xbzbing/dsh-auth-gateway

Adds secure remote access to DeepSeek Harness with password auth and TOTP two-factor authentication (2FA).

An authentication gate in front of the DeepSeek Harness Web UI — password auth + TOTP two-factor + layered brute-force protection + session management + login audit, with real interception of every request (HTTP and WebSocket) at the gateway layer. dsh web ships with no auth layer and pins its configuration plane to loopback; this plugin fills that role in-process. On first deployment an initial password is auto-generated and printed to the console (one-time credential); after login you set a personal password (scrypt-hashed). TOTP 2FA is optional.

uncategorized ★ 3 updated 2026-08-17
View on GitHub ↗

Install

dsh plugin --profile web add dsh-auth-gateway && dsh web --port 8080

npm package dsh-auth-gateway 0.5.1 (registry-verified 2026-08-28): dsh plugin --profile web add dsh-auth-gateway, then start on the gateway port dsh web --port 8080 (internal webserver auto-moves to 8081). Uninstall: run ~/.dsh/profiles/web/node_modules/.bin/dsh-auth-gateway-uninstall first, then dsh plugin --profile web remove dsh-auth-gateway. Forgot the password? dsh-auth-gateway-reset (restart prints a new initial password). GitHub/local installs supported — see docs/en/INSTALL.md.

Compatibility

DeepSeek Harness web runtime (supports latest dsh 0.1.1-rc.2). In-process gateway: the gateway exclusively owns the external port; the bundle patch pins the internal webserver to loopback.

Details

Recent updates

password auth + TOTP 2FA; layered brute-force protection; session management + login audit; real HTTP/WebSocket interception; loopback-pinned internal server.

FAQ

Why does dsh need this?
dsh web ships with no authentication layer and pins its settings/credentials RPCs to loopback — this plugin is the missing auth layer, as an in-process gateway that owns the external port.
How do I get the initial password?
On first deployment an initial password is auto-generated and printed to the console; after login you are guided to set a personal scrypt-hashed password.
Does it support 2FA?
Yes — optional TOTP two-factor authentication, plus layered brute-force protection, session management and login audit.

Alternatives

suntianc/dsh-codex-auth · Player-MINEPIG/dsh-llm-codex-oauth · ziyou979/dsh-llm-oauth

More plugins in uncategorized

Browse more in uncategorized

Guides for uncategorized plugins