AI Agent Hub
Back to plugins
🖥️

dsh-remote-auth

Client Updated 2026.09.11

Run the following command in DeepSeek Harness:

dsh plugin install wentao75/dsh-remote-auth

Paste the following prompt into your AI chat to install this plugin:

Run dsh plugin install wentao75/dsh-remote-auth in your DeepSeek Harness terminal to install; the full source repository is https://github.com/wentao75/dsh-remote-auth

About this plugin

Every dsh web process mints a fresh random launch token so the browser can exchange it for a 30-day signed cookie. On the same machine that is frictionless, but on an iPad, a phone, or a second laptop reached over Tailscale or a home Wi-Fi, the only option is to SSH in and fish the token-bearing URL out of the server logs. dsh-remote-auth removes that step.

The plugin registers a public /mobile-auth route on the dsh webserver. Open it from any device, optionally enter a PIN, and the page renders a QR code plus an authorization link that is scope-exact to the current process and the authority the device is actually using. One tap or one scan and the browser is cookie-authenticated, signed by a persistent key that survives dsh restarts and refreshes on a 30-day cycle. Security is handled by an OR-semantic gate on allowed Host names and source-IP CIDRs (both empty means loopback-only, fail closed), a per-source-IP PIN lockout after five failed attempts, and PIN values that never appear in the UI.

It is built for developers who run dsh web across multiple screens and network contexts, such as LAN, Tailscale, or remote Wi-Fi, and want a single fixed URL to open, a code to scan, and no more log-digging.

Use Cases

  • Scan a QR code on an iPad or phone to access dsh web over LAN
  • Open the current dsh session from a remote device via Tailscale with one click
  • Skip digging launch tokens out of server logs after every dsh restart

Best For

  • Developers sharing a single dsh web instance across multiple devices
  • Users who develop remotely over Tailscale or home Wi-Fi
  • Operators who want PIN-gated and CIDR-whitelisted access control