Skip to content

dsh-webcode-bridge

Verified

dsh-webcode-bridge Β· v0.19.51 Β· MIT Β· Web UI

Use your logged-in web AI (DeepSeek, GLM, Kimi, Qwen, Doubao...) as model providers in DeepSeek Harness. Web models emit tool calls, DSH runs them under its native permission system, and results return to the same web session. No API keys.

Install

dsh plugin add dsh-webcode-bridge

Confirm the layer applied with dsh --profile default --dump-config β€” see the install guide.

Source

Tags

Creators

Readme

Harness Web Bridge

Use your logged-in web AI (DeepSeek, GLM / Z.ai, Kimi, Qwen, Doubao) as model providers inside DeepSeek Harness. Web models emit tool calls, DSH executes them under its native permission and approval system, and the results go back into the same web session.

No API keys β€” it drives the site through your own browser login.

dsh plugin --profile web add dsh-webcode-bridge

Restart dsh web after installing. Installing only swaps files on disk; the running process still has the old code loaded. This is the single most common "it does not work" report.

What it does

  • Real sites in the DSH right sidebar β€” not a screenshot, not a mock. The actual site is loaded through a same-origin mirror, so you can type, scroll and click in it. Login state persists.
  • Per-site protocol teaching β€” each site is taught the tool-call shape it actually accepts (DeepSeek's native token format, GLM's fenced ```json code block, <tool_call> tags elsewhere), recomputed from the live tool list every turn.
  • Global and per-site settings β€” model, instruction, send gap and prompt-delivery mode can each be set globally and overridden for one site, without disturbing the others.
  • Multi-account β€” one site can hold several independent logins, each with its own browser profile and its own request pacing.
  • Observable β€” every delivery, fallback and rate-limit event is projected into GET /__webcode/status.

Requirements

Node.js 22.13 or newer
DeepSeek Harness 0.1.0-rc.6 or newer
Browser None to install β€” the plugin ships its own Chromium (Playwright). A system browser is used only as a fallback.

Install

From the npm registry (recommended)

dsh plugin --profile web add dsh-webcode-bridge

Pin a version with dsh-webcode-bridge@<version>.

From a release tarball

Download dsh-webcode-bridge-<version>.tgz from Releases, then:

dsh plugin --profile web add C:\path\to\dsh-webcode-bridge-<version>.tgz

From source

pnpm install            # do NOT add --frozen-lockfile, see ../../doc/ci-cd.md
pnpm pack              # produces dsh-webcode-bridge-<version>.tgz

Two local helper scripts exist for troubleshooting only: scripts/verify-pack.mjs compares the packed tarball against the working tree file by file, and scripts/install-profiles.mjs removes the old directory before unpacking (which avoids pnpm's "Already up to date" shortcut on a same-version tarball). Both encode a bug that actually happened.

Site status

DeepSeek is the primary target and holds up over long sessions. GLM works, but it is unstable.

Site Status
DeepSeek deepseek:deepseek Primary. Validated over long multi-turn tool loops on a real browser session, with auto-continue, session-cursor persistence, and recovery from Harness history after a restart.
GLM glm:glm-5.3 / glm-5.3-flash Usable but unstable. The end-to-end tool loop passes on a real session: a random secret present only in the tool result is echoed back verbatim by the model, so the round-trip is genuinely live.
Kimi / Qwen / Doubao / Z.ai Wired up, not validated over long runs. Availability depends on your login state.
Claude Region-restricted; the site says so itself.
ChatGPT / Grok / Gemini Not reachable from our network (502 plus an explanatory page).

What "unstable" means for GLM, concretely:

  • Thinking cannot be turned off, and it dominates the stream (1051 of 2472 replies were thinking-only).
  • The site intercepts tool-call tags in prose through its own native tool layer, so GLM is taught only the fenced code-block shape, with fallback parsing from the thinking stream.
  • Deep-link navigation is stopped by an Aliyun slider captcha, so probes go through the driver path instead.
  • Two failure modes have been fixed and are worth knowing: a stream that died mid-thinking produced an empty reply, and call-fence tails leaked into the reply body as garbage.

Read it as: DeepSeek is the one to run all day; GLM is a good second opinion. When GLM fails, retry β€” attributable failures surface as coded messages rather than silent degradation.

Documentation

The full documentation lives in the repository:

Document Contents
README Project overview, install, configuration and troubleshooting.
docs index The authoritative entry point for repository documentation.
progress ledger Where the project currently stands and what is next.
long-term issues Known defects and why they are not fixed yet.
permissions and boundaries Dependencies, permissions, external services and failure boundaries.
settings copy What every settings label means, and the full explanation behind it.
CI/CD Build, release and rollback.
CHANGELOG Release history for this package.

License

MIT β€” full text in LICENSE. Third-party notices are kept in permissions and boundaries rather than in the license body, so GitHub's license detection reports MIT instead of NOASSERTION.

SSE decoding protocol references the MIT project three-water666/webcode.