# OpenCode

The open-source coding agent for terminal, desktop, IDE and web

**Verdict: conditional.** OpenCode is a free, MIT-licensed coding agent for terminal, desktop, IDE and web that works with 75+ model providers, plus optional paid Zen and Go model plans. The condition is trust: its permissions docs describe permission rules, not a sandbox, most permissions default to allow, and a High-severity advisory hit npm-, pnpm- and Bun-installed copies running `opencode serve`. Right for developers who patch fast and isolate it in a VM or container. Last verified 2026-10-03.

OpenCode describes itself as "an open source agent that helps you write code in your terminal, IDE, or desktop" (opencode.ai). The docs list a terminal UI, desktop app, IDE extension and web interface, and the repo describes a CLI and desktop app. It connects to Claude, GPT, Gemini and "75+ LLM providers through Models.dev, including local models", and supports GitHub Copilot and ChatGPT Plus/Pro logins. Features named in the docs: LSP integration, multi-session, shareable session links (`/share`), plan mode (Tab), undo/redo, image drag-and-drop, project init that writes `AGENTS.md`, MCP server configuration, Agent Skills, plugins, an SDK and a headless HTTP server (`opencode serve`, default 127.0.0.1:4096, optional basic auth via `OPENCODE_SERVER_PASSWORD`). The GitHub repo (anomalyco/opencode, maintained by Anomaly) is MIT-licensed and showed 211.5k stars at fetch. The site says OpenCode "does not store any of your code or context data". The enterprise page says the optional `/share` feature, when enabled, sends the conversation and its data to the service that hosts share pages at opencode.ai, and recommends disabling it for trials. Security: the permissions docs say most permissions default to "allow" (doom_loop and external_directory default to "ask"; .env reads are denied by default) and the page we read does not describe sandboxing of tool execution. GitHub advisory GHSA-632h-h47v-g4x4 (High, CVSS 7.5, no CVE, published 2026-09-24): the `/global/upgrade` endpoint accepted cross-origin requests without origin validation, so a malicious web page could cause installation of an attacker-chosen package where OpenCode was installed via npm, pnpm or Bun and the victim ran `opencode serve`; curl, Homebrew, Chocolatey and Scoop installs are described as unaffected. Affected versions: the advisory's description says impacted versions are believed to span v1.14.30 through v1.18.16 (the structured field reads >=1.14.30). Patched: 1.18.22. Paid options: OpenCode Zen (curated models, pay as you go, per-model price table on opencode.ai/docs/zen; the docs say prices pass along price drops by selling at cost and that credit card fees are passed along at cost, 4.4% + $0.30 per transaction) and OpenCode Go ($10/month, Go Plus $40/month, 30+ models, usage limits expressed as monthly dollar amounts per model with 5-hour, weekly and monthly tiers). Enterprise: central config, SSO, internal AI gateway support, per-seat pricing by quote.

## Strengths

- Developers who want one agent across terminal, desktop, IDE and web with their pick of 75+ providers, including local models
- Teams that want a free MIT-licensed base and an optional enterprise layer (SSO, central config, internal gateway)
- Low-cost model access through Go at $10/month, with usage limits expressed as dollar caps per model
- Running untrusted repositories or unattended jobs on a machine holding secrets (the docs we read describe permissions, not a sandbox, and most default to allow)
- Anyone running `opencode serve` on an unpatched npm-, pnpm- or Bun-installed copy (GHSA-632h-h47v-g4x4, fixed in 1.18.22)
- Teams that cannot absorb Zen card fees, which the Zen docs say are passed along at cost (4.4% + $0.30 per transaction)

## Pricing

- Model: open-source
- Open source: Free (MIT)
- Zen: Pay as you go
- Go: $10/mo
- Go Plus: $40/mo
- Enterprise: Custom

Website: https://opencode.ai

## Sources

- [OpenCode docs](https://opencode.ai/docs/)
- [OpenCode Zen](https://opencode.ai/zen)
- [OpenCode GitHub repository](https://github.com/anomalyco/opencode)
- [GitHub advisory GHSA-632h-h47v-g4x4](https://github.com/anomalyco/opencode/security/advisories/GHSA-632h-h47v-g4x4)
- [OpenCode Zen docs (card fees)](https://opencode.ai/docs/zen/)
- [OpenCode Go docs](https://opencode.ai/docs/go/)
- [OpenCode enterprise docs](https://opencode.ai/docs/enterprise)
- [OpenCode permissions docs](https://opencode.ai/docs/permissions/)
- [OpenCode site](https://opencode.ai)
- [OpenCode server docs](https://opencode.ai/docs/server/)

Canonical: https://neomanex.com/directory/opencode
