Skip to content
    ↑↓ select↵ openesc close
    tinfoilsh

    Provider

    @tinfoilsh/opencode-provider·v0.1.1·Model Providers

    Verifiably-private models from Tinfoil secure enclaves, for the opencode coding agent

    GitHub stars

    0

    Monthly installs

    286

    14 in 7 days

    Composite score

    34.5

    Multi-signal model

    Last commit

    17 days ago

    2026-09-17

    Install and configure

    opencode.json

    Writes to this project's opencode.json — applies to this repository only.

    opencode.json

    {
      "$schema": "https://opencode.ai/config.json",
      "plugin": ["@tinfoilsh/opencode-provider@0.1.1"]
    }

    OpenCode loads npm dependencies through its embedded runtime on startup and caches them locally — no manual global install needed.

    Use Tinfoil's verifiably-private open models from the opencode coding agent. Inference runs inside hardware secure enclaves that even Tinfoil cannot read into.

    npm Documentation

    Setup

    1. Install the plugin:

      opencode plugin @tinfoilsh/opencode-provider --global
      
    2. Set your API key:

      opencode auth login
      

      Pick Tinfoil, then paste your key from the Tinfoil Dashboard.

    3. Pick a Tinfoil model with /models, or run one directly:

      opencode run --model tinfoil/gpt-oss-120b "explain this repo"
      

    How verification works

    When opencode starts, the plugin uses the tinfoil SDK to verify the inference enclave: it checks the enclave's attestation, confirms the running code against the release digest signed in Sigstore, and binds the attested key to the live connection. Every request body is then encrypted end-to-end with HPKE, so only the verified enclave can read it.

    The plugin fails closed. If verification does not succeed, requests are refused before anything leaves your machine, including your API key, your prompts and your code.

    Seeing the verification state

    The sidebar shows a Tinfoil section, above Context and LSP:

        Tinfoil ✓ encrypted
          v0.0.145 · 43fe4ff77e94
    

    For the full verification document run /tinfoil, or open the command palette (ctrl+p) and pick Tinfoil: verification details.

    Settings

    Variable Default Purpose
    TINFOIL_API_KEY (none) Your tk_… key, for headless workflows. Not needed if you use opencode auth login, the preferred login for everyday operation.
    TINFOIL_DEBUG (unset) Log verification and model discovery to stderr.

    Similar plugins