@tumnel/opencode
v0.1.12
Published
Secure outbound bridge between OpenCode Desktop and Tumnel web clients
Readme
@tumnel/opencode
Global OpenCode Desktop plugin that creates an outbound, credential-free WebSocket connection to a Tumnel Cloudflare relay.
Install the Tumnel connector
Run:
npx @tumnel/[email protected] installThe installer registers the connector in the global OpenCode configuration and preserves its other
plugins and JSONC comments. When run interactively, it offers to restart or open OpenCode Desktop
and waits for the local Tumnel connector to become ready. Use --restart to skip the prompt or
--no-restart to install without touching the running app. Version 0.1.11 connects to the hosted
Tumnel relay by default:
https://openbridge.jlfloressanchez01.workers.devSet TUMNEL_RELAY_URL before starting OpenCode Desktop only when you need to override the relay,
for example ws://127.0.0.1:5173 during local development.
The plugin also binds a pairing-only endpoint to 127.0.0.1:43816. It accepts approved OpenBridge origins, returns short-lived signed proofs, and never exposes OpenCode SDK methods or model credentials over localhost. The port and production origin can be configured with TUMNEL_LOCAL_PORT and TUMNEL_APP_ORIGIN.
The host identity is an Ed25519 key pair stored at ~/.config/tumnel/identity.json. Existing
~/.config/opencode/tumnel/identity.json identities are migrated automatically so current pairings
remain valid. Other Tumnel connectors on the same computer reuse this identity while their
projects, sessions, events, and requests remain isolated by connector. The private key never leaves
the computer.
