liguobao/ds-harness-remote 预览 preview

liguobao/ds-harness-remote

一个基于 DeepSeek Harness 插件机制构建的多端远程访问方案,通过安全、低延迟、端到端加密的 P2P 优先网络,支持从 PC、Android 和 Web 随时访问并操作远程 Harness 和 CodeX。 (A multi-device remote access solution built on the DeepSeek Harness plugin system, enabling PC, Android, and Web clients to securely access and operate remote Harness and CodeX over a low-latency, end-to-end encrypted, P2P-first network.)

Project Overview项目介绍

DSH Remote is a plugin that turns DeepSeek Harness into a cross-device workspace over an end-to-end encrypted channel. It lets phones, computers, and browsers continue the same Harness session, send instructions, view progress, and respond to permission prompts without exposing a public port. Use it when you need to resume work across devices. Caveat: 0.4.1 only supports Harness rc.2 and alpha.1, and cross-generation connections are rejected.

DSH Remote 是 DeepSeek Harness 的远程接入插件。它通过端到端加密通道,让手机、电脑或浏览器继续同一 Harness 会话、发送指令、查看进度并回答权限请求,无需公网端口。适用于跨设备延续工作流的场景。注意:0.4.1 仅支持 rc.2 与 alpha.1 协议版本,跨版本连接会被拒绝。

Or use CLI install (for developers)或使用命令行安装(适合开发者)

CLI Install命令行安装

dsh plugin --profile web add ds-harness-remote@0.4.13

liguobao/ds-harness-remote 加入你的 DSH 配置(web profile)即可启用。

READMEREADME

DeepSeek Harness Remote

English  ·  中文  ·  Documentation  ·  Download: Windows  ·  macOS  ·  Linux  ·  Web  ·  Android

npm  ·  GitHub  ·  dshfind downloads

Connect once. Ready whenever you are.

Continue using your DeepSeek Harness instance from a phone, computer, or browser.

Return to the same Harness session from whichever device is with you. Harness keeps running on your work computer, with the same workspaces, tools, and project setup. Remote is simply another window into that environment.

Features

  • Continue active sessions and review their latest progress from another device
  • Send new instructions, change direction, and use image prompts with Harness dsh-v0.1.1-rc.2, dsh-v0.1.2-alpha.1rc.1, or dsh-v0.1.5-rc.1
  • Answer questions and permission requests from clients with live conversation controls
  • Open workspaces from another authorized computer on the same account
  • Reuse the native Harness interface instead of maintaining a separate desktop conversation UI
  • Preview remote files between two Harness installations with the optional dsh-file-viewer plugin
  • Run a terminal-only dsh-TUI profile as a Host and authorize it with a GitHub or Zhihu QR code
  • The Harness Host does not need a public listening port. Connect securely from anywhere with internet access over a bidirectional end-to-end encrypted channel

Install

Path A: DSH Desktop

Install DSH Desktop on Windows, macOS, or Linux. Remote is included and enabled by default, so no separate plugin installation is required.

Path B: Existing DSH installation

Add the exact package version through DSH's plugin manager for the web profile:

dsh plugin --profile web add ds-harness-remote@0.4.13

Restart Harness after installation.

Do not install this package directly with npm. Only dsh plugin updates the selected profile and adds the bundle's configuration layer.

Path C: dsh-TUI Host

Remote can run as a Host in a terminal-only dsh-TUI profile; it does not require the Desktop browser connection service. Install the plugin in the TUI profile:

dsh plugin --profile dsh-tui add ds-harness-remote@0.4.13

Start dsh-TUI and use its native slash command:

/remote                    # live Host status
/remote login              # Zhihu QR login by default
/remote login github
/remote status
/remote logout

/remote login opens a TUI-native QR scene and prints a clickable authorization URL below the QR code. Login defaults to Zhihu; GitHub is also supported. Host control is enabled by default, and /remote logout revokes the Host and rotates its local device identity. Host configuration is not exposed yet; the integration uses https://dsh.r2049.cn. Tab completion is available for the subcommands and login providers. The /remote Host-management surface supports TUI profiles on dsh-v0.1.1-rc.2, dsh-v0.1.2-alpha.1rc.1, and dsh-v0.1.5-rc.1; Remote workspace capabilities are advertised only when their official Harness carrier is available.

See the dsh-TUI Remote guide for the compatibility matrix, rc.2 ApiProxy setup, status fields, and troubleshooting.

Quick start

  1. Open Remote from the Harness sidebar.
  2. Sign in with a GitHub or Zhihu QR code, or use your account and password. New password accounts can register through Remote Web; the site shows the current invitation requirements.
  3. Enable remote control for the current computer.
  4. On another device, open DSH Desktop, Remote Web, or the Android client and sign in to the same account.
  5. Select the online Host, then choose an existing workspace or browse remote directories to open one.

The public service currently uses the hosted Remote relay. A supported self-hosted relay option is not available yet.

Screenshots

Desktop

Enable Allow control of this device in Remote settings to make the current computer available as a Host.

On another computer, select an online Host and open one of its workspaces.

Remote workspace picker listing online Hosts

The workspace opens in the native Harness interface, with the active Host and encrypted connection status shown in the header.

A Harness conversation running through an encrypted remote connection

Android

Download the latest Android APK from GitHub Releases.

Sign in to the Android client with your existing account, select an available computer, open a workspace, and continue the conversation with text or image prompts. The conversation toolbar also lets you switch the active model and choose any reasoning effort declared by it.

Android client listing online and offline computers Sending an image prompt from the Android client Viewing the image response in the Android client

How it works

DSH Desktop / Remote Web / Android
  ↔ authenticated, end-to-end encrypted channel
Remote Plugin on the Host
  ↔ supported Harness or optional Codex workspace support
Harness sessions/workspaces or Codex projects

The Harness Host does not need a public listening port. You can connect from anywhere with internet access, and Remote communicates over a bidirectional end-to-end encrypted channel. It switches the client to the selected Host's native Harness API, so the original workspace, tools, and permission flow remain on that computer. Every settings namespace currently registered by the Host can also be configured remotely through the official Harness settings API. Credential values remain write-only, and Host-local document/open actions are never exposed.

Experimental Codex workspaces

Remote can also show Codex projects from an authorized Host. Pick one from the normal workspace chooser and continue in the existing Harness or Android interface; there is no separate Codex screen to learn. The Desktop chooser and Android workspace page can also add a Host directory to the Codex project catalog without importing it into Harness storage.

Codex Remote is meant as a convenience layer for your own devices. It supports text prompts, image prompts where available, model and permission controls, interrupt, and approvals. It is still published as experimental while long-running recovery and compatibility work continue.

Web and Desktop approval controls show the Host-confirmed mode for the selected Codex session. If it has not been reported, they indicate that Host settings are inherited. Changing the mode requires Host confirmation; sending a prompt preserves the session's current policy.

Codex is enabled by default and can be turned off in the DeepSeek Remote settings card. Advanced configuration and implementation notes live in Codex Remote technical notes.

End-to-end encryption

Harness business traffic is encrypted on the Client and decrypted only by the selected Host using the fixed Noise_IK_25519_ChaChaPoly_SHA256 suite. Account membership and locally pinned device identity keys must both authorize a connection. The service can route connections and observe network metadata, but it cannot read session messages, prompts, tool output, workspace paths, or File Viewer content. See End-to-end encryption for the handshake, key lifecycle, visible metadata, replay protection, and security limits.

Network and transport

The Host opens outbound connections only; it does not listen on a public port or require router port forwarding. Remote negotiates LAN -> P2P -> TURN -> Relay, falling back to the encrypted WebSocket Relay when WebRTC is unavailable or cannot connect. Every path carries the same Noise ciphertext and keeps the same Host/Client identity boundary. See Network and transport for the topology, control and data planes, NAT behavior, fallback, reconnect semantics, and current validation status.

Security

  • Session traffic is end-to-end encrypted. The service relays ciphertext without storing session plaintext or device private keys.
  • Server membership and the Host's locally pinned peer identity must both authorize a connection.
  • Remote does not expose a direct shell, PTY, general tool RPC, or remote desktop. Harness tools may still modify files or run commands on the Host under Harness's normal permission controls.
  • The workspace picker lists folders only and returns bounded, read-only directory metadata.
  • Optional File Viewer access is limited to authenticated, encrypted range reads and continues to enforce provider root and locator authorization.
  • Remote file preview cannot write, delete, upload, execute, or open a path in an external application.
  • Codex Remote is optional, can be disabled, and follows the same encrypted Host permission boundary as the rest of Remote.
  • Removing a device revokes its credentials, membership, and active Remote connections.

Compatibility

Breaking change notice: Plugin 0.4.1 removes the earlier experimental Remote business RPC surface (sessions.*, session.*, permissions.respond, sync.from). Harness session traffic now only uses the official rc.2 ApiProxy or the v0.1.2 Typert Remote Gateway, and this plugin does not provide an adapter or wire-format translation for the old RPC surface.

Plugin 0.4.13 supports DeepSeek Harness dsh-v0.1.1-rc.2 through the legacy official ApiProxy, and dsh-v0.1.2-alpha.1rc.1 through the official Typert Remote Gateway. It also supports dsh-v0.1.5-rc.1 Session V3 through the official Typert Remote Gateway. A 0.4.13 Client running rc.2 remains compatible with older rc.2 Hosts through the legacy capability fallback.

Remote Web/Desktop and the Android app also normalize released sessions that still report the retired code agent preset to ptc, so old sessions can resume on dsh-v0.1.5-rc.1 without changing DeepSeek Harness itself.

Desktop endpoints must use a compatible Harness carrier. Plugin 0.4.13 selects the legacy ApiProxy path for rc.2 Hosts when that Host exposes it, and Session V3 Desktop clients can open legacy v0.1.2 Typert Remote Hosts through Remote-side history and event normalization. Legacy Typert clients still reject Session V3 Hosts before switching the native UI or mutating a Workspace.

Documentation

Links

Project status and trademarks

This is an independent community project and is not an official DeepSeek product. DeepSeek and related names and marks belong to their respective owners.

License

MIT

上一个 Prev DeepSeekGUI 下一个 Next pi2dsh