curated collections / remote-mobile

DSH Remote Access & Web GUI: Run DeepSeek Harness from Phone & Browser

Four head plugins (★418–★8,217) put dsh on your phone and in your browser: a one-command web workbench, QR-code pairing, a cross-device agent desk and a native iOS client — plus the tunnels, gateways and auth layers that carry them.

DeepSeek Harness ships its own Web UI: one `dsh web` command starts it at http://127.0.0.1:3080 and opens your browser. The catch is the loopback-only default — the moment you want the same session on your phone, a second computer or a server, you need one of the plugins below. Four product lines cover it: dsh-web (★8,217) installs a full web workbench in one command; dsh-pocket (★1,438) mirrors dsh to your phone behind a QR code over LAN or a cloudflared tunnel; Agents-Anywhere (★1,330) turns any device into a cross-device workbench; dsh-mobile (★418) is a native iOS client with its gateway plugin. Below them, the auto-ranked list adds LAN exposure, Tailscale, relays and self-hosted gateways — grouped by where your phone is, with an official-mechanism primer and a port-exposure security section.

Fastest path: run `dsh web` on the computer, install dsh-pocket, scan its QR code from your phone — usable in about two minutes on the same Wi-Fi. Reaching dsh from outside your network? Pick dsh-pocket's public tunnel mode or a self-hosted gateway, and add an auth layer before you expose any port.

358 plugins19.3K stars

Synced from our GitHub list · Catalog updated 2026-09-30

Why it matters now

01

The demand is real and unanswered: people search the web UI by its command name, by install-command fragments like "web ui all", even by whole error strings such as "authentication required — reopen the url printed by dsh web" — and no aggregation page anywhere gives the straight answer. The official docs stop at the local launch.

02

The Web UI is a first-class face of dsh: `dsh web` is the official command, the official docs ship a Web UI guide, and SSH launches print the host URL. But the default bind is 127.0.0.1 only — everything past the local machine is plugin territory, and the ecosystem has built the answers.

03

The deepest supply of any cluster this round: the four heads alone carry 11,400+ stars and all were pushed within a day of 2026-09-30 — with scan-to-connect, LAN gates, Tailscale, relay gateways and MFA layers still landing behind them.

In this collection

Editor’s picks lead, then the rest of the theme is auto-discovered by GitHub topics and ranked by stars. Catalog data, refreshed on every sync.

  1. 1
    dsh-webby zhu1090093659

    One-command install of a full DSH web workbench: monitoring HUD, task board, SSH panel, mobile remote, vision tool, git graph, skins, plugin manager.

    Editor’s pickCuratedWeb UI & Frontend
    8,166553
  2. 2
    dsh-pocketby shaobeichen

    Mobile/remote access to dsh web: LAN + public cloudflared tunnel QR codes, real-time WS mirror, mobile drawer UI (ports dsh-web-mobile), a Settings '手机访问' page, auto-rotating public URLs

    Editor’s pickCuratedWeb UI & Frontend
    1,40570
  3. 3
    agents-anywhereby anywhere-labs

    An open-source workspace for using AI agents across devices.

    Editor’s pickMCP & Protocols
    1,309133
  4. 4
    dsh-mobileby clarklevis1995

    iOS app for DeepSeek Harness, bringing the plugin ecosystem to mobile.

    Editor’s pickDesktop & Apps
    40832
  5. 5
    dsh-imby xmanrui

    把 IM 机器人接入 DSH:统一管理飞书/微信/钉钉/企业微信/QQ/Telegram/Discord/WhatsApp 八个渠道,扫码或凭据接入、流式回复与设置页管理

    CuratedChat & IM
    1,544186
  6. 6
    dsh-mobileby saya-ch

    Exposes a computer's DeepSeek Harness over a secure LAN to a phone browser or Android App; provides a mobile layout, device pairing (QR/link/key), /mobile conversational customization of the phone UI, and a local extension host for phone-triggered computer capabilities (e.g. live CPU/RAM/disk monitor).

    CuratedDesktop & Apps
    34129
  7. 7

    Lets authorized desktop, web, and Android clients operate a remote Harness host.

    CuratedDesktop & Apps
    24125
  8. 8

    Open-source Windows desktop client and GUI for DeepSeek Harness — zero-setup installer with Codex, plugins, skills, SSH, mobile remote access, and 11 skins.

    CuratedWeb UI & Frontend
    75324
  9. 9
    dsh-iosby zseven-w

    DeepSeek Harness (DSH) plugin: a live iOS Simulator — and a USB-connected iPhone — inside the conversation. 22 agent tools for booting, building, driving the UI by accessibility identity, OCR text or list rows, plus a streaming sidebar panel you can tap and drag on.

    CuratedDesktop & Apps
    30825
  10. 10
    dsh-remoteby flymysql

    Remote-work assistant for DeepSeek Harness (DSH): connect SSH (key or password), pick a remote workspace, operate with rw_* tools, and SFTP-mirror it into a real local DSH workspace.

    CuratedDesktop & Apps
    10322
  11. 11
    dsh-web-mobileby mexiaosqwq

    Adapts dsh web UI to portrait/mobile devices: safe-area status bar, drawer nav, mobile session header, settings sheet, markdown table and message bubble fixes

    CuratedWeb UI & Frontend
    10524
  12. 12
    dsh-androidby zseven-w

    DeepSeek Harness plugin for Android — build, run, and interact with a live emulator or USB device stream inside a conversation, driven entirely through adb.

    CuratedAgents, Automation & Workflows
    16415
  13. 13
    dsh-bridgeby wenbin-wb

    多通道远程访问:局域网扫二维码在手机上继续会话(默认端口 3082)、Cloudflare 隧道一键公网、自建隧道固定域名、微信 Bot(多工作区/会话持久化/媒体/审批)

    CuratedChat & IM
    17910
  14. 14
    dsh-mobile-apkby kelai141

    Android shell for DeepSeek Harness — WebView UI with an embedded Termux runtime, SAF file bridge, keep-alive services and online runtime updates.

    Desktop & Apps
    56866
  15. 15
    local-shell-mcpby fwerkor

    Enables LLM to use a cli environment.

    CuratedAgents, Automation & Workflows
    8014
  16. 16
    dsh-passwordsby slywalker2006

    Server-grade gateway that turns DeepSeek Harness into a multi-tenant platform: remote access + auto HTTPS, subuser permissions & quotas, sandbox enforcement, encrypted auth, audit log.

    CuratedDesktop & Apps
    6415
  17. 17
    tingly-boxby tingly-dev

    Your Intelligence, Orchestrated. Every builder. Every team. Every agent. For Everyone.

    Agents, Automation & Workflows
    34843
  18. 18
    dsh-notifierby thewolfwalker

    DSH notification & remote-control plane: 28 outbound channels, 6 inbound controls, Native Notify & Control UI, live hot-apply, zero runtime deps.

    CuratedChat & IM
    5412

The official mechanism: one `dsh web` command, loopback by default

Before picking a plugin, know what dsh itself already does — the official README spends exactly one paragraph on the web command, and every remote plugin on this page builds on that baseline.

`dsh web`: the built-in Web UI launcher

`npx @deepseek-ai/dsh web` starts the Web UI at http://127.0.0.1:3080 by default and opens it in your default browser. `--no-open` runs the server without opening a browser, and an SSH launch only prints the host URL because the SSH client owns the forwarded address. The official docs include a Web UI guide — the feature is first-class; the remote story is simply not documented.

Loopback-only: why your phone can't reach 127.0.0.1:3080

The default bind is the machine's own loopback address, so nothing else can reach the UI out of the box — a deliberate security default, and the single reason this collection exists. Community plugins own the rebind: dsh-web-startup-auth replaces the hard 0.0.0.0 rejection with login/register pages and signed session cookies, and the MFA options one level up are in the security section below.

"dsh web ui all" is a community bundle, not an official package

People searching "dsh web ui all" are usually after `@linxin666/dsh-web-ui-all` — a community aggregate that installs the whole web-UI plugin family (task board, git graph, remote web UI, skins…) with one `dsh plugin --profile web add`. It ships from the dsh-web ecosystem repo, not from DeepSeek's official npm scope. Treat it as a convenient bundle, not an official component.

dsh remote, three ways: scan-to-connect, tunnel, self-hosted server

Every plugin on this page is one of three shapes. Pick by where the phone is: on the same Wi-Fi, on another network, or in front of a server you own.

Scan-to-connect (same network, zero config)

dsh-pocket prints LAN and public cloudflared-tunnel QR codes side by side, mirrors the session over WebSocket in real time and rotates public URLs automatically — run `dsh web`, scan, done. dsh-remote-web-gateway does the same over a Cloudflare Quick Tunnel: a one-time QR or an 8-character pairing code, per-device authorization you can revoke at any time, optional GitHub Device Flow login.

LAN or mesh exposure (rebind wider, stay inside)

For phones on your own network: dsh-mobile (saya-ch) serves dsh over a secure LAN to the phone browser with QR/link/key device pairing; iceapriler/dsh-remote-mobile adds authenticated LAN and Tailscale access with persistent device sessions; dsh-web-startup-auth rebinds to 0.0.0.0 behind login pages. A Tailscale mesh keeps the whole path private — it pairs naturally with these.

Server deployment (reachable from anywhere)

For access beyond your network: mrrisega/dsh-remote runs a relay or self-hosted service your phone's browser connects through; juanwang-buaa/dsh-full-remote is an auditable token-gated gateway with per-device sessions; flymysql/dsh-remote and ds-harness-remote let authorized clients operate a remote Harness host directly. The deployment walkthrough lives in our self-hosted server guide, linked below.

Before you expose a port: authentication comes first

The web UI can approve tool calls, read your workspace and spend your quota. Every exposure path above should end up behind one of the layers in this section.

The risk: an open port is an open agent

A browser that reaches your dsh web UI can approve tool calls, browse session history and workspace files, and burn your API quota. A bare 0.0.0.0 rebind with no login puts the controls on the café's Wi-Fi — and on the public internet the moment a tunnel goes up. Never forward the raw port without an auth layer in front of it.

Auth layers: password, MFA, per-device sessions

xgone/dsh-remote (★67) puts login, TOTP-based MFA and role permissions in front of the loopback-only harness, with remote file preview; dsh-webui-auth gates every resource and API call behind an account created on first visit. Gateway-style tools (dsh-remote-web-gateway, dsh-full-remote) issue per-device authorizations you can revoke from the host at any time.

Tunnels are transport, not permission

cloudflared, Tailscale and relays solve reachability; they don't decide who gets to click. Prefer plugins that rotate or pair their URLs (dsh-pocket's auto-rotating public URLs), keep MFA on anything that leaves the LAN, and review active sessions on the host side. If an option on this page can't tell you who is connected right now, don't use it outside your home network.

Frequently asked questions

How do I start the dsh web UI?

Run `dsh web` (or `npx @deepseek-ai/dsh web` if you don't install the CLI globally). It starts the Web UI at http://127.0.0.1:3080 by default and opens it in your default browser; add `--no-open` to run the server without opening a browser. An SSH launch only prints the host URL, because the SSH client owns the forwarded address. If your shell says "command not found: dsh", use the npx form or install the CLI first.

My phone shows "authentication required — reopen the url printed by dsh web". What now?

That is dsh's own auth gate: the Web UI issues a tokenized, per-launch URL and refuses other requests. On the same machine, reopening the exact URL printed in the terminal usually fixes it. From a phone the tokenized loopback URL is unreachable in the first place — you need one of the remote paths on this page: QR pairing (dsh-pocket), a gateway with per-device authorization, or an MFA layer.

Why can't my phone open http://127.0.0.1:3080?

127.0.0.1 is the computer's own loopback address — it only exists on the machine dsh runs on, so no other device can reach it by design. That default is a security feature. To get in from a phone you either rebind to the LAN address behind an authenticating plugin, publish a temporary public URL through a tunnel, or deploy a self-hosted relay — the three paths compared above.

Do I need a native app on my phone?

No. The browser is the default path: dsh-pocket mirrors the web UI into the phone browser after one QR scan, and several LAN plugins ship a mobile-adapted layout. Native clients exist if you want them — dsh-mobile is a native iOS client speaking WebSocket through its mobile-gateway plugin, and Android has native remote and APK options. Start browser-first; add an app only if you end up using it daily.

Is it safe to expose dsh to my phone?

Treat the web UI like a remote shell: it can approve tool calls, read your workspace and spend your token quota. Keep the default loopback bind unless a plugin manages the rebind, prefer pair-per-device access you can revoke, and put login or MFA in front of anything that leaves the LAN — xgone/dsh-remote adds password plus TOTP two-factor. Tunnels solve reachability, not permission.

How is this different from remote desktop or SSH?

Remote desktop streams a whole screen and is clumsy on a phone; SSH gives you the CLI without the session UI. The plugins here serve dsh's actual web UI to the device you hold — session list, approvals, streaming replies — with pairing and auth sized for mobile. If your goal is working inside a remote machine's workspace, that's a different job: see the self-hosted and SSH picks on this page and the remote access guide.

Explore the full directory

Hundreds of plugins across every category — or submit your own and get listed.

DSH Plugins is an independent community directory of DeepSeek Harness plugins. Not affiliated with or endorsed by DeepSeek. Third-party plugins are not security-audited — review the source before installing.

New DeepSeek Harness plugins, weekly. No spam.