Introduction

DeepSeek Harness (DSH) is a plugin-based system designed to provide flexible agent control capabilities. In local development or deployment scenarios, users typically need a Web UI to manage sessions and view output. The kevin66z0/dsh-telegram plugin provides DSH with a Telegram remote control entry point, allowing users to interact directly with the Agent from a mobile device, with support for session binding, real-time viewing of streaming replies, and quick actions.

Plugin Overview

This plugin is maintained by Kevin66Z0 and is released under the MIT license. It uses Telegram as a unified console and manages access permissions through an allowlist mechanism to ensure session security.

Core Features

  • Full session console: Supports binding sessions, viewing session details, sending text prompts, and displaying replies in real time by editing a single message.
  • Real-time streaming replies: Assistant output is streamed into the message through live editing, including the reasoning process and tool-call steps, and finalized as HTML.
  • Interactive question buttons: When the Agent invokes an interactive question, the interface generates clickable inline keyboards, allowing users to answer without typing text.
  • Quick keyboard: Provides a row of quick actions, such as /create (Create), /archive (Archive), /attach (Bind), and /stop (Stop).
  • Secure defaults: Uses an allowlist mechanism, so only authorized chat IDs can communicate with the bot, and all other access is denied with an access-denied message.
  • Tokens never touch the disk: The bot token is referenced from an environment variable (!!js process.env.TELEGRAM_BOT_TOKEN) and is not written directly into a configuration file.
  • Cold session recovery: Communicates through the Host’s apiProxy, supporting cold session recovery and queued message semantics.

Installation and Enablement

Environment Requirements

  • Node.js >= 22.19
  • An installed DeepSeek Harness source directory (recommended) or a running DSH deployment
  • A Bot Token obtained from @BotFather
  • Outbound access to api.telegram.org

Installation Steps

  1. Clone or download the plugin code.
  2. Run the Installation script to mount the plugin into the DSH directory:
./install.sh /path/to/deepseek-harness

Configuration Steps

  1. Set the environment variable: Inject the token into DSH_HOME/.env and set 600 permissions:
echo 'TELEGRAM_BOT_TOKEN=<token-from-@BotFather>' >> "$DSH_HOME/.env"
chmod 600 "$DSH_HOME/.env"
  1. Configure the allowlist: Configure the chat IDs that are allowed to access in $DSH_HOME/settings.yaml:
telegram:
  allowChatIds: [123456789]
  1. Restart the service: Restart the DSH service to make the configuration take effect.

Typical Usage

The plugin is operated through Telegram bot commands. The following is a list of the main commands:

  • /attach [scope|n|id|none|arc]: Bind the current chat to the specified session.
  • /create: Open the creation submenu.
  • /operate: Open the operations submenu.
  • /new [path|n|none]: Create a new session.
  • /fork [n|id]: Fork a session from the last completed turn.
  • /archive [n|id]: Archive the specified session.
  • /status [n|id]: View session details.
  • /model [name]: Set the global default model.
  • /rename [title]: Rename the currently bound session.
  • /preset [name|n]: Select a preset Agent configuration.

Security and Caveats

  • Allowlist restriction: The plugin denies all access by default, and allowChatIds must be specified in the configuration.
  • No inbound listening: The plugin does not listen on any inbound port and communicates only through outbound long polling to Telegram, making it suitable for use behind NAT.
  • Token management: The token is stored in an environment variable. If leaked, it can be quickly revoked and regenerated through @BotFather.
  • Dependency requirement: Node.js >= 22.19 is required.

Summary

dsh-telegram provides DeepSeek Harness with a secure, lightweight mobile control solution. Through Telegram, developers can manage Agent sessions on any device without relying on a Web UI. All sensitive operations, such as token storage and session binding, follow security best practices.

Plugin directory
GitHub repository