Provider
Verifiably-private models from Tinfoil secure enclaves, for the opencode coding agent
0
286
14 in 7 days
34.5
Multi-signal model
17 days ago
2026-09-17
Install and configure
opencode.jsonWrites to this project's opencode.json — applies to this repository only.
opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["@tinfoilsh/opencode-provider@0.1.1"]
}Writes to ~/.config/opencode/opencode.json — applies to every project.
~/.config/opencode/opencode.json
{
"$schema": "https://opencode.ai/config.json",
"plugin": ["@tinfoilsh/opencode-provider@0.1.1"]
}If you want to modify the plugin locally, install it into the project and reference the local path.
shell
pnpm add -D @tinfoilsh/opencode-providerOpenCode loads npm dependencies through its embedded runtime on startup and caches them locally — no manual global install needed.
Use Tinfoil's verifiably-private open models from the opencode coding agent. Inference runs inside hardware secure enclaves that even Tinfoil cannot read into.
Setup
Install the plugin:
opencode plugin @tinfoilsh/opencode-provider --globalSet your API key:
opencode auth loginPick Tinfoil, then paste your key from the Tinfoil Dashboard.
Pick a Tinfoil model with
/models, or run one directly:opencode run --model tinfoil/gpt-oss-120b "explain this repo"
How verification works
When opencode starts, the plugin uses the
tinfoil SDK to verify the inference
enclave: it checks the enclave's attestation, confirms the running code against
the release digest signed in Sigstore, and binds the attested key to the live
connection. Every request body is then encrypted end-to-end with HPKE, so only
the verified enclave can read it.
The plugin fails closed. If verification does not succeed, requests are refused before anything leaves your machine, including your API key, your prompts and your code.
Seeing the verification state
The sidebar shows a Tinfoil section, above Context and LSP:
Tinfoil ✓ encrypted
v0.0.145 · 43fe4ff77e94
For the full verification document run /tinfoil,
or open the command palette (ctrl+p) and pick Tinfoil: verification
details.
Settings
| Variable | Default | Purpose |
|---|---|---|
TINFOIL_API_KEY |
(none) | Your tk_… key, for headless workflows. Not needed if you use opencode auth login, the preferred login for everyday operation. |
TINFOIL_DEBUG |
(unset) | Log verification and model discovery to stderr. |
Similar plugins
Finish Guard
@bandonker/opencode-finish-guard
Normalises OpenAI-compatible SSE streams so a content or reasoning delta that arrives after the finish reason cannot kill a session ("OpenAI Chat received content after the finish reason").
Omniroute V2
@piyush97/opencode-omniroute-v2
OpenCode v2 plugin for live OmniRoute model discovery, combos, authentication, and metadata.
Failover
opencode-failover
OpenCode plugin for automatic API-key failover and rotation across multiple provider keys