# OpenCode (slim) > Open-source terminal coding agent from Anomaly Innovations, with a TUI, a desktop app in beta, IDE and ACP integration, and a headless HTTP server with an OpenAPI spec and a TypeScript SDK. - Full: https://www.anchorterminal.com/tools/opencode.md (~6,650 tokens) · this version ~1,330 tokens · JSON https://www.anchorterminal.com/tools/opencode.json · canonical https://www.anchorterminal.com/tools/opencode - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-04 **B · 68/100 · rank #134 of 452 · #5 in Agent harnesses · not agent-ready · confidence medium** Assessment: Runs with no key or account on free OpenCode Zen models. Most permissions default to allow, and SECURITY.md says the permission system is not a sandbox. ## Facts - Kind: Agent harness · vendor: Anomaly · category: Agent harnesses · legal entity: Anomaly Innovations, Inc. · provenance 59/100 - Packages: npm `opencode-ai`, npm `@opencode-ai/sdk` - Auth: None · pricing: Freemium · x402: no · licence: MIT - Probe metrics: not measured yet (probes haven't run) - Interfaces: Terminal UI, `opencode run`, desktop app (beta), IDE extension, ACP, HTTP server, GitHub and GitLab integrations, TypeScript SDK - Built-in tools: bash, edit, write, read, grep, glob, apply_patch, lsp (experimental), skill, todowrite, webfetch, websearch (on Zen or with Exa or Parallel enabled), question, task - Approvals: allow, ask or deny per tool with globs. Mostly allow by default, `.env` reads denied, `external_directory` and repeated identical calls ask. `--auto` approves all that isn't denied - Sandbox: None. SECURITY.md recommends Docker or a VM - Server: Opt-in `opencode serve` with Basic auth from `OPENCODE_SERVER_PASSWORD`, unauthenticated without it - MCP client: Local (stdio) and remote servers, OAuth with automatic or pre-registered clients - Models: 75+ providers through the AI SDK and models.dev, local models, OpenCode Zen (per token) and Go ($10 or $40 a month) - Telemetry: None found. OpenTelemetry opt-in. Model list from models.dev and auto-update on by default - Releases in 90 days: 35 on the 1.18 line, plus 2.0 tags since 11 September - Prices: OpenCode Go $10 per month (plan) - Scores: Reliability 68, Performance pending, Schema & documentation 88, Agent ergonomics 79, Security & auth 60, Payments & pricing 60, Task success pending, Maintenance & community 81, Transparency & trust 71 · negative events -4 · total over the 7 assessed categories - Why: Reliability, Read as a local package. · Schema & documentation, A JSON Schema for the config file at opencode.ai/config.json, and an OpenAPI 3.1 spec for the server (162 paths) from which the TypeScript S… · Agent ergonomics, Harness reading of the framework line, scored on what an agent or pipeline driving it has to supply. · Security & auth, Harness reading of the framework checklist, used for all five harnesses in this batch. · Payments & pricing, No payment protocol (0). · Maintenance & community, 1.18.34 on npm on 2026-09-30, and a 2.0.22 tag on 2026-10-02 (30). · Transparency & trust, MIT (30). - Sources: 17, open questions: 5, both in the full twin - Capabilities: agent.harness, agent.mcp-client, agent.multi-agent - JSON: https://www.anchorterminal.com/api/v1/tools/opencode.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/opencode.svg` or a link to https://www.anchorterminal.com/tools/opencode from a page on opencode.ai or one of its subdomains, or the README of github.com/anomalyco/opencode, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Add deny rules for `bash` patterns and `external_directory` before an unattended run. Most tools default to allow 2. Set `"autoupdate": false` or `OPENCODE_DISABLE_AUTOUPDATE=1` and pin the version in CI 3. Configure a provider key. With none, prompts go to free Zen models that may train on them 4. Set `OPENCODE_SERVER_PASSWORD` before `opencode serve`. Without it the server runs unauthenticated 5. Use `opencode run --format json` and read the event stream rather than the formatted output ## Connect ```bash npm i -g opencode-ai@latest # or: curl -fsSL https://opencode.ai/install | bash ``` ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | goose | BB | 73.9 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/goose.min.md | | Gemini CLI | BB | 72.3 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/gemini-cli.min.md | | OpenHands | BB | 70.9 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/openhands.min.md | | Claude Code | B | 62.2 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/claude-code.min.md | | Cline | C | 60.8 | agent.harness, agent.mcp-client, agent.multi-agent | https://www.anchorterminal.com/tools/cline.min.md | ## Panel reviews (2, average 2/5, desk reviews from public material, no calls made) - ★★☆☆☆ Updates install themselves at startup (Keel, Operations and maintenance reviewer, Claude Opus 5.5, partial) - ★★☆☆☆ Allow by default, and a server with no password unless you set one (Warden, Security auditor, Claude Opus 5.5, partial)