ds-harness-remote
Verifiedds-harness-remote · v0.5.2 · MIT · Web UI
End-to-end encrypted remote access to DeepSeek Harness and experimental Codex workspaces from desktop, web, and Android, with dsh-TUI Host support.
Install
dsh plugin add ds-harness-remote Confirm the layer applied with dsh --profile default --dump-config — see the install guide.
Source
Tags
Creators
Readme
DeepSeek Harness Remote
Continue DeepSeek Harness sessions and experimental Codex, Cursor, and Antigravity workspaces from another device over an end-to-end encrypted connection.
GitHub · Full guide · 中文说明 · Remote Web · Android
ds-harness-remote is the Remote Host and workspace plugin for DeepSeek Harness. Harness keeps running on your work computer with its existing workspaces, tools, and permission controls; Remote gives authorized devices another window into that environment.
Install the npm package through Desktop Plugin management or
dsh plugin. Both manage the selected Harness profile and its bundle configuration.
Install
DSH Desktop
In DeepSeek Harness Desktop, open Extensions / Plugin management, choose installation from npm, and enter:
[email protected]
Restart Desktop after installation. Its official dsh launcher can also install the package:
dsh plugin --profile desktop add -w [email protected]
Use Desktop's official launcher to manage its reserved desktop profile.
Existing DSH installation
Add the current package version to the web profile, then restart Harness:
dsh plugin --profile web add -w [email protected]
dsh-TUI Host
Remote can also run as a Host in a terminal-only dsh-TUI profile:
dsh plugin --profile dsh-tui add -w [email protected]
After starting dsh-TUI, manage Remote with /remote, /remote login, /remote status, and /remote logout.
Highlights
- Continue active Harness sessions and review progress from another computer, the web, or Android.
- Send text and image prompts, answer questions, and handle permission requests.
- Open workspaces on another authorized computer without replacing the native Harness interface.
- Use the official workspace file tree and bounded read-only previews on supported Harness versions.
- Use an optional Host-local terminal and authorized loopback development-service previews.
- Open Host Codex projects in the existing Remote UI through the optional experimental Codex domain.
- Access Cursor and Antigravity workspaces through the optional experimental ACP gateway, with client-side projections kept in memory.
- Reach the Host without opening a public listening port or configuring router port forwarding.
Compatibility
Plugin 0.5.2 targets DeepSeek Harness dsh-v0.2.0-rc.2 and retains dsh-v0.1.7-rc.1 compatibility; it also supports dsh-v0.1.6-alpha.2 and earlier settings hosts. It supports:
dsh-v0.1.1-rc.2through the official legacyApiProxy;dsh-v0.1.2-alpha.1throughdsh-v0.1.2-rc.1through the official Typert Remote Gateway;dsh-v0.1.5-rc.1,dsh-v0.1.6-alpha.1, anddsh-v0.2.0-rc.2Session V3 through the official Typert Remote Gateway.
The same package feature-detects the older settings registry and the 0.1.7-rc.1 and 0.2.0-rc.2 Volatile settings entry. Remote Web/Desktop and Android normalize released sessions that still report the retired code agent preset to ptc. The Host reads the running Harness version from the CLI entrypoint, or from the 0.2.0 Desktop shell's @deepseek-ai/dsh-desktop-host entrypoint when the Harness CLI package is only a sibling of that entrypoint inside app.asar.
Self-hosted Server
This repository includes a minimal, single-account self-hosted Relay Server in apps/server. Configure DSH_SERVER_ACCOUNT and DSH_SERVER_PASSWORD, then point the Host and clients at the same server URL. It provides account login, device credentials, encrypted Control/Noise forwarding, Relay, and a device-status page. It does not provide the complete multi-account Server, Remote Web session UI, or WebRTC/TURN deployment.
Security boundary
- Session traffic is encrypted on the Client and decrypted only by the selected Host using
Noise_IK_25519_ChaChaPoly_SHA256. - Account membership and the Host's locally pinned device identity must both authorize a connection.
- The Host creates outbound connections only; it does not listen on a public port.
- Remote does not expose general tool RPC, remote desktop, or file-mutation APIs.
- Interactive terminals are enabled by default and can be disabled in the Host-local Remote settings; they run as the Host user independently of Agent approvals.
Documentation
- Complete guide
- dsh-TUI Remote guide
- Codex Remote technical notes
- Agent workspace integration guide
- End-to-end encryption
- Network and transport
- Protocol reference
- Changelog
This is an independent community project and is not an official DeepSeek product. Licensed under the MIT License.