dsh-deeppilot
August 31, 2026 · View on GitHub
English | 简体中文
The open-source DSH companion plugin for DeepPilot, a native iPhone client for using DeepSeek Harness remotely. It connects the app directly to the DSH Host on your own Mac and does not replace or modify the DSH Web UI.
DeepPilot is currently in TestFlight review. The invitation link will accept testers after Apple approves the build.
What you get
- Browse projects, sessions, history, and live agent output from iPhone.
- Send prompts, switch models, create sessions, and answer approvals/questions.
- Pair with a five-minute single-use code and a per-device P-256 key; physical iPhones keep the private key in Secure Enclave.
- Connect over a trusted LAN or the optional embedded Tailscale Funnel.
- Receive live notifications and optional APNs notifications while offline.
- Self-update hint: the settings page footer shows the installed plugin version, with an inline "new version" link to the matching GitHub release when one exists (background check, stable releases only, no third-party dependency).
Install from npm
Requirements: Node.js 22+, DSH with a web profile, and macOS. The bundled
Funnel helper currently supports Apple silicon; trusted-LAN mode does not
require it.
| Plugin version | Required DSH | How to install |
|---|---|---|
0.6.0-alpha.x (new, alpha tag) | DSH 0.1.2-alpha.2 or newer | dsh plugin --profile web add dsh-deeppilot@alpha |
0.5.x (previous stable, latest) | DSH 0.1.1-rc.2–0.1.2-alpha.1 | dsh plugin --profile web add dsh-deeppilot |
The 0.6.0 alpha line is built against the DSH
0.1.2-alpha.2
controller and client package family, so it requires DSH 0.1.2-alpha.2 or
newer (its alpha npm dist-tag). Earlier DSH builds do not provide the Host
APIs required by this plugin. Users who need a DSH release before that must
stay on the 0.5.x plugin.
# DSH 0.1.2-alpha.2 or newer (recommended):
dsh plugin --profile web add dsh-deeppilot@alpha
# DSH 0.1.1-rc.2 through 0.1.2-alpha.1 (previous stable):
dsh plugin --profile web add dsh-deeppilot
dsh web
After DSH restarts, open Settings → DeepPilot, enable the connection, show the pairing QR code, and scan it in the DeepPilot app. The same panel also shows a copyable pairing code for Simulator or manual entry.
Package: npmjs.com/package/dsh-deeppilot
Update or uninstall
dsh plugin --profile web update dsh-deeppilot
dsh plugin --profile web remove dsh-deeppilot
Restart DSH after updating. Uninstalling the package does not delete the local
DeepPilot state under $DSH_HOME/deeppilot/.
Publishing (maintainers)
0.6.0-alpha.x targets DSH 0.1.2-alpha.2+; 0.5.x stays compatible with
DSH 0.1.1-rc.2–0.1.2-alpha.1. Keep both published:
-
Bump
versioninpackage.jsonand in the root""entry ofpackage-lock.json, then runnpm test && npm run typecheck && npm run buildand inspectnpm pack --dry-run --json(the checktests/compatibility-metadata.test.tsenforces the^0.1.2-alpha.2peer ranges). -
Commit the release and push it.
npm publishrunsprepack(build) andprepublishOnly(test + typecheck) automatically. -
Publish the alpha line without touching
latest:npm publish --tag alphaAfter a successful publish,
npm view dsh-deeppilot dist-tags --jsonshows"latest": "0.5.x"and"alpha": "0.6.0-alpha.x". Verify the published package by installing it into a DSH0.1.2-alpha.2profile before pointing users at it. -
Tag the release commit
v0.6.0-alpha.xand prepare a GitHub Release (English + 简体中文 notes) that links this README section. -
When the alpha graduates to stable, bump to
0.6.0and publish withnpm publish --tag latest, which moveslatestto the new line. Stable releases must never be published with--tag alpha.
Never run npm publish from a copy that still has the old 0.5.x version.
Connection and privacy
Conversation traffic travels directly between the iPhone and your DSH Host.
Trusted-LAN ws:// traffic is unencrypted, so use it only on a network you
trust. Optional Funnel mode exposes only the DeepPilot connection, one-time
pairing, and health endpoints, not the complete DSH Web UI.
The DeepPilot settings page exposes Connections per public source under
the collapsed Advanced settings section. It defaults to 8, accepts
1–16, and briefly restarts the Funnel helper when changed, so connected
remote clients reconnect once.
Offline push is optional. Relay mode sends only the target APNs device token and a limited notification payload; full conversation history and live output do not pass through the relay. Read PRIVACY.md and SECURITY.md before enabling remote access or push. Protocol-v2 implementation status and remaining release validation are tracked in docs/SECURITY_ROADMAP.md.
Screenshots
| Home | Sidebar | Chat | Settings |
|---|---|---|---|
![]() | ![]() | ![]() | ![]() |
Compatibility
See COMPATIBILITY.md for the tested baseline and current limitations. DSH is still evolving; include exact DSH and plugin versions when reporting an issue.
Protocol
PROTOCOL.md is the normative DeepPilot bridge protocol. Any
wire change must update that document and src/protocol.ts together and be
coordinated with the private iOS client. Protocol v2 is the only supported wire
version; upgrades from v1 require re-pairing.
Development
npm ci
npm test
npm run typecheck
npm run build
cd helper && go test ./...
Community and feedback
DeepPilot is an independent community project and is not affiliated with or endorsed by DeepSeek.
License
MIT — see LICENSE.



