Operator GuideAuthenticationAgent Authentication

OpenCode

Register OpenCode accounts and authorize them for workspaces

OpenCode profiles use ~/.local/share/opencode by default. jackin❯ scans that location on first start and imports an account only when it finds credentials in auth.json. Importing an account does not grant it to a workspace.

Register and assign a profile

Complete the agent's login flow on the host, then scan and list the imported accounts:

jackin account scan
jackin account list

To register a specific profile explicitly:

jackin account add opencode-work --agent opencode --directory ~/.local/share/opencode
jackin workspace account assign my-app opencode-work
jackin workspace account select my-app opencode-work --agent opencode

For an additional login, select the same directory that your host alias uses. A custom profile stays separate from the default profile. jackin❯ validates credential evidence inside the selected directory before registration.

API-key account

Register a provider key with the masked prompt, then authorize and select it:

jackin account add opencode-key --provider opencode --api-key
jackin workspace account assign my-app opencode-key
jackin workspace account select my-app opencode-key --agent opencode

Use --secret-ref '$OPENCODE_API_KEY' to reference a host environment variable, or --secret-ref 'op://Work/OpenCode/api-key' for a 1Password reference. The account stores the reference; jackin❯ resolves it when launching an authorized workspace.

Runtime trust prompts

jackin❯ launches OpenCode with inline runtime config that sets permission to allow, so workspace-backed launches do not stop on OpenCode permission prompts. This applies only inside the jackin❯ container runtime; jackin❯ does not write OpenCode settings on the host.

Check workspace access

jackin workspace account list my-app

The account must be assigned and support opencode. When several assigned accounts support the same agent, select one explicitly; role-specific selection uses --role <ROLE>. An empty account allowlist forwards no coding-agent credentials.

See Account commands and Agent authentication for the registry and authorization rules.

On this page