The official dsh web listens only on 127.0.0.1 by default, so mobile apps cannot connect directly. The dsh-mobile-gateway plugin solves this problem. It overrides the webserver configuration to change the server address to 0.0.0.0 and mounts a token-gated /m/api prefix route for mobile apps.

Core Features

This plugin mainly provides the following capabilities:

  • Server listens on all network interfaces: Overrides configuration via cordis.patch.yml, without modifying source code or recompiling.
  • Mobile access to all RPCs: Mounts a /m/api route alongside the official /api, validates the token, and forwards in-process to the official apiProxy, without touching the official security boundaries.
  • Real-time message push: Provides WebSocket downlink streams at /m/api/events.mux and /m/api/events.host, with frame format consistent with the official implementation.
  • Approval/question response: Provides a direct path to the official respond channel through the /m/api/respond endpoint.
  • Large image sending: Increases the request body limit and supports 500 MB message images.
  • Admin page: Provides the /m/ path, restricted to local access only. Used to generate/rotate tokens, generate pairing QR codes per network interface, and manage the device list and blocking.
  • Sidebar entry: Displays a phone icon at the bottom of the official Web GUI sidebar (next to Settings). Clicking opens the admin page in a popup or new tab.
  • QR scanning pairing: The QR code encodes server\|token, and the companion app fills it in automatically after scanning.

Installation

Install the plugin using the official CLI:

dsh plugin --profile web add github:agent-mobile/dsh-mobile-gateway

Configuration

After installation, a token must be configured. The token is required, while the other fields have default values. There are two configuration methods:

Method 1: profile patch

Edit ~/.dsh/profiles/web/cordis.patch.yml:

- id: mobile-gateway
  config:
    token: 换成一个长随机串
    allowSettings: true        # 放行 settings.*,默认 true
    allowCredentials: true     # 放行 credentials.*,默认 true
    maxRequestBodyBytes: 750000000

Method 2: Web GUI

Modify it in the Web GUI under “Settings → Plugin Configuration → mobile-gateway”; hot reload is supported.

Configuration Field Description

Field Default Description
token (required) The app presents it as Authorization: Bearer <token>; if left empty, the plugin refuses to start
allowSettings true Allows settings.describe/update/replace/mutate
allowCredentials true Allows credentials.describe/set/unset
maxRequestBodyBytes 750000000 Request body limit per request (must be increased in sync with the official connection limit)

Startup and Usage

After configuring, simply start dsh web:

dsh web

After startup, the terminal prints the LAN address (for example LAN: http://192.168.1.5:3080). The mobile app (requires v1.0.35+) connects through that LAN address while on the same Wi-Fi, and includes Authorization: Bearer <token> in the request headers.

App Endpoint Mapping

The app must change the request prefix from the official /api to /m/api:

  • Official direct connect: POST /api/<method>
  • This plugin route: POST /m/api/<method>
  • Official WebSocket: ws://…/api/events.mux
  • This plugin WebSocket: ws://…/m/api/events.mux

Notes

  • Version requirements: Verified compatible with @deepseek-ai/dsh 0.1.2-rc.1; Node.js must meet ^22.19 || >=24.
  • LAN boundary: This plugin only provides LAN access and does not provide a public tunnel. For external network access, you must set up an authenticated channel such as a Cloudflare named tunnel yourself.
  • Disable --trusted-host: Do not use the --trusted-host argument; this plugin achieves security isolation through an independent route.
  • Uninstall: To disable it, run the following command and restart:
dsh plugin --profile web remove dsh-mobile-gateway

Ecosystem Background

DeepSeek Harness (DSH) adopts the “everything is a plugin” design philosophy. As a community plugin, dsh-mobile-gateway extends the official interfaces to provide a LAN access solution without modifying source code.