Description
Zen only serves CORS headers on /zen/v1/models. None of the inference endpoints return Access-Control-Allow-Origin on preflight, so no third-party browser client can call any Zen model - paid or free.
Steps to reproduce
$ curl -i -X OPTIONS https://opencode.ai/zen/v1/models \
-H 'Origin: https://example.com' \
-H 'Access-Control-Request-Method: POST' \
-H 'Access-Control-Request-Headers: accept,content-type,authorization'
HTTP/2 200
access-control-allow-origin: *
access-control-allow-headers: Content-Type, Authorization
access-control-allow-methods: GET, POST, OPTIONS
$ curl -i -X OPTIONS https://opencode.ai/zen/v1/chat/completions \
-H 'Origin: https://example.com' \
-H 'Access-Control-Request-Method: POST' \
-H 'Access-Control-Request-Headers: accept,content-type,authorization'
HTTP/2 404
(no Access-Control-Allow-Origin)
Same 404-with-no-CORS-headers result for every inference path:
/zen/v1/chat/completions 404 gpt-*, qwen3.8-max, deepseek-v4*, kimi-*, glm-*, minimax-*, big-pickle, space-bunny-free
/zen/v1/responses 404 grok-*, gpt-*, muse-spark-1.3-contributor-free
/zen/v1/messages 404 claude-*, qwen3.5-3.7
/zen/v1/models/{gemini-*} 404
/zen/v1/systemone 404
The browser fails the preflight and never issues the POST, so the client reports a generic connection/CORS error. Meanwhile GET /zen/v1/models succeeds, which makes it look like the base URL and API key are correct.
Expected
All /zen/v1/* endpoints behind the gateway should return the same CORS headers as /zen/v1/models, so third-party web clients can use Zen.
Note (separate issue)
Free-tier models return 403 FreeTierError: "OpenCode's free tier can only be used from within OpenCode", which is not documented. Paid models are unaffected. Reporting the CORS gap here, which also affects paid models.
Description
Zen only serves CORS headers on
/zen/v1/models. None of the inference endpoints returnAccess-Control-Allow-Originon preflight, so no third-party browser client can call any Zen model - paid or free.Steps to reproduce
Same 404-with-no-CORS-headers result for every inference path:
The browser fails the preflight and never issues the POST, so the client reports a generic connection/CORS error. Meanwhile
GET /zen/v1/modelssucceeds, which makes it look like the base URL and API key are correct.Expected
All
/zen/v1/*endpoints behind the gateway should return the same CORS headers as/zen/v1/models, so third-party web clients can use Zen.Note (separate issue)
Free-tier models return
403 FreeTierError: "OpenCode's free tier can only be used from within OpenCode", which is not documented. Paid models are unaffected. Reporting the CORS gap here, which also affects paid models.