Preface

The design philosophy of DeepSeek Harness (DSH) is “everything is a plugin.” dsh-deeppilot is one of its client plugins, providing a native iPhone companion app for DeepSeek Harness. It does not replace or modify the DSH Web interface; instead, it connects directly to your DSH host over an encrypted tunnel, allowing you to browse sessions, send prompts, and manage agent workflows on your phone.

Plugin Information

  • Name: dsh-deeppilot
  • Maintainer: Mars-Sea
  • Category: Client
  • License: MIT

Core Features

  1. End-to-end interaction: Browse projects, sessions, history, and live agent output from your iPhone; send prompts, switch models, create sessions, and handle system prompt approvals and questions.
  2. Secure pairing: Pair using a five-minute single-use code and per-device P-256 keys. A physical iPhone stores the private key in the Secure Enclave, ensuring the key never leaves the device.
  3. Connection methods:
    • Local area network (LAN): A dedicated TCP port 3098 is enabled by default, with TLS encryption only. The host issues a certificate during pairing and verifies the fingerprint.
    • Tailscale Funnel: Optional built-in Tailscale Funnel mode is supported.
  4. Notification support: Supports real-time push notifications, with optional offline APNs notifications (in offline relay mode, only the APNs device token and a limited payload are forwarded, and the full conversation history is not transmitted).
  5. Self-updating: The settings footer displays the installed version, checks for stable GitHub releases in the background, and provides a version update link (no third-party dependencies).

Installation and Activation

Run the following command in the terminal to install the plugin:

dsh plugin --profile web add dsh-deeppilot

After installation, restart DSH. Go to Settings → DeepPilot, enable the connection, and display the pairing QR code. Scan the QR code in the DeepPilot app to complete pairing. Below the pairing panel, a copyable address, one-time code, and certificate fingerprint are also shown for paste-based pairing when the camera cannot be used.

Configuration and Notes

  1. Port and firewall: LAN access listens on TCP 3098 by default. If a firewall is enabled on the system, allow this inbound port on the network you are using. The port can be changed on the DeepPilot settings page.
  2. Connection switching: When switching between LAN and public addresses, the plugin immediately generates a new QR code and string.
  3. Protocol upgrade: If upgrading from an older version (older versions used plaintext ws:// on LAN), all devices paired over LAN must be re-paired to obtain the new certificate fingerprint.
  4. Data retention: Uninstalling the plugin does not delete local state files under $DSH_HOME/deeppilot/.

Use Cases and Limitations

  • DeepPilot status: DeepPilot is currently in Apple’s TestFlight review process; the invitation link will become active after Apple approves the review.
  • DSH version requirements: The plugin source code is developed based on Node.js 22+ and the DSH 0.2.x series (compatible with versions from 0.2.0-rc.2 up to before 0.3.0), and it requires the web profile configuration.
  • Security recommendation: Conversation traffic is transmitted directly between the iPhone and the DSH host and is encrypted end to end. Before enabling remote access or push features, read PRIVACY.md and SECURITY.md.

Summary

dsh-deeppilot provides DSH users with native mobile interaction capabilities. Through private key isolation on the physical device, TLS certificate binding, and direct connection mode, it maintains a high level of security while delivering convenient interaction. The plugin is currently in testing and is suitable for developers who want to use DeepSeek Harness more deeply on mobile.