Summary
opencode2 serve rejects the exact HTTP Basic Auth username and password supplied through OPENCODE_SERVER_USERNAME and OPENCODE_SERVER_PASSWORD. In a browser, this causes an endless login prompt and prevents using serve with fixed credentials.
Environment
- opencode version:
opencode2 v0.0.0-beta-18414
- OS:
Linux 7.0.0-30-generic x86_64 (Ubuntu)
- Terminal:
TERM=xterm-256color, COLORTERM=truecolor, Herdr terminal environment
- Shell:
/bin/bash
- Install/channel: beta binary installed at
~/.opencode/bin/opencode2
- Active plugins: local
.opencode/plugins/smoke-theme.json and .opencode/plugins/tui-smoke.tsx; no plugins configured in the global config
Reproduction
-
Start a fresh server with known credentials:
OPENCODE_SERVER_USERNAME=testuser OPENCODE_SERVER_PASSWORD=testpass opencode2 serve --port 4197
-
Confirm that both variables are present in the running server process.
-
Request the health endpoint with those exact credentials:
curl -u testuser:testpass http://127.0.0.1:4197/api/health
-
Open http://127.0.0.1:4197 in a browser and enter the same credentials.
Expected Behavior
The configured credentials authenticate successfully, the health request returns 200, and the web UI loads after one login prompt.
Actual Behavior
The authenticated health request returns 401. The server log records repeated responses such as:
http.method=GET http.url=/api/health http.status=401
http.method=GET http.url=/ http.status=401
The browser keeps showing the Basic Auth login prompt after the correct credentials are entered.
Additional Context
- Reproduces consistently with a clean temporary server and known test credentials.
- The exact credentials read from the running process environment also return
401, ruling out shell quoting and browser credential caching.
opencode2 pair credentials authenticate successfully against the managed background service, but they do not authenticate against the explicit serve endpoint.
- The managed-service pairing workflow is not equivalent to running a stable
serve endpoint with user-selected credentials.
- No secrets or real credentials are included above.
Summary
opencode2 serverejects the exact HTTP Basic Auth username and password supplied throughOPENCODE_SERVER_USERNAMEandOPENCODE_SERVER_PASSWORD. In a browser, this causes an endless login prompt and prevents usingservewith fixed credentials.Environment
opencode2 v0.0.0-beta-18414Linux 7.0.0-30-generic x86_64(Ubuntu)TERM=xterm-256color,COLORTERM=truecolor, Herdr terminal environment/bin/bash~/.opencode/bin/opencode2.opencode/plugins/smoke-theme.jsonand.opencode/plugins/tui-smoke.tsx; no plugins configured in the global configReproduction
Start a fresh server with known credentials:
Confirm that both variables are present in the running server process.
Request the health endpoint with those exact credentials:
Open
http://127.0.0.1:4197in a browser and enter the same credentials.Expected Behavior
The configured credentials authenticate successfully, the health request returns
200, and the web UI loads after one login prompt.Actual Behavior
The authenticated health request returns
401. The server log records repeated responses such as:The browser keeps showing the Basic Auth login prompt after the correct credentials are entered.
Additional Context
401, ruling out shell quoting and browser credential caching.opencode2 paircredentials authenticate successfully against the managed background service, but they do not authenticate against the explicitserveendpoint.serveendpoint with user-selected credentials.