npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

@tinfoilsh/opencode-provider

v0.1.1

Published

Verifiably-private models from Tinfoil secure enclaves, for the opencode coding agent

Readme

Tinfoil provider for opencode

Use Tinfoil's verifiably-private open models from the opencode coding agent. Inference runs inside hardware secure enclaves that even Tinfoil cannot read into.

npm Documentation

Setup

  1. Install the plugin:

    opencode plugin @tinfoilsh/opencode-provider --global

    Use this command rather than editing your config by hand. The plugin has two halves, the provider and the sidebar panel, and the command registers both.

  2. Set your API key:

    opencode auth login

    Pick Tinfoil, then paste your key from the Tinfoil Dashboard.

  3. Pick a Tinfoil model with /models, or run one directly:

    opencode run --model tinfoil/gpt-oss-120b "explain this repo"

opencode already knows the tinfoil provider through models.dev, so there is no base URL, API key or model list to add to opencode.json, and no local proxy to run.

How verification works

When opencode starts, the plugin uses the tinfoil SDK to verify the inference enclave: it checks the enclave's attestation, confirms the running code against the release digest signed in Sigstore, and binds the attested key to the live connection. Every request body is then encrypted end-to-end with HPKE, so only the verified enclave can read it.

The plugin fails closed. If verification does not succeed, requests are refused before anything leaves your machine, including your API key, your prompts and your code:

Error: Tinfoil: refusing to send this request. Enclave verification failed: <reason>

Verification is retried on the next request, at most once every 30 seconds.

This is not a full external verifier: there is no independent AMD signature-chain check. For that, use tinfoil-cli.

Seeing the verification state

The sidebar shows a Tinfoil section, above Context and LSP:

    Tinfoil ✓ encrypted
      v0.0.145 · 43fe4ff77e94

| Sidebar | What it means | | --- | --- | | Tinfoil ✓ encrypted | Verified. Requests are sealed to this enclave. | | Tinfoil ! UNVERIFIED | Verification failed. Requests are blocked. | | Tinfoil ! NOT PROTECTED | opencode is not sending through the plugin, so nothing is verified or encrypted. Please report it. | | Tinfoil · checking… | The first attestation is still running. |

No Tinfoil section at all means the plugin is not loaded, and you are not verified. Start opencode with TINFOIL_DEBUG=1 to see why.

For the full verification document — release tag and digest, code and enclave fingerprints, attested keys, and every verification step — type /tinfoil, or open the command palette (ctrl+p) and pick Tinfoil: verification details. It opens in the terminal only: nothing is added to the conversation and no context is re-sent.

Settings

| Variable | Default | Purpose | | --- | --- | --- | | TINFOIL_API_KEY | (none) | Your tk_… key, for headless workflows. Not needed if you use opencode auth login, the preferred login for everyday operation. | | TINFOIL_DEBUG | (unset) | Log verification and model discovery to stderr. |

Contributing

Bug reports and patches are welcome. See CONTRIBUTING.md for how to run the plugin from a checkout, and for the opencode plugin behaviour worth knowing before you change anything.

License

Apache-2.0