跳到主要内容
    ↑↓ 选择↵ 打开esc 关闭
    tinfoilsh

    Provider

    @tinfoilsh/opencode-provider·v0.1.1·模型接入

    Verifiably-private models from Tinfoil secure enclaves, for the opencode coding agent

    GitHub 星标

    0

    月装机量

    286

    近 7 天 14

    综合评分

    34.5

    生态多维模型

    最近提交

    17 天前

    2026-09-17

    快速安装与配置

    opencode.json

    写入当前项目的 opencode.json,只对这个仓库生效。

    opencode.json

    {
      "$schema": "https://opencode.ai/config.json",
      "plugin": ["@tinfoilsh/opencode-provider@0.1.1"]
    }

    OpenCode 启动时会通过内嵌运行时自动加载 npm 依赖并缓存至本地目录,无需手动在全局环境执行安装。

    Use Tinfoil's verifiably-private open models from the opencode coding agent. Inference runs inside hardware secure enclaves that even Tinfoil cannot read into.

    npm Documentation

    Setup

    1. Install the plugin:

      opencode plugin @tinfoilsh/opencode-provider --global
      
    2. Set your API key:

      opencode auth login
      

      Pick Tinfoil, then paste your key from the Tinfoil Dashboard.

    3. Pick a Tinfoil model with /models, or run one directly:

      opencode run --model tinfoil/gpt-oss-120b "explain this repo"
      

    How verification works

    When opencode starts, the plugin uses the tinfoil SDK to verify the inference enclave: it checks the enclave's attestation, confirms the running code against the release digest signed in Sigstore, and binds the attested key to the live connection. Every request body is then encrypted end-to-end with HPKE, so only the verified enclave can read it.

    The plugin fails closed. If verification does not succeed, requests are refused before anything leaves your machine, including your API key, your prompts and your code.

    Seeing the verification state

    The sidebar shows a Tinfoil section, above Context and LSP:

        Tinfoil ✓ encrypted
          v0.0.145 · 43fe4ff77e94
    

    For the full verification document run /tinfoil, or open the command palette (ctrl+p) and pick Tinfoil: verification details.

    Settings

    Variable Default Purpose
    TINFOIL_API_KEY (none) Your tk_… key, for headless workflows. Not needed if you use opencode auth login, the preferred login for everyday operation.
    TINFOIL_DEBUG (unset) Log verification and model discovery to stderr.

    同类生态推荐