN by running an authenticated reverse-proxy gateway on a separate port, enabling phone QR-code remote control of the agent on the PC.

Plugin Positioning

This is a personally customized plugin based on dsh-remote-link (MIT License), maintained by developer Hjay1101. It mainly addresses the question of “how to control a DSH agent from a mobile device without sacrificing security.”

Core Features

  1. Phone QR-code control: One-time pairing via QR code or short code; phone browsers can directly open the official UI for control.
  2. Session persistence: With pairing.persistSessions enabled, paired devices remain logged in after a DSH process restart.
  3. Session fork tool (fork_session): The model can call this tool to create a child session using the most recent turn as the boundary, inheriting context without affecting the current session.
  4. Link keep-alive: To address the lack of heartbeat in DSH downstream event streams, the gateway injects WS ping messages when idle, preventing connections from being silently dropped by carrier NAT.
  5. Status monitoring: Provides a /status page that displays real-time connection RTT, device identity, upstream health, and keep-alive counts.
  6. Device management: Supports viewing the list of connected devices, kicking old devices, or generating new pairing codes.
  7. MiMo Code support: Can act as an authentication gateway, converting the mobile UI of the MiMo Code service into a form controllable from a phone.
  8. Authentication gateway: Based on a loopback reverse proxy, provides HMAC challenge-response authentication and HttpOnly cookie session management.

Installation and Activation

Install the plugin via the official CLI:

dsh plugin --profile web add ./dsh-ios-control

After installation, the plugin takes over the DSH Web profile and adds a remote-link configuration item to the configuration file. The default binding address is 0.0.0.0, and the port is 3081.

Typical Usage

Pair a device: Enter a command in the chat box to obtain one-time pairing information.

Input: give me a pairing code
Output: Includes the QR code URL, an ASCII QR code image, and a 6-digit short code.

Manage devices: Query or clean up paired devices.

Input: show who has connected to me / kick my old iPad
Tool: remote_devices

Create a child session: Try a different conversation branch.

Input: fork it and try another direction
Tool: fork_session

Manual pairing: If the phone cannot scan the QR code, open the pairing address on any device.

Access: http://<IP>:3081/pair and enter the short code.

View status: View link health in a desktop browser.

Access: http://127.0.0.1:<port>/status

Use Cases and Notes

This plugin suits developers who need to debug or interact with a locally running DSH agent anytime and anywhere.

Security limitations:
* Based on HTTP transport, LAN sniffers can copy the cookie to hijack the session (HTTP ceiling).
* If the gateway is bound to a non-loopback address, has no password, and pairing is disabled, it refuses to load.
* The pairing secret exists only in the URL fragment; the server stores only the SHA-256 digest, which expires after 5 minutes.

MiMo mode:
* In MiMo Code mode, management tools in the chat box (such as remote_qr, fork_session) are unavailable; pairing is handled by the /qr page.

Dependencies and runtime:
* Zero runtime dependencies and a pure Node.js implementation.
* When persistSessions is set to true in the configuration file, session summaries are written with 0600 permissions to the $DSH_HOME/remote-link/ directory.