Skip to content

fix(agent-runtime): route OpenCode free-tier like the native CLI - #1282

Open
khanhdeptraivaicachuong wants to merge 1 commit into
vastsa:mainfrom
khanhdeptraivaicachuong:OpencodeZenFreeModelFix
Open

khanhdeptraivaicachuong wants to merge 1 commit into
vastsa:mainfrom
khanhdeptraivaicachuong:OpencodeZenFreeModelFix

Conversation

@khanhdeptraivaicachuong

Copy link
Copy Markdown

The Zen gateway rejects free-tier requests that do not look like the native opencode CLI, answering 403 FreeTierError even with a valid key.

Changes

  • Send timestamp-encoded ses_/msg_ ids (UUID/random ids are rejected): derived per harness conversation and stable across retries, fresh per ad-hoc call.
  • Force the native client identity: x-opencode-client cli and User-Agent opencode/ (keeps a genuine opencode/ prefix).
  • Reserve x-opencode-request next to x-opencode-session (agent-runtime + host-core validation).
  • Complete the body signature via a fetch-level gate (markers read/write/edit/bash in the correct envelope plus a non-empty system default); paid models, non-Zen hosts, and malformed bodies pass through byte-identical.

The muse-spark responses pin is intentionally not included: the pi catalog now owns model metadata and already lists those ids under openai-responses.

Validation

  • agent-runtime vitest (touched files + binding): 99/99.
  • Full agent-runtime suite: 1141/1143 (3 pre-existing environment failures in untouched files: dist-root lookup, Windows fork paths, TMPDIR location).
  • Desktop catalog node --test: 17/17. tsc clean (agent-runtime, desktop). cargo fmt clean. pnpm build:js passes.
  • Task-candidate E2E and live keyless probe not run yet.

The Zen gateway rejects free-tier requests that do not look like the
native opencode CLI, answering 403 FreeTierError even when the key is
valid. Send timestamp-encoded ses_/msg_ ids (UUIDs are rejected),
force the cli client identity with an opencode/ User-Agent, reserve
x-opencode-request next to x-opencode-session, and complete the body
signature with marker tools plus a non-empty system prompt.

The Zen muse-spark responses pin is intentionally not included: the
pi catalog now owns model metadata and already lists those ids under
openai-responses, so the old models.dev pin is obsolete.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant