dsh-webcode-bridge
Verifieddsh-webcode-bridge Β· v0.19.51 Β· MIT Β· Web UI
Use your logged-in web AI (DeepSeek, GLM, Kimi, Qwen, Doubao...) as model providers in DeepSeek Harness. Web models emit tool calls, DSH runs them under its native permission system, and results return to the same web session. No API keys.
Install
dsh plugin add dsh-webcode-bridge Confirm the layer applied with dsh --profile default --dump-config β see the install guide.
Source
Tags
Creators
Readme
Harness Web Bridge
Use your logged-in web AI (DeepSeek, GLM / Z.ai, Kimi, Qwen, Doubao) as model providers inside DeepSeek Harness. Web models emit tool calls, DSH executes them under its native permission and approval system, and the results go back into the same web session.
No API keys β it drives the site through your own browser login.
dsh plugin --profile web add dsh-webcode-bridge
Restart
dsh webafter installing. Installing only swaps files on disk; the running process still has the old code loaded. This is the single most common "it does not work" report.
What it does
- Real sites in the DSH right sidebar β not a screenshot, not a mock. The actual site is loaded through a same-origin mirror, so you can type, scroll and click in it. Login state persists.
- Per-site protocol teaching β each site is taught the tool-call shape it actually accepts
(DeepSeek's native token format, GLM's fenced ```json code block,
<tool_call>tags elsewhere), recomputed from the live tool list every turn. - Global and per-site settings β model, instruction, send gap and prompt-delivery mode can each be set globally and overridden for one site, without disturbing the others.
- Multi-account β one site can hold several independent logins, each with its own browser profile and its own request pacing.
- Observable β every delivery, fallback and rate-limit event is projected into
GET /__webcode/status.
Requirements
| Node.js | 22.13 or newer |
| DeepSeek Harness | 0.1.0-rc.6 or newer |
| Browser | None to install β the plugin ships its own Chromium (Playwright). A system browser is used only as a fallback. |
Install
From the npm registry (recommended)
dsh plugin --profile web add dsh-webcode-bridge
Pin a version with dsh-webcode-bridge@<version>.
From a release tarball
Download dsh-webcode-bridge-<version>.tgz from
Releases, then:
dsh plugin --profile web add C:\path\to\dsh-webcode-bridge-<version>.tgz
From source
pnpm install # do NOT add --frozen-lockfile, see ../../doc/ci-cd.md
pnpm pack # produces dsh-webcode-bridge-<version>.tgz
Two local helper scripts exist for troubleshooting only: scripts/verify-pack.mjs compares the
packed tarball against the working tree file by file, and scripts/install-profiles.mjs removes the
old directory before unpacking (which avoids pnpm's "Already up to date" shortcut on a same-version
tarball). Both encode a bug that actually happened.
Site status
DeepSeek is the primary target and holds up over long sessions. GLM works, but it is unstable.
| Site | Status |
|---|---|
DeepSeek deepseek:deepseek |
Primary. Validated over long multi-turn tool loops on a real browser session, with auto-continue, session-cursor persistence, and recovery from Harness history after a restart. |
GLM glm:glm-5.3 / glm-5.3-flash |
Usable but unstable. The end-to-end tool loop passes on a real session: a random secret present only in the tool result is echoed back verbatim by the model, so the round-trip is genuinely live. |
| Kimi / Qwen / Doubao / Z.ai | Wired up, not validated over long runs. Availability depends on your login state. |
| Claude | Region-restricted; the site says so itself. |
| ChatGPT / Grok / Gemini | Not reachable from our network (502 plus an explanatory page). |
What "unstable" means for GLM, concretely:
- Thinking cannot be turned off, and it dominates the stream (1051 of 2472 replies were thinking-only).
- The site intercepts tool-call tags in prose through its own native tool layer, so GLM is taught only the fenced code-block shape, with fallback parsing from the thinking stream.
- Deep-link navigation is stopped by an Aliyun slider captcha, so probes go through the driver path instead.
- Two failure modes have been fixed and are worth knowing: a stream that died mid-thinking produced an empty reply, and call-fence tails leaked into the reply body as garbage.
Read it as: DeepSeek is the one to run all day; GLM is a good second opinion. When GLM fails, retry β attributable failures surface as coded messages rather than silent degradation.
Documentation
The full documentation lives in the repository:
| Document | Contents |
|---|---|
| README | Project overview, install, configuration and troubleshooting. |
| docs index | The authoritative entry point for repository documentation. |
| progress ledger | Where the project currently stands and what is next. |
| long-term issues | Known defects and why they are not fixed yet. |
| permissions and boundaries | Dependencies, permissions, external services and failure boundaries. |
| settings copy | What every settings label means, and the full explanation behind it. |
| CI/CD | Build, release and rollback. |
| CHANGELOG | Release history for this package. |
License
MIT β full text in LICENSE. Third-party notices are kept in
permissions and boundaries rather than in the license
body, so GitHub's license detection reports MIT instead of NOASSERTION.
SSE decoding protocol references the MIT project
three-water666/webcode.