You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
policy: deny shell * on custom agent breaks free tier with "can only be used from within OpenCode" #50627
Enabling permissions: [{action: shell, resource: "*", effect: deny}] on a custom primary agent makes every request fail on all free-tier models with OpenCode's free tier can only be used from within OpenCode, even though the request originates from inside OpenCode TUI.
Send any message to that agent on any Console free-tier model via TUI.
Observe Error: Error from provider (Console): OpenCode's free tier can only be used from within OpenCode.
Comment out the shell: "*" deny lines -> works again.
Expected Behavior
Shell deny should only block shell tool calls; the LLM request itself should still authenticate as in-OpenCode free-tier use.
Actual Behavior
Entire session fails with free-tier origin error on every message, before any tool use. Always reproducible; removal fixes. Affects all free models. Error is single line only.
Summary
Enabling
permissions: [{action: shell, resource: "*", effect: deny}]on a custom primary agent makes every request fail on all free-tier models withOpenCode's free tier can only be used from within OpenCode, even though the request originates from inside OpenCode TUI.Environment
Reproduction
~/.config/opencode/agents/search.mdwith frontmatter:Error: Error from provider (Console): OpenCode's free tier can only be used from within OpenCode.shell: "*"deny lines -> works again.Expected Behavior
Shell deny should only block shell tool calls; the LLM request itself should still authenticate as in-OpenCode free-tier use.
Actual Behavior
Entire session fails with free-tier origin error on every message, before any tool use. Always reproducible; removal fixes. Affects all free models. Error is single line only.
Additional Context
mode: primary.permission deny shell+ free-tier trigger — appears to be a new trigger for the same validation bug.