@tinfoilsh/opencode-provider
v0.1.1
Published
Verifiably-private models from Tinfoil secure enclaves, for the opencode coding agent
Readme
Tinfoil provider for opencode
Use Tinfoil's verifiably-private open models from the opencode coding agent. Inference runs inside hardware secure enclaves that even Tinfoil cannot read into.
Setup
Install the plugin:
opencode plugin @tinfoilsh/opencode-provider --globalUse this command rather than editing your config by hand. The plugin has two halves, the provider and the sidebar panel, and the command registers both.
Set your API key:
opencode auth loginPick Tinfoil, then paste your key from the Tinfoil Dashboard.
Pick a Tinfoil model with
/models, or run one directly:opencode run --model tinfoil/gpt-oss-120b "explain this repo"
opencode already knows the tinfoil provider through
models.dev, so there is no base URL, API key or model list
to add to opencode.json, and no local proxy to run.
How verification works
When opencode starts, the plugin uses the
tinfoil SDK to verify the inference
enclave: it checks the enclave's attestation, confirms the running code against
the release digest signed in Sigstore, and binds the attested key to the live
connection. Every request body is then encrypted end-to-end with HPKE, so only
the verified enclave can read it.
The plugin fails closed. If verification does not succeed, requests are refused before anything leaves your machine, including your API key, your prompts and your code:
Error: Tinfoil: refusing to send this request. Enclave verification failed: <reason>Verification is retried on the next request, at most once every 30 seconds.
This is not a full external verifier: there is no independent AMD signature-chain check. For that, use tinfoil-cli.
Seeing the verification state
The sidebar shows a Tinfoil section, above Context and LSP:
Tinfoil ✓ encrypted
v0.0.145 · 43fe4ff77e94| Sidebar | What it means |
| --- | --- |
| Tinfoil ✓ encrypted | Verified. Requests are sealed to this enclave. |
| Tinfoil ! UNVERIFIED | Verification failed. Requests are blocked. |
| Tinfoil ! NOT PROTECTED | opencode is not sending through the plugin, so nothing is verified or encrypted. Please report it. |
| Tinfoil · checking… | The first attestation is still running. |
No Tinfoil section at all means the plugin is not loaded, and you are not
verified. Start opencode with TINFOIL_DEBUG=1 to see why.
For the full verification document — release tag and digest, code and enclave
fingerprints, attested keys, and every verification step — type /tinfoil,
or open the command palette (ctrl+p) and pick Tinfoil: verification
details. It opens in the terminal only: nothing is added to the conversation
and no context is re-sent.
Settings
| Variable | Default | Purpose |
| --- | --- | --- |
| TINFOIL_API_KEY | (none) | Your tk_… key, for headless workflows. Not needed if you use opencode auth login, the preferred login for everyday operation. |
| TINFOIL_DEBUG | (unset) | Log verification and model discovery to stderr. |
Contributing
Bug reports and patches are welcome. See CONTRIBUTING.md for how to run the plugin from a checkout, and for the opencode plugin behaviour worth knowing before you change anything.
