The official dsh web listens only on 127.0.0.1 by default, so mobile apps cannot connect directly. The dsh-mobile-gateway plugin solves this problem. It overrides the webserver configuration to change the server address to 0.0.0.0 and mounts a token-gated /m/api prefix route for mobile apps.
Core Features¶
This plugin mainly provides the following capabilities:
- Server listens on all network interfaces: Overrides configuration via
cordis.patch.yml, without modifying source code or recompiling. - Mobile access to all RPCs: Mounts a
/m/apiroute alongside the official/api, validates the token, and forwards in-process to the officialapiProxy, without touching the official security boundaries. - Real-time message push: Provides WebSocket downlink streams at
/m/api/events.muxand/m/api/events.host, with frame format consistent with the official implementation. - Approval/question response: Provides a direct path to the official respond channel through the
/m/api/respondendpoint. - Large image sending: Increases the request body limit and supports 500 MB message images.
- Admin page: Provides the
/m/path, restricted to local access only. Used to generate/rotate tokens, generate pairing QR codes per network interface, and manage the device list and blocking. - Sidebar entry: Displays a phone icon at the bottom of the official Web GUI sidebar (next to Settings). Clicking opens the admin page in a popup or new tab.
- QR scanning pairing: The QR code encodes
server\|token, and the companion app fills it in automatically after scanning.
Installation¶
Install the plugin using the official CLI:
dsh plugin --profile web add github:agent-mobile/dsh-mobile-gateway
Configuration¶
After installation, a token must be configured. The token is required, while the other fields have default values. There are two configuration methods:
Method 1: profile patch
Edit ~/.dsh/profiles/web/cordis.patch.yml:
- id: mobile-gateway
config:
token: 换成一个长随机串
allowSettings: true # 放行 settings.*,默认 true
allowCredentials: true # 放行 credentials.*,默认 true
maxRequestBodyBytes: 750000000
Method 2: Web GUI
Modify it in the Web GUI under “Settings → Plugin Configuration → mobile-gateway”; hot reload is supported.
Configuration Field Description¶
| Field | Default | Description |
|---|---|---|
token |
(required) | The app presents it as Authorization: Bearer <token>; if left empty, the plugin refuses to start |
allowSettings |
true |
Allows settings.describe/update/replace/mutate |
allowCredentials |
true |
Allows credentials.describe/set/unset |
maxRequestBodyBytes |
750000000 |
Request body limit per request (must be increased in sync with the official connection limit) |
Startup and Usage¶
After configuring, simply start dsh web:
dsh web
After startup, the terminal prints the LAN address (for example LAN: http://192.168.1.5:3080). The mobile app (requires v1.0.35+) connects through that LAN address while on the same Wi-Fi, and includes Authorization: Bearer <token> in the request headers.
App Endpoint Mapping¶
The app must change the request prefix from the official /api to /m/api:
- Official direct connect:
POST /api/<method> - This plugin route:
POST /m/api/<method> - Official WebSocket:
ws://…/api/events.mux - This plugin WebSocket:
ws://…/m/api/events.mux
Notes¶
- Version requirements: Verified compatible with
@deepseek-ai/dsh0.1.2-rc.1; Node.js must meet^22.19 || >=24. - LAN boundary: This plugin only provides LAN access and does not provide a public tunnel. For external network access, you must set up an authenticated channel such as a Cloudflare named tunnel yourself.
- Disable
--trusted-host: Do not use the--trusted-hostargument; this plugin achieves security isolation through an independent route. - Uninstall: To disable it, run the following command and restart:
dsh plugin --profile web remove dsh-mobile-gateway
Ecosystem Background¶
DeepSeek Harness (DSH) adopts the “everything is a plugin” design philosophy. As a community plugin, dsh-mobile-gateway extends the official interfaces to provide a LAN access solution without modifying source code.