Atlas / MCP servers / alaeddinemessadi / OpenCode

OpenCodeCAUTION

mcp/alaeddinemessadi/opencode

MCP server for OpenCode AI — 70 tools, 10 resources, 5 prompts. Use npx opencode-mcp with Claude Desktop, Claude Code, Cursor, Windsurf, or any MCP client.

Verdict
CAUTION
Grade
B
Trust score
89 /100
Exposed tools
86 68r · 16w · 2d
Transport
stdio
License
MIT
Stars
145
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

[](https://www.npmjs.com/package/opencode-mcp) [](LICENSE) [](https://nodejs.org/)

Delegate coding work to OpenCode from your MCP client.

opencode-mcp connects Claude, Cursor, VS Code, and other MCP clients to OpenCode's headless API. Ask questions, implement features, monitor background work, respond to questions and permissions, and review changes across projects.

Version 3.0.0 requires Node.js 22 or newer. Upgrading from 2.x? See the migration notes.

Quick Start

Install OpenCode and start its server from your project:

opencode serve --hostname 127.0.0.1 --port 4096

If you use the TUI, start it with opencode --port 4096 and share that server. Set OPENCODE_BASE_URL for another endpoint.

For Claude Code:

claude mcp add opencode -- npx -y opencode-mcp

For clients using an mcpServers configuration:

{
"mcpServers": {
"opencode": {
"command": "npx",
"args": ["-y", "opencode-mcp"]
}
}
}

Restart the client and call opencode_setup. Choose a provider from its configured providers, then use opencode_provider_models to select a model. Set OPENCODE_DEFAULT_PROVIDER and OPENCODE_DEFAULT_MODEL together or pass the selected IDs in each prompt call.

Client-specific configuration includes VS Code, Windsurf, Continue, Zed, and Amazon Q. To test unreleased changes, build from source and configure your client to run node with the absolute path to dist/index.js.

Choose a Workflow

Read from source at commit aa814d1c2a88OBSERVED · 2026-10-07
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code
claude mcp add opencode-mcp --env OPENCODE_SERVER_PASSWORD=${OPENCODE_SERVER_PASSWORD} -- npx -y [email protected]
claude-desktop
{
  "mcpServers": {
    "opencode-mcp": {
      "command": "npx",
      "args": [
        "-y",
        "[email protected]"
      ],
      "env": {
        "OPENCODE_SERVER_PASSWORD": "${OPENCODE_SERVER_PASSWORD}"
      }
    }
  }
}
03

Exposed tools (86)

68 read · 16 write · 2 destructive. Blast radius: 2 tools can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.

ToolRiskDescription
buildreadBuild agent
opencode_agent_listreadList all available agents with their names, descriptions, and modes (primary/subagent)
opencode_askreadAsk OpenCode a question in one step. Creates a new session, sends your prompt, and returns the AI response. This is the easiest way to interact with OpenCode.
opencode_auth_setwriteSet authentication credentials for a provider (e.g. API key). Credentials are stored globally and shared across all projects.
opencode_checkreadGet current task status, pending input, todos and file counts. Uses session summary metadata instead of fetching patches. Pass jobId for exact durable turn correlation; detailed includes response text.
opencode_command_executewriteExecute a slash command in a session (e.g. /init, /undo, /redo)
opencode_command_listreadList all available commands (built-in and custom slash commands)
opencode_config_getreadGet the current opencode configuration
opencode_config_providersreadList all configured providers and their default models
opencode_config_updatewriteUpdate the opencode configuration. Pass a partial config object with fields to update.
opencode_contextreadGet full project context in one call: current project, path, VCS info, config, and available agents. Useful to understand the current state before starting work.
opencode_conversationreadGet the full conversation history of a session, formatted for easy reading. Shows all messages with their roles and content.
opencode_events_pollreadPoll project events from OpenCode, or explicitly select global scope. Collects up to maxEvents within the duration. Connection failures are reported with any partial events; stopping observation does not abort remote work.
opencode_file_listreadList files and directories at a path
opencode_file_readreadRead the content of a file
opencode_file_statusreadGet status for tracked files (VCS changes: modified, added, deleted, etc.)
opencode_find_filereadFind files and directories by name (fuzzy match)
opencode_find_symbolreadFind workspace symbols by name (functions, classes, variables, etc.)
opencode_find_textreadSearch for text patterns in project files (regex supported). Returns file paths, line numbers, and matching lines.
opencode_firereadDispatch a durable background task and return its job, session and message IDs immediately. Use opencode_check or opencode_wait to observe; job_cancel stops the task.
opencode_formatter_statusreadGet the status of configured formatters
opencode_healthreadCheck server health and version
opencode_instance_disposereadDispose the current opencode instance (shuts it down). WARNING: This is destructive and will terminate the server.
opencode_job_inputreadRespond to a job
opencode_job_listreadList locally retained jobs in this OpenCode server and credential scope.
opencode_logwriteWrite a log entry to the opencode server
opencode_lsp_statusreadGet the status of LSP (Language Server Protocol) servers
opencode_mcp_addwriteAdd an MCP server dynamically to opencode
opencode_mcp_statusreadGet the status of all MCP servers configured in opencode
opencode_message_getreadGet details of a specific message in a session
opencode_message_listreadList all messages in a session with formatted output showing roles and content
opencode_message_sendwriteSend a prompt message to a session and wait for the AI response. Use parts to send text, and optionally specify a model.
opencode_message_send_asyncwriteSend a prompt asynchronously and return its messageId. Pass sessionId and messageId to opencode_wait to observe this exact turn.
opencode_path_getreadGet the current working path of the opencode server
opencode_permission_listreadList all pending permission requests across all sessions. When a session is blocked waiting for approval (e.g. to run a shell command or access a file outside the project), it appears here. Respond with
opencode_project_currentreadGet the current active project
opencode_project_initread
opencode_project_listreadList all projects known to the opencode server
opencode_provider_auth_methodsreadGet available authentication methods for all providers
opencode_provider_listreadList all configured providers with their connection status. Returns a compact summary — use opencode_provider_models to see models for a specific provider.
opencode_provider_modelsreadList available models for a specific provider. Call opencode_provider_list first to see provider IDs.
opencode_provider_oauth_authorizewriteStart OAuth authorization for a provider
opencode_provider_oauth_callbackreadHandle OAuth callback for a provider
opencode_provider_testreadQuick-test whether a provider is working. Creates a temporary session, sends a trivial prompt, checks the response, and cleans up. Great for debugging auth issues.
opencode_question_listreadList pending OpenCode questions, optionally filtered to a session.
opencode_question_rejectreadReject a pending OpenCode question explicitly.
opencode_question_replyreadAnswer an OpenCode question request. Supply one array of selected labels or free text per question.
opencode_replywriteSend a follow-up message to an existing session. Use this to continue a conversation started with opencode_ask or opencode_session_create.
opencode_review_changesreadGet a formatted summary of all file changes made in a session. Shows diffs in a readable format.
opencode_runwriteSend a task and wait for its correlated response. Returns a durable job ID; an observation timeout leaves the remote job running and can be resumed with opencode_wait.
opencode_session_abortreadAbort a running session
opencode_session_childrenreadGet child sessions of a session
opencode_session_createwriteCreate a new session. Optionally provide a parentID to create a child session, and a title.
opencode_session_deletedestructiveDelete a session and all its data
opencode_session_diffreadGet the diff for a session, optionally for a specific message
opencode_session_forkreadFork an existing session, optionally at a specific message
opencode_session_getreadGet details of a specific session by ID
opencode_session_initwriteAnalyze the app and create AGENTS.md for a session. NOTE: This is a long-running operation that may take 30-60+ seconds depending on project size.
opencode_session_listreadList all sessions
opencode_session_permissionreadRespond to a permission request in a session. Use
opencode_session_revertreadRevert a message in a session
opencode_session_searchreadSearch sessions by keyword in title. Useful for finding a specific session among many.
opencode_session_sharereadShare a session publicly
opencode_session_statusreadGet status for all sessions (running, idle, etc.)
opencode_session_summarizereadSummarize a session using a specified model. NOTE: This is a long-running operation that may take 30-60+ seconds.
opencode_session_todoreadGet the todo list for a session
opencode_session_unrevertreadRestore all reverted messages in a session
opencode_session_unsharereadUnshare a previously shared session
opencode_session_updatewriteUpdate session properties (e.g. title)
opencode_sessions_overviewreadGet a quick overview of all sessions with their titles and status. Useful to find which session to continue working in.
opencode_setupreadCheck OpenCode status, provider configuration, and optionally initialize a project directory. Use this as the first step when starting work — it tells you what is ready and what still needs configuration.
opencode_shell_executewriteRun a shell command through the opencode session
opencode_statusreadGet a quick status dashboard: server health, provider count, session count, and VCS info. Lighter than opencode_setup — good for at-a-glance checks.
opencode_tool_idsreadList all available tool IDs that the LLM can use (experimental)
opencode_tool_listreadList tools with JSON schemas for a given provider and model (experimental)
opencode_tui_append_promptreadAppend text to the TUI
opencode_tui_clear_promptdestructiveClear the current prompt text in the TUI
opencode_tui_execute_commandwriteExecute a slash command through the TUI (e.g.
opencode_tui_open_helpreadOpen the help dialog in the TUI
opencode_tui_open_modelsreadOpen the model selector in the TUI
opencode_tui_open_sessionsreadOpen the session selector in the TUI
opencode_tui_open_themesreadOpen the theme selector in the TUI
opencode_tui_show_toastreadShow a toast notification in the TUI
opencode_tui_submit_promptwriteSubmit the current prompt in the TUI (equivalent to pressing Enter)
opencode_vcs_inforeadGet VCS (version control) info for the current project (branch, remote, status)
opencode_waitreadWait for a session or durable job. Returns completed, failed, input_required, or a resumable timeout. Cancelling this wait stops observation; use job_cancel or session_abort to stop OpenCode.
04

Trust audit

CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfaceWARN
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (1 observation(s))
Network
declared (3 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
none-found

Findings (10)

MEDIUMNetwork egress · net.raw_ip · CWE-200, CWE-319
src/helpers.ts:622
tips.push("- Verify OPENCODE_BASE_URL is correct (default: http://127.0.0.1:4096)");
MEDIUMFilesystem / path · mcp.destructive_tools · CWE-22, CWE-59
opencode_session_delete, opencode_tui_clear_prompt
Why it matters. 2 tool(s) can delete or overwrite
Fix. prefer a read-only mode or scoped tokens; the page states the blast radius
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/project-tool.test.ts:123
const result = await callInit({ path: "/etc/foo" });
LOWFilesystem / path · fs.system_paths · CWE-22, CWE-59
tests/tools.test.ts:1563
patterns: ["/etc/hosts"],
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
README.md:88
| `OPENCODE_BASE_URL` | Server endpoint; defaults to `http://127.0.0.1:4096` |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/configuration.md:9
| `OPENCODE_BASE_URL` | `http://127.0.0.1:4096` | OpenCode HTTP endpoint |
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
docs/configuration.md:44
claude mcp add opencode --env OPENCODE_BASE_URL=http://127.0.0.1:8080 -- npx -y opencode-mcp
LOWNetwork egress · net.raw_ip · CWE-200, CWE-319
scripts/mcp-smoke-test.mjs:20
baseUrl: env.OPENCODE_BASE_URL ?? "http://127.0.0.1:4096",
LOWSupply chain · supply.unpinned · CWE-829, CWE-1357
package.json
@modelcontextprotocol/core, @modelcontextprotocol/server, @opencode-ai/sdk, zod, @modelcontextprotocol/client, @modelcontextprotocol/sdk, @types/node, @vitest/coverage-v8
Why it matters. 10 dependency range(s) float
Fix. pin exact versions or ship a lockfile
LOWPrompt injection · prompt.transfer_instruction · CWE-94, CWE-1427
docs/getting-started.md:72
Check its current state and pending input. Use `opencode_job_list` to rediscover tracked work after reconnecting. A server/network error or `unknown` state is not a reason to submit the same prompt ag
Why it matters. an instruction to move sensitive data to an outside destination
Fix. remove; a skill never needs the user's secrets off the machine

Gates applied: no_behavioural_pass.

Audited 2026-10-07 · audit v0.4.1 · source sha aa814d1c2a88full audit observations/trust-audit/mcp-server/alaeddinemessadi__opencode.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-07aa814d1c2a88CAUTIONB89first audit
06

Questions

What is the OpenCode MCP server?

MCP server for OpenCode AI — 70 tools, 10 resources, 5 prompts. Use npx opencode-mcp with Claude Desktop, Claude Code, Cursor, Windsurf, or any MCP client.

What tools does OpenCode expose?

86 in total: 68 read-only, 16 that write, and 2 that can delete or overwrite (opencode_session_delete, opencode_tui_clear_prompt). Every one is listed on this page with its risk.

Is OpenCode safe to connect to an agent?

With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 2 of its tools can destroy data, so scope the token you give it to what you actually need.

What credentials does OpenCode need?

It reads OPENCODE_SERVER_PASSWORD from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does OpenCode run?

It speaks stdio, so it runs as a local process your client starts. It is published on npm as opencode-mcp at 3.0.0.

How current is this page?

The grade is for one exact copy of the source (aa814d1c2a88), read on 2026-10-07. The repository is watched and re-audited when it changes.

Advertisement