Skip to content

[BUG] opencode serve: returns 401 Unauthorized when OPENCODE_SERVER_PASSWORD is unset → UI infinite loading, no auth prompt (regression since ~v2.0.6) #50370

Description

@ixode0

Description

The bug is NOT that a password is required. The bug is that opencode serve returns HTTP 401 Unauthorized on all endpoints even though OPENCODE_SERVER_PASSWORD is NOT set in the environment. Because of these 401 responses, the web UI at http://127.0.0.1:4096 hangs on infinite loading for sessions and models, and never prompts for credentials. Multiple restarts (5+) occasionally make it work.

Important: this bug is specific to opencode serve. The regular TUI (opencode without serve) works fine. So the issue is in the HTTP server / auth layer, not in the core.

Regression: this behavior has been present since at least v2.0.6 and still exists in v2.0.12.

To Reproduce

  1. Make sure OPENCODE_SERVER_PASSWORD is NOT set: unset OPENCODE_SERVER_PASSWORD
  2. Run: opencode serve --port 4096 --print-logs --log-level debug
  3. Open http://127.0.0.1:4096 in a browser
  4. Observe: infinite "Loading" spinners for sessions and models, empty model list, no auth prompt
  5. In another terminal: curl -sS -o /dev/null -w "HTTP %{http_code}\n" http://127.0.0.1:4096/global/health → HTTP 401
  6. Check server log: every request is answered with 401

Expected behavior

  • When OPENCODE_SERVER_PASSWORD is unset, the server must NOT require auth
  • /global/health, /session, /project, /config/providers should return JSON (HTTP 200)
  • The web UI should load sessions and models normally
  • Auth should only be enforced when OPENCODE_SERVER_PASSWORD is explicitly set
  • When auth IS required, the UI should prompt for credentials instead of hanging

Environment

  • OS: Debian (PRoot-Distro on Android)
  • Arch: aarch64 (ARM64)
  • Kernel: Linux 6.17.0-PRoot-Distro
  • OpenCode version: opencode v2.0.12 (bug reproduced since ~v2.0.6)
  • Node: v22.23.2
  • Bun: 1.4.2
  • Command: opencode serve --port 4096 --print-logs --log-level debug
  • TUI (opencode without serve) works correctly in the same environment

Diagnostic Output

=== 1. SYSTEM & VERSION ===
Linux localhost 6.17.0-PRoot-Distro #1 SMP PREEMPT_DYNAMIC Fri, 10 Oct 2025 00:00:00 +0000 aarch64 GNU/Linux
Node: v22.23.2
Bun: 1.4.2
OpenCode: opencode v2.0.12

=== 2. PROCESS STATUS ===
aid_u0_+ 17869 1.8 0.3 6477992 37440 pts/0 S<l+ 2023 0:24 opencode serve --port 4096 --print-logs --log-level debug

=== 5. LATEST LOG (last 40 lines) ===
timestamp=2026-09-21T14:01:39.159Z level=INFO run=ce8be381 message="Sent HTTP response" http.span=6 role=server http.method=GET http.url=/global/health http.status=401
timestamp=2026-09-21T14:01:39.283Z level=INFO run=ce8be381 message="Sent HTTP response" http.span=3 role=server http.method=GET http.url=/session http.status=401
timestamp=2026-09-21T14:01:39.520Z level=INFO run=ce8be381 message="Sent HTTP response" http.span=1 role=server http.method=GET http.url=/ http.status=401
timestamp=2026-09-21T13:57:41.475Z level=INFO run=868b1a5a cause="InterruptError: All fibers interrupted without error..." http.span=3332 role=server http.method=GET http.url=/api/event http.status=200

=== 6. API ENDPOINTS TEST (v2 paths) ===
GET /global/health -> HTTP 401 | HTML/Other (not JSON)
GET /session -> HTTP 401 | HTML/Other (not JSON)
GET /project -> HTTP 401 | HTML/Other (not JSON)
GET /config/providers -> HTTP 401 | HTML/Other (not JSON)

=== 7. AUTH CHECK ===
OPENCODE_SERVER_PASSWORD NOT set in current env

Additional context

Plugins

not using

OpenCode version

2.0.12

Steps to reproduce

  1. Run: opencode serve
  2. Open http://127.0.0.1:4096 in a browser
  3. Observe: infinite "Loading" spinners for sessions and models, empty model list, no auth prompt
  4. Run: curl -sS -o /dev/null -w "HTTP %{http_code}\n" http://127.0.0.1:4096/global/health
  5. Result: HTTP 401

Screenshot and/or share link

Image Image

Operating System

Debian GNU/Linux 13 (trixie) aarch64

Terminal

Termux PRoot Distro

Activity

dekarl commented on Sep 21, 2026

@dekarl

See #43039 for the same issue worded as feature request and #46270 for a possible implementation to adopt.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions