The DeepSeek Harness (DSH) runtime interface is usually bound locally. To operate directly from mobile devices, existing solutions either rely on a feature-limited Companion app or require configuring complex tools such as SSH. The omdsh-remctrl plugin provides a more direct path: it creates a “second door” on DSH’s own port. It exposes the full DSH interface to the public internet through a reverse proxy and adds a passcode-based authentication layer in front. Through this entry point, a phone can monitor sessions, approve tool requests, and dispatch new work.

Plugin Positioning

  • Name: omdsh-remctrl
  • Owner: omdsh-plugins
  • Category: system
  • One-line description: Remote control for DeepSeek Harness: acts as a “second door” on the dedicated port, allowing a phone to monitor sessions, approve requests, and dispatch new work after device pairing and a tiered method whitelist.

Core Features

This plugin enables remote access through a reverse proxy layer. Its core capabilities include:

  1. Reverse proxy: Provides HTTP and WebSocket reverse proxy, forwarding traffic to Harness’s webServer and replicating the native full interface.
  2. Passcode authentication: Adds a passcode authentication gate at the proxy layer; the interface cannot be accessed without passing authentication.
  3. Automatic tunneling: Starts a cloudflared subprocess by default and automatically generates a public HTTPS address.
  4. Plugin Center integration: Provides card integration, allowing the plugin to be enabled or disabled through a toggle.
  5. Mobile optimization: Optimizes keyboard pop-up and sidebar expansion logic for mobile devices.
  6. Session management: Manages session cookies and sets HttpOnly and SameSite=Lax attributes.

Installation and Activation

The plugin is disabled by default and must be manually activated after installation.

  1. Install the plugin through the Plugin Center or by accessing the repository directly.
  2. In the DSH interface, locate the Plugin Center card and click the toggle to enable it.

Typical Usage

The core of the configuration is determining the public access address:

  1. Use the default tunnel:
    Leave the publicHost configuration item empty. The plugin starts a cloudflared quick tunnel and assigns an https://<uuid>.trycloudflare.com address. This method requires no domain or firewall configuration.

  2. Phone login:
    The plugin card displays the public address, a login link prefilled with the password, and the password itself. Send the link to the phone and click it; the browser automatically carries the password to complete login and redirects, without requiring manual password entry in the address bar.

  3. Use your own domain:
    If the machine already has a public address (such as harness.example.com), set publicHost in the configuration. Since this method uses HTTP, you must manually set allowInsecure at the proxy layer to allow the connection.

  4. Toggle control:
    Use the toggle on the Plugin Center card to enable or disable remote access at any time.

Security and Configuration

The plugin has very few configuration options, and security mainly relies on DSH’s own mechanisms:

  • Forwarding restriction: No requests are forwarded until a valid session cookie is resolved.
  • Rate limiting: Each address is limited to 6 authentication attempts per minute.
  • Transport encryption: Enforces HTTPS transport through the cloudflared tunnel.
  • No other configuration: The plugin does not provide any other configurable options.

Environment Requirements

The plugin depends on a Node.js runtime environment. The version must satisfy one of the following:

  • Node.js ^22.19.0
  • Node.js >=24.0.0

Short Conclusion

omdsh-remctrl provides native remote control capabilities for DSH. It is not a feature-limited Companion app; instead, it replicates the full DSH interface to the public internet through a reverse proxy and a Cloudflared tunnel. With the Plugin Center toggle and passcode, you can securely manage DeepSeek Harness sessions on any device.