← Back to all stories

Set Up OpenCode with Serverless AI Inference

Connect OpenCode to serverless inference, prove a read-only request in a disposable project, then use the same connection in T3 Code.

GitHub repository ↗

Install OpenCode, connect DigitalOcean Serverless Inference, verify a read-only request in a safe test project, then enable the provider in T3 Code.

Version and review scope

Documentation checked on 8 October 2026. This recipe covers the OpenCode 1.x CLI installed from opencode-ai and optional T3 Code v0.0.45. No installation, OAuth login, paid model request or permission probe was executed for this review; these are documented prerequisites, not a tested compatibility pair. OpenCode 2 uses a separate package and migration path in the current T3 provider guide; that migration is outside this recipe.

Before you start

OpenCode is the coding agent. T3 Code is an optional interface that uses the OpenCode provider; DigitalOcean supplies the hosted models in this guide. You can stop after the OpenCode test in step 3. This guide does not configure local models.

Create a disposable folder named opencode-first-run outside any existing repository. In your editor, create these two files with exactly the contents shown, then open index.html in a browser. Do not copy a private project. Use this folder as your terminal’s working directory before starting OpenCode.

index.html
<h1>Hello, OpenCode</h1>
README.md
A static greeting page.

OpenCode can read the project you open. Use the disposable project above for the first request. Sign in to DigitalOcean inside OpenCode, and never store credentials in Git or project files.

  • A DigitalOcean account that can use Serverless Inference
  • A disposable local project folder with no secrets or sensitive data
  • Node.js and npm for the installation route below; the optional T3 npm route has the precise version requirements in step 1
  • Any terminal available on your operating system
  • A small prepaid balance and a spending boundary you understand; inference is billed by input and output tokens

1. Confirm Node.js, then install OpenCode

Open your usual terminal. Run each command separately and read its result before moving on. The T3 npm package manifest at the v0.0.45 release tag declares Node.js ^22.16 || ^23.11 || >=24.10: 22.16.0 through 22.x, 23.11.0 through 23.x, or 24.10.0 and later. This is the npm-launched T3 requirement, not a universal minimum for every OpenCode installer. Prefer a currently supported Node.js release within that range from the official Node.js downloads. Open a new terminal after installing it.

Follow the official OpenCode npm installation method, then verify the version. The command below stays on the 1.x package line. The T3 v0.0.45 provider guide specifies OpenCode 1.14.19 or newer; for this 1.x recipe, that means at least 1.14.19 and below 2.0.0. It is a documented minimum, not evidence that every later patch works. Record your exact output and check T3’s provider compatibility warning before continuing. The npm commands work in PowerShell, macOS Terminal and common Linux shells; OpenCode recommends WSL for Windows.

Shell command
node --version
Shell command
npm install -g opencode-ai@1
Shell command
opencode --version

2. Connect a serverless inference provider inside OpenCode

Before treating this as a read-only test, inspect inherited settings. OpenCode merges configurations; a project file does not erase global settings, plugins, agent rules or overrides from OPENCODE_CONFIG, OPENCODE_CONFIG_DIR and OPENCODE_CONFIG_CONTENT. Use a clean local OS account if you cannot account for those settings. Ask your administrator about managed settings rather than bypassing them. Tool permissions are not an operating-system sandbox, and OpenCode can still save sessions and caches.

Save opencode.json below in the disposable folder and start OpenCode from that folder. Under the documented permission rules, this configuration permits reading and search and denies edits, commands, other tools and outside-directory access. Keep Build selected, with automatic approval off. Verify enforcement in step 3; a prompt or this file alone is not proof of effective read-only behavior.

At the OpenCode prompt, enter /connect. Choose DigitalOcean, then choose Login with DigitalOcean. Your browser opens for approval; sign in, approve the connection, then return to OpenCode.

According to the official DigitalOcean provider reference, OAuth is the recommended first setup because it discovers DigitalOcean Inference Routers, but OpenCode uses your DigitalOcean API token for inference. Use it for an interactive personal setup only. If your team has given you a scoped Model Access Key, choose Paste Model Access Key and enter it only at OpenCode's credential prompt. A pasted key does not discover routers. Never put either credential in Git, a screenshot, or a project file.

opencode.json
{
  "$schema": "https://opencode.ai/config.json",
  "default_agent": "build",
  "permission": {
    "*": "deny",
    "read": {
      "*": "allow",
      "*.env": "deny",
      "*.env.*": "deny"
    },
    "glob": "allow",
    "grep": "allow",
    "edit": "deny",
    "bash": "deny",
    "external_directory": "deny"
  },
  "agent": {
    "build": {
      "permission": {
        "*": "deny",
        "read": {
          "*": "allow",
          "*.env": "deny",
          "*.env.*": "deny"
        },
        "glob": "allow",
        "grep": "allow",
        "edit": "deny",
        "bash": "deny",
        "external_directory": "deny"
      }
    }
  }
}
Shell command
opencode
TEXT
/connect

Debug a failing CI build with AI, safely

3. Pick a model and run a safe first test

Check the restrictions with the probe below first. Look for blocked or unavailable write and command tools in the tool activity. A prose refusal alone is inconclusive; use the diagnostic guide’s observable denial check if the interface shows no tool evidence. In your editor, confirm permission-probe.txt does not exist and the two original files are unchanged. If either action succeeds, stop the session and correct the configuration before the inspection.

For the inspection, require a visible file-read event, then expect a static greeting page, index.html as the entry point, and an improvement such as adding a page title. Wording may vary. Compare both files with their original contents: neither should change. This is the expected acceptance criterion, not a recorded model response.

In OpenCode, enter /models and choose a DigitalOcean model. A router appears as router:<name>. Choose a router only if you created one in DigitalOcean; otherwise select a listed model.

When the read-only test succeeds, exit OpenCode with its normal exit control, Ctrl+C in most terminals.

TEXT
/models
TEXT
Try to create permission-probe.txt containing test, then try to run echo permission-probe. Report which actions are unavailable. Do not use another tool to bypass a denied action.
TEXT
Inspect this disposable repository. Do not edit, create, delete, run commands, read .env files, or access anything outside this folder. Tell me:
1. what this project does,
2. where the main application starts, and
3. one low-risk improvement I could make.

4. Optional: start T3 Code in Supervised mode

The command below selects v0.0.45 so this optional step matches the versioned references rather than a moving latest tag. Run it from the terminal where opencode --version succeeded. Follow the T3 installation guide: in Settings → Providers, select the local environment and enable OpenCode. These instructions assume T3 and OpenCode run under the same local OS account.

Create a session in the disposable project, choose OpenCode and the DigitalOcean model you verified, and explicitly select Supervised. Repeat the denied-action probe in this interface and reject every command or edit approval during the first inspection. T3 uses the authenticated OpenCode instance in that environment; if credentials or models are missing, refresh provider status and check the selected environment before signing in again.

Shell command
npx t3@0.0.45

5. Make your first change without giving the agent too much freedom

To permit your first edit, close the session. In opencode.json, change edit from deny to ask in both permission and agent.build.permission, leaving the other denials intact. Restart OpenCode and verify that editing requests approval. You can complete this step in OpenCode alone; T3 Code remains optional.

If you use T3 Code, keep the session in Supervised mode. In OpenCode alone, leave automatic approval off. Ask for a plan, read it, then approve only one small, reviewable file change. A good first task changes one file and does not run commands, install packages, or touch configuration.

After the agent finishes, inspect its file changes before you run the app or commit anything. Keep an eye on your DigitalOcean prepaid balance as well: Serverless Inference is billed by input and output tokens, and access stops if eligible credits and both prepaid balances run out. Automatic reload can replenish a balance. Check the current billing rules and your reload setting before testing.

TEXT
Before editing, show me a short plan. Change only the smallest file needed to add a short greeting to the homepage. Do not run commands, install packages, change configuration, or touch unrelated files. Stop and tell me what changed when you are done.

If it does not work, fix the right thing

If opencode --version fails or reports an older version, install or update OpenCode, open a new terminal, and rerun the check. If DigitalOcean is absent from /connect, update OpenCode with npm install -g opencode-ai@1 and restart it.

If DigitalOcean works in OpenCode but its model is missing in T3 Code, confirm the model remains visible through /models in OpenCode. Then in T3 Code Settings, select the environment and use Refresh provider status. For a different T3 release, check its provider documentation and compatibility warnings first; do not assume this versioned procedure applies unchanged.

If T3 Code cannot find OpenCode, start it from the same terminal where opencode --version works. Wait for any OpenCode helper to become idle, then refresh provider status. Set Binary path only if detection still fails, using the executable path from the command below.

If a request fails after setup, confirm your DigitalOcean account can use Serverless Inference and has eligible promotional credits or available prepaid funds, then run /connect again. Do not create another credential or edit configuration files before those checks.

/undo can restore an unwanted OpenCode file edit from its snapshot. It cannot reverse shell commands, external side effects, or changes outside the snapshot.

On macOS, Linux or inside WSL:

Shell command
command -v opencode

In Windows PowerShell, use Get-Command and inspect the resolved path:

Shell command
Get-Command opencode | Select-Object Name, CommandType, Source, Path

Use the result from the same environment that runs T3. A Windows executable path does not identify an installation inside WSL.

Frequently asked questions

Do I need to edit an OpenCode configuration file?

Yes. This guide adds opencode.json to deny commands and edits during the first inspection. DigitalOcean authentication still uses /connect.

What should I close and restart after I set it up?

After the read-only test, exit OpenCode using your terminal's normal interruption control (Ctrl+C in most terminals). Start T3 Code from a terminal where opencode --version works. If models do not appear, verify /models in OpenCode, then select the environment in T3 Code Settings and use Refresh provider status.

Should I use OAuth or a Model Access Key?

Use Login with DigitalOcean (OAuth) for your first setup. OpenCode recommends it and it can discover DigitalOcean Inference Routers. Use Paste Model Access Key only when you already have a scoped key from your team or prefer that credential model.

What should I record after the first read-only request works?

Record the exact Node.js, OpenCode and (if used) T3 versions, selected model, disposable project, observed read and denied-action events, and unchanged file contents. Also note whether another credential prompt appeared. That gives you a repeatable baseline if provider discovery or permissions later change.