DeepSeek Harness v0.2.1-alpha.1
DeepSeek Harness v0.2.1-alpha.1: Mods, Plugins & Web
- Author
- DeepSeekAgent.io Editorial Team
- Published
- Updated
DeepSeek Harness v0.2.1-alpha.1 was released on October 3, 2026. It is not the new npm default: latest and next still point to 0.2.0-rc.2, so users must install 0.2.1-alpha.1 explicitly or select the alpha channel to receive these changes.
The release concentrates on three areas: an experimental Claude Code Mods compatibility layer, an Agent-assisted route into Creator mode for authoring plugins, and --public-url for reverse-proxy deployments. It also changes proactive-compaction headroom, session diagnostics, and several plugin extension points that custom Profiles must review before upgrading.
Major changes
| Area | Update |
|---|---|
| Claude Code Mods | Experimental bridge maps Mod hook chains onto DSH extension points |
| Plugin creation | Plugin Manager can carry an unsent draft into Creator so the Agent can author a DSH Plugin |
| Web deployment | --public-url advertises a public origin with an optional reverse-proxy path prefix |
| Developer Tools | Optional bundle adds raw Session logs, transcript navigation, and Host diagnostics |
| Session UX | New sessions accept unsent initial prompts and preserve file, folder, and Session references across workspace moves |
| Long sessions | Proactive compaction reserves request output and additional context headroom |
| Automation | Automation becomes part of Web, with reminder tools limited to Standard, Creator, and PTC |
Claude Code Mods: a compatibility experiment, not a full replacement
The official release describes this as an alpha interface-compatibility experiment. DSH uses defineMod to wrap a Mod's register(on, options) as a Cordis Plugin, then maps selected events and $ methods onto Harness services.
The bridge currently covers paths including session.start, prompt.submit, turn.start, tool.call, turn.complete, command.run, ui.render, and session.end. A Mod can register commands and tools, read Session facts, work with files, and draw a band above the prompt.
It does not implement every Claude Code event, Pane, Telemetry, Managed Tier, or settings interface. The official Token Weather, Blast Radius, and Replay Theater examples work through the bridge, while larger Mods that require agent.spawn, prompt.context, Telemetry, or a placed Pane do not run unchanged.
Security is another hard boundary. A Mod runs inside the Host process like a DSH Plugin and is not protected by the Agent sandbox. It can access the process environment, network, files, and Harness tools. Mount only a Mod you are willing to execute as local application code.
Let the Agent create a plugin
Plugin Manager's Add plugin menu now includes “Let the agent create a plugin.” The action closes the menu, enters Creator mode, and preserves the unsent draft; work starts only after the request is submitted.
This removes the context break of leaving the current task and manually entering Creator, but it does not remove installation review. Inspect the generated Bundle's:
package.jsonandcordis.ymldeclarations;- Host-side file, network, and process authority;
- dependency build scripts;
- cleanup behavior after disable, uninstall, and HMR;
- exported localized labels, descriptions, and icons.
What --public-url actually solves
DSH Web still listens on loopback. --public-url tells the browser, interface, and model which external address users actually visit:
dsh --profile web \
--public-url https://app.example/ui/ \
--trusted-host app.example
--public-url neither exposes the listener nor trusts the hostname. The reverse proxy must preserve the browser-facing Host, strip /ui/ before forwarding, carry WebSocket upgrades, and rewrite the cookie Path to the mount. --trusted-host admits the authority to the API fence; the launch token and signed session cookie provide authentication.
Developer Tools and session observability
The optional Developer Tools Bundle exposes raw Session logs, two-way navigation between collapsed chat groups and transcript content, and embedded Host diagnostics. It helps answer questions such as “which events were persisted beneath this visible turn?” and “why did a tool record land outside the expected group?”
Raw diagnostics can contain prompts, tool arguments, paths, and response content. Do not paste complete logs into public tickets or show them in an untrusted screen share. Third-party Session tabs may remain visible even when the built-in Developer Tools setting is off and must be assessed under the plugin's own authority.
Compaction now reserves more than a window ratio
In 0.2.1-alpha.1, proactive compaction combines the resolved context window W, request-output reservation O, and additional headroom:
floor(min(W × thresholdRatio, W − O − headroomTokens))
The default thresholdRatio is 0.8, and headroomTokens defaults to 65,536. DSH can therefore compact before history reaches 80% when one full output would otherwise leave too little room to generate a summary. Capacity is resolved from the active Provider route and recalculated after a Provider or model switch.
Plugin migrations
Two breaking changes need explicit review:
- runtime invariant plugins and package
./invariantexports are removed; - the former composer
statsextension is split intoactivityandusageentries.
Third-party plugins and custom Profiles that use those seams must migrate. The release fixes missing dependency maps after enabling a Bundle and stale maps after disabling or uninstalling one, but replacing an installed package version still requires a restart.
Should you upgrade?
Most users should remain on npm latest, currently 0.2.0-rc.2. Test the alpha in an isolated Profile when you need to:
- evaluate Claude Code Mod portability;
- publish Web behind a prefixed reverse-proxy route;
- inspect raw Session and Host diagnostics during plugin development;
- verify the new proactive-compaction policy on long sessions.
Back up Profiles and Sessions, pin the complete version, and test invariant imports, composer extension IDs, HMR disposal, and dependency resolution before moving a primary workspace.
Related reading
- Claude Code Mods and DSH Plugins: Bridge, Capability Boundaries, and Migration
- Publishing DeepSeek Harness Web Behind a Reverse Proxy
- DeepSeek Harness Long-Session Cost and Compaction
- DeepSeek Harness Plugin Manager Source Analysis