Originally created by: imshaikot
The side panel runs on whichever agent CLI you already have logged in — seven so far. OpenCode (anomalyco/opencode, MIT, npm i -g opencode-ai) is the obvious next one: open source, provider-agnostic — Anthropic, OpenAI, Google, local models and a dozen more behind one CLI — and with a documented headless mode, opencode run --format json.
It is worth adding for reach as much as coverage: someone who has settled on OpenCode to keep their choice of model has no way to put it behind the side panel today.
| What a runner needs | OpenCode 1.18 |
|---|---|
| Streaming | run --format json — one event per line: step_start, text, tool_use, step_finish (with token counts), error. No closing event, so endsOnExit |
| Per-run MCP server | mcp.<name> in an inline config passed as OPENCODE_CONFIG_CONTENT, with environment for the run id |
| System prompt | instructions, a list of files appended to OpenCode's own prompt |
| Resume | --session <id>; every event carries sessionID |
| Per-run tool rules | an agent defined in that same config, with a permission ruleset ("*": "deny", then allows by name) — run with --agent <name> |
| Model / effort | --model provider/model, --variant <name> |
Everything is per invocation and nothing needs writing into the user's own config, which is the best position any runner has started from.
Each of these is a way the obvious adapter would be wrong, so each needs a test, not a comment:
{env:VAR} and {file:path} anywhere in its config, and a unicode escape does not stop it. The run's system prompt carries page text — the focused element, fetched data, file reports — so a page that says {file:~/.ssh/id_rsa} would get that file read into the prompt. The prompt has to be a file the config points at; instruction files are read verbatim.browsentic with {"*": "allow", "bash": "allow"}, their "*" keeps its place and their bash lands after our deny. The run's agent needs a name nobody picks by accident, and the reader should stop a run in which a tool outside the browser actually ran.--pure is load-bearing — and it has to cover local plugin files, not only npm ones."share": "auto" publishes every session to a public link. OPENCODE_DISABLE_SHARE must be set.opencode run reads stdin to EOF and appends it to the message. With stdin left open it hangs silently at start-up.Read, every new session spends a model call on a title, and every folder outside git shares one session list with the user's own work./ outside git.OpenCode Zen's free models will not serve a contained run. They answer only requests carrying OpenCode's own built-in tools (403 FreeTierError: free tier can only be used from within OpenCode), and a Browsentic run offers the browser's alone. That is their policy, and working around it would mean loosening containment, so the runner should instead report needs setup until OpenCode is signed in to a provider (opencode auth login) or declares one in its config.
src/daemon/agent/runners/opencode.ts, one line in RUNNERS, a catalog entry and a CONTAINMENT entry — no extension changes beyond the vendor mark.vetPlan can see the containment even though it lives in an environment variable, and refuses a plan that lost the deny, --pure, the agent name or the share switch.Not to be confused with driving Browsentic from OpenCode over MCP, which already works — that is MCP clients. This is about what runs the side panel.
Ticket changed by: imshaikot