Start typing to search the documentation.

CLI navigation

Providers

Connect a provider in the TUI, then choose one of its models:

/connect
/models

/connect lists the integrations available from the current server and project. Select a provider, choose an authentication method when it offers more than one, and follow the prompts.

TUI

The TUI supports API keys, OAuth, and provider authentication commands. OAuth opens an authorization URL or shows a code to enter; press o to open the URL and c to copy the authorization details.

/connect
# Select OpenAI, then ChatGPT Pro/Plus (headless).

Run /connect again to add another account. Selecting an already connected provider opens its account list, where you can activate, rename, or delete a saved account.

CLI

Use auth login for the same provider methods without opening the TUI. With no provider argument, the command opens an interactive provider picker.

opencode auth login

Pass an integration ID or name to skip the first picker. Use --method key to select API-key entry explicitly.

opencode auth login anthropic --method key

Method IDs are provider-specific. Run the command without --method to see the available methods when a provider has more than one.

opencode auth login openai

API-key entry and provider forms require an interactive terminal. OAuth methods that ask you to paste an authorization code also require one.

Methods

OpenCode receives provider credentials through four integration methods:

MethodBehavior
API keyPrompts for a secret and saves it as a provider account.
OAuthProvides a browser URL, device code, or authorization-code prompt, then saves tokens and refreshes them when supported.
CommandRuns a provider-supplied authentication command and saves its standard output as a key.
EnvironmentReads a supported variable from the server process without saving it.

Providers can add forms to API-key and OAuth methods for required details such as an Azure resource name or a GitHub Enterprise domain. The CLI and TUI render those forms before starting authentication.

Environment

Set a provider’s supported environment variable on the server process that runs model requests. For a one-off private server, pass it when starting standalone mode.

ANTHROPIC_API_KEY=sk-ant-... opencode --standalone

For the shared background server, add the variable to its managed environment. This stops a running service; the next OpenCode command starts it with the new value.

opencode service set env ANTHROPIC_API_KEY sk-ant-...
opencode auth list

Environment connections appear in auth list with type environment. They are not accounts: auth logout cannot remove them, so unset the variable to disconnect. A saved account takes precedence over an environment connection for the same integration.

opencode auth list
opencode service unset env ANTHROPIC_API_KEY

Some cloud providers also use their native ambient credential chain instead of an API-key variable:

  • Amazon Bedrock supports the AWS default credential chain, including profiles, access-key environments, web identity, and container credentials. It also supports AWS_BEARER_TOKEN_BEDROCK.
  • Google Vertex uses Application Default Credentials and a resolvable project. For example, authenticate with gcloud auth application-default login and set GOOGLE_CLOUD_PROJECT.
  • Azure exposes Microsoft Entra ID (Azure CLI) as a connect method when az is installed. Run az login first, then select that method in /connect or auth login azure.
gcloud auth application-default login
GOOGLE_CLOUD_PROJECT=my-project opencode

See Providers for provider-specific and server-side setup.

Accounts

Each successful API-key, OAuth, or command login creates a saved account. The newest account becomes active; switch the active account by its label or credential ID.

opencode auth list
opencode auth switch anthropic work

Remove a saved account with auth logout. Both commands open pickers when their arguments are omitted.

opencode auth logout anthropic work

In the TUI, /connect provides the same add, activate, rename, and delete operations for saved accounts.

Storage

Saved API keys and OAuth tokens live in the server’s SQLite database. For the local server, print its database path with:

opencode debug paths db

The usual release path is ~/.local/share/opencode/opencode.db; XDG_DATA_HOME, the release channel, and OPENCODE_DB can change it. Do not edit the database to manage credentials; use /connect or the auth commands.

V2 imports supported credentials from the legacy auth.json in the OpenCode data directory during its database migration. New and updated credentials are stored in SQLite rather than written back to that file.