Use eb1 with OpenCode

Install the opt-in opencode-keiro launcher. Plain opencode, your global packages, and your opencode.json / opencode.jsonc stay unchanged.

On this page 1 of 5

Install and configure#

Create a dedicated key on the console's API keys page. Keep the newly revealed secret available in your password manager until setup is complete. On macOS or Linux, with bash, curl and Node 22.15 or later installed, run the complete command from the directory where you intend to use OpenCode:

Run a curl request Shell
bash -c "$(curl -fsS 'https://api.keirolabs.ai/v1/opencode/install.sh')"

The console supplies this command using its configured API base. The entire HTTPS download completes before execution, and the script runs its main function only on its final line, so a truncated download runs nothing. The X-Content-SHA256 response header checks the downloaded bytes; it is not an independent signature. For inspection or key-file input, download to keiro-opencode.sh, inspect it, then run bash keiro-opencode.sh.

Setup reuses a compatible OpenCode installation from any channel. The pinned runtime is opencode-ai@1.18.11; other releases require a compatibility update. If OpenCode is absent, npm is required to install that exact release into a private directory. Setup never installs Node or npm, upgrades an external installation, runs a global npm install, or creates a plain opencode command. An incompatible external executable must be upgraded through its original installation channel. Only incompatible Keiro-managed runtimes are replaced, side by side, with the previous generation retained for rollback.

Enter the key at the hidden local prompt. Without a terminal, supply --key-file /absolute/path/to/key. That input must be a current-user-owned regular file with mode 0600 and one nonempty token (at most 4096 bytes; one final newline is allowed). Symlinks and multiline credentials are refused. --key is refused because it exposes the key in shell history and the process list.

Setup verifies a bounded authenticated GET to the configured /models endpoint. Redirects, authorization errors, throttling, malformed responses and network failures stop activation. No inference request is made. “Verified” covers authentication and configuration in the inspected directory, not future projects, plugin behavior, remote policies or completed inference.

Start with the command printed by setup:

Run in the terminal Shell
opencode-keiro

Fresh sessions select keiro/eb1-preview. An explicit --model wins; --continue and --session keep the resumed session's model. Change directory before launching; project and directory override arguments are rejected when their configuration scope cannot be inspected. Use plain opencode for administrative commands, including debug, upgrade, and remote attachment. Never run opencode debug config with a real key: it can print resolved secrets.

Files and credentials#

Setup creates the following under ${XDG_DATA_HOME:-$HOME/.local/share}/keiro/opencode:

The launcher is ${KEIRO_BIN_DIR:-$HOME/.local/bin}/opencode-keiro. The separate settings document references the key with {file:/absolute/path}. The key never appears in configuration, launcher, manifest, command arguments, or environment variables. Setup does not use KEIRO_API_KEY or auth.json as a fallback. This per-user file store is not an OS keychain: same-user processes and OpenCode plugins can read what OpenCode can read.

An unchanged rerun verifies authentication again but changes no installed bytes, modes, mtimes, runtime packages or credential identity. Unsafe mode drift is reported rather than silently repaired. Setup uses an exclusive lock; a stale lock is not removed automatically. Confirm no setup is running before following the reported manual recovery action.

  • generations/<generation>/opencode.json: the additional Keiro settings layer.
  • generations/<generation>/manifest.json and run.cjs: ownership, integrity, runtime selection and launch preflight.
  • credentials/<opaque-id>: an owner-only 0600 credential file in a 0700 directory.
  • runtimes/1.18.11/: a private npm prefix, only if needed.

Configuration boundaries and migration#

OPENCODE_CONFIG is an additional configuration layer, not an isolated profile. In OpenCode's own precedence, project opencode.json[c] and OPENCODE_CONFIG_CONTENT override it, so setup and every launch inspect applicable local sources before resolving the managed credential. Inherited configuration overrides, duplicate keys, malformed JSONC, disabled-provider policies, unsupported custom directories and uninspectable managed or remote sources fail closed. Existing opencode.json or opencode.jsonc files that use {file: or {env: substitution are refused because setup cannot inspect them without resolving the values, as is every inherited OPENCODE_* variable except OPENCODE_DISABLE_AUTOUPDATE and OPENCODE_DISABLE_MODELS_FETCH; keep plain opencode for those setups. This is not a sandbox against malicious plugins or concurrent modifications by another same-user process.

A legacy manual provider.keiro entry is a conflict, even when it looks identical. Keep your custom setup and use plain OpenCode, or deliberately remove or rename that entry yourself before rerunning setup. Setup never renames, normalizes or rewrites user files, and never adopts a legacy credential.

Rotate, roll back or remove#

Only active and immediately previous generations retain credentials. Rollback verifies the retained key again; a revoked key cannot be reactivated offline.

Management dispatch runs before ordinary launch credential resolution. Uninstall removes the launcher and reports the retained directory for deliberate removal and key revocation. Plain OpenCode remains unchanged.

  1. Create a new dedicated key and save it in an owner-only 0600 file.
  2. Run bash keiro-opencode.sh --key-file /absolute/path/to/replacement.
  3. Setup verifies the replacement before switching the launcher. Failure leaves the previous setup active.
  4. Revoke the old key on the console API keys page when rollback is no longer needed.
    Run in the terminal Shell
    opencode-keiro self status
    opencode-keiro self rollback
    opencode-keiro self uninstall

Advanced: generated settings preview#

This is a read-only preview of the separate managed document, not a block to paste into user configuration. Context windows come from the public model catalog; limit.output is the explicit per-turn cap. Pi uses the same limits.

JSON payload JSON
{
  "$schema": "https://opencode.ai/config.json",
  "provider": {
    "keiro": {
      "npm": "@ai-sdk/openai-compatible",
      "name": "Keiro",
      "options": {
        "baseURL": "https://api.keirolabs.ai/v1",
        "apiKey": "{file:/absolute/path/to/keiro/opencode/credentials/<opaque-id>}",
        "timeout": 120000,
        "headerTimeout": 60000,
        "chunkTimeout": 60000
      },
      "models": {
        "eb1-preview": {
          "name": "eb1-preview",
          "limit": { "context": 400000, "output": 32000 }
        },
        "eb1-frontier-preview": {
          "name": "eb1-frontier-preview",
          "limit": { "context": 869811, "output": 32000 }
        },
        "eb1-fast-preview": {
          "name": "eb1-fast-preview",
          "limit": { "context": 400000, "output": 32000 }
        },
        "eb1-efficient-preview": {
          "name": "eb1-efficient-preview",
          "limit": { "context": 400000, "output": 32000 }
        }
      }
    }
  }
}

See Models, API auth, and Usage and billing.

Search Keiro docs

Start typing to search pages and sections.

Start typing to search pages and sections.

Documentation

Console