npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

opencode-multiauth-profiles

v0.1.0

Published

Switch local OpenCode authentication profiles without exposing credentials.

Readme

OpenCode MultiAuth Profiles

opencode-multiauth-profiles is a local OpenCode plugin for storing and switching authentication credentials for multiple accounts.

Version 1 is configured for OpenAI ChatGPT OAuth (openai) by default. The profile storage is provider-agnostic and supports OpenCode credential formats oauth, api, and wellknown; additional providers must be explicitly enabled in plugin configuration.

Why

OpenCode stores one active credential per provider in its auth file. Signing in again with /connect replaces that credential. This plugin saves named, local copies and restores one when requested. It only changes the selected provider entry, so credentials for other providers are preserved.

OpenCode must be restarted after selecting a profile. Do not select profiles while another OpenCode process is running: it could refresh and overwrite the active credential during the switch.

Install

Clone the repository:

git clone https://github.com/RuBAN-GT/opencode-multiauth-profiles.git

Add the local checkout to ~/.config/opencode/opencode.json, replacing the path with the location where you cloned it:

{
  "$schema": "https://opencode.ai/config.json",
  "plugin": ["file:///absolute/path/to/opencode-multiauth-profiles"]
}

Point the local spec at the package directory, not src/index.ts, so OpenCode can load both the server and TUI entrypoints.

After the package is published to npm, it can instead be added by package name:

{
  "$schema": "https://opencode.ai/config.json",
  "plugin": ["opencode-multiauth-profiles"]
}

Quit and restart OpenCode after changing its configuration. /account appears in the command menu. In the terminal TUI it can also open a profile dialog; otherwise the command lists profiles and asks which to use. The auth_profiles tool remains available to the model.

OpenAI Setup

  1. In OpenCode, run /connect, choose OpenAI, then choose ChatGPT Plus/Pro and authenticate the first account.
  2. Run /account save openai work. The plugin saves the current credential as work.
  3. Run /connect again and authenticate the second account.
  4. Run /account save openai personal.
  5. To switch later, run /account and pick a profile in the TUI dialog, or run /account use openai work. Then quit OpenCode and start it again.

Use these commands:

/account save openai <profile>
/account use openai <profile>
/account list
/account list openai
/account current openai

OpenCode custom commands are model-driven. The /account command instructs the active model to call the plugin tool and returns the tool result. No credential values are sent to the model: the tool returns only profile names and operation status.

Configuration

The default configuration enables only OpenAI:

{
  "plugin": [["opencode-multiauth-profiles", { "providers": ["openai"] }]]
}

To enable a verified additional provider later:

{
  "plugin": [
    [
      "opencode-multiauth-profiles",
      {
        "providers": ["openai", "github-copilot"]
      }
    ]
  ]
}

Available options:

| Option | Default | Purpose | | ------------- | ---------------------------------- | ------------------------------------------------------------------ | | providers | ["openai"] | Provider IDs that save, use, and current may access. | | command | "account" | Name of the OpenCode slash command. | | profilesDir | ~/.config/opencode/auth-profiles | Directory used to hold local profile files. | | authFile | OpenCode XDG auth path | Override only for tests or non-standard OpenCode data directories. |

profilesDir is a directory of plaintext OAuth refresh tokens, not encryption. The plugin creates profile directories with mode 0700 and profile files with mode 0600. Use full-disk encryption or a secret manager if the local machine needs stronger protection.

Token Refreshes

OpenCode refreshes OAuth credentials in its active auth file. Before a profile is replaced, the plugin snapshots the outgoing credential into its selected profile. This retains a rotated refresh token when switching accounts.

The initial save command marks that profile as selected. If credentials are later changed manually with /connect, run save again to associate the new credential with a profile.

Development

corepack enable
yarn install
yarn check

The package uses Yarn 4.5.0 with the node-modules linker, so dependencies are available in the standard node_modules directory. It uses the strict configuration from eslint-config-detemiro and Prettier. Tests use temporary files with synthetic credentials only.

Security

  • Credentials are never emitted in tool output, errors, tests, or documentation.
  • Profile names are validated and cannot escape the profile directory.
  • Provider directory names are URL-encoded before being used as paths.
  • The primary OpenCode auth document is updated through a temporary file and atomic rename.
  • This plugin does not authenticate with OpenAI itself; use OpenCode /connect for OAuth.

License

MIT