AI Agent Hub
Back to plugins
🧩

dsh-totp

admin-security Updated 2026.09.10

Run the following command in DeepSeek Harness:

dsh plugin install SodaZheng/dsh-totp

Paste the following prompt into your AI chat to install this plugin:

Run dsh plugin install SodaZheng/dsh-totp in the DeepSeek Harness terminal, then restart your Web instance to apply the plugin; the source is available at https://github.com/SodaZheng/dsh-totp .

About this plugin

A personal DSH Web instance is open to anyone who knows the URL, which feels precarious in a shared LAN or behind a port-forwarded tunnel. dsh-totp solves this with a single, familiar mechanism: a standard TOTP six-digit code gate at the DSH entry point. No Google or Microsoft account is required, and no separate login server needs to be stood up. Once protection is on, every entry point—local, intranet, or public—demands a valid code before the workspace loads.

Binding happens entirely inside DSH's settings page: scan a QR code with Google Authenticator or Microsoft Authenticator, confirm with the current code, and you are done. The protection toggle can be flipped at any moment; a one-click lock revokes every active session instantly; and ten one-time recovery codes provide a safety net when a phone is lost or replaced. Under the hood, the plugin enforces replay protection, per-IP and global failure-rate limits, and page-session expiry, so a lightweight TOTP gate still carries real security weight.

It is built for the one-person, one-instance use case—no multi-user roles, no password-plus-TOTP two-factor ceremony, just a self-controlled door in front of DSH. It suits anyone who shares DSH on a local network, exposes it through a port mapping, or simply does not want a guessed URL to be an open invitation.

Use Cases

  • Add a code gate when accessing DSH over LAN or a remote tunnel
  • One-click lock to revoke every active session when stepping away
  • Recover access with one-time codes after losing a phone

Best For

  • Individuals sharing DSH on a local network
  • Users reaching DSH via port forwarding or reverse proxy
  • Lightweight users who want a gate without standing up extra login infra