Deepseek Harness Relay
sorsama/deepseek-harness-relay · skills
Authenticated remote access for a DeepSeek Harness web profile: TLS, QR/passcode device pairing, password sign-in, and per-device revocation in front of an untouched loopback harness.
★ 7GitHub stars
2Forks
2026-09-08Last updated
TypeScriptLanguage
MITLicense
Key features
- packages/client/connection/src/api-request-trust.ts — the /api fence "is not an auth layer".
- Password sign-in for a browser, as a signed HttpOnly
- They cannot reach a self-signed listener.
- Set publicHostnames to the name you reach it by, or the fence will refuse the request.
- packages/bundle/web-app/src/startup.ts — dsh web --host 0.0.0.0 is refused, because "it would expose remote code execution to the network".
Install command
dsh plugin --profile web add github:sorsama/deepseek-harness-relay