xbzbing/dsh-auth-gateway
Adds secure remote access to DeepSeek Harness with password auth and TOTP two-factor authentication (2FA).
An authentication gate in front of the DeepSeek Harness Web UI — password auth + TOTP two-factor + layered brute-force protection + session management + login audit, with real interception of every request (HTTP and WebSocket) at the gateway layer. dsh web ships with no auth layer and pins its configuration plane to loopback; this plugin fills that role in-process. On first deployment an initial password is auto-generated and printed to the console (one-time credential); after login you set a personal password (scrypt-hashed). TOTP 2FA is optional.
Install
dsh plugin --profile web add dsh-auth-gateway && dsh web --port 8080npm package dsh-auth-gateway 0.5.1 (registry-verified 2026-08-28): dsh plugin --profile web add dsh-auth-gateway, then start on the gateway port dsh web --port 8080 (internal webserver auto-moves to 8081). Uninstall: run ~/.dsh/profiles/web/node_modules/.bin/dsh-auth-gateway-uninstall first, then dsh plugin --profile web remove dsh-auth-gateway. Forgot the password? dsh-auth-gateway-reset (restart prints a new initial password). GitHub/local installs supported — see docs/en/INSTALL.md.
Compatibility
DeepSeek Harness web runtime (supports latest dsh 0.1.1-rc.2). In-process gateway: the gateway exclusively owns the external port; the bundle patch pins the internal webserver to loopback.
Details
- Repo: xbzbing/dsh-auth-gateway
- Category: uncategorized
- Stars: 3
- Version: npm dsh-auth-gateway 0.5.1 (registry-verified 2026-08-28)
- Last push: 2026-08-17
- First seen: 2026-08-14
Recent updates
password auth + TOTP 2FA; layered brute-force protection; session management + login audit; real HTTP/WebSocket interception; loopback-pinned internal server.
FAQ
- Why does dsh need this?
- dsh web ships with no authentication layer and pins its settings/credentials RPCs to loopback — this plugin is the missing auth layer, as an in-process gateway that owns the external port.
- How do I get the initial password?
- On first deployment an initial password is auto-generated and printed to the console; after login you are guided to set a personal scrypt-hashed password.
- Does it support 2FA?
- Yes — optional TOTP two-factor authentication, plus layered brute-force protection, session management and login audit.
Alternatives
suntianc/dsh-codex-auth · Player-MINEPIG/dsh-llm-codex-oauth · ziyou979/dsh-llm-oauth