OpenCode 2 v2.0.20: auth export/import, ChatGPT sign-in, owner-only databases#

Published by

Part of the OpenCode 2 Version Tracker series. | OpenCode on GitHub | OpenCode 2 docs

OpenCode 2 v2.0.20 follows v2.0.19 with three changes worth pulling out: auth export and auth import commands that move provider credentials as JSON, a ChatGPT sign-in path that uses your plan's tokens directly for OpenAI models, and database files restricted to their owner.

New and changed CLI commands#

CommandWhat It Does
opencode auth exportPrint stored provider credentials as JSON so they can be moved to another machine (#52139).
opencode auth importRead credentials back from that JSON on another machine (#52139).
opencode serviceDisable the background service, and re-enable it (#52107).

The non-interactive run command changed how it treats a denied permission. Rejecting a permission ask no longer ends the run; it continues (#51968). A follow-up made subagent asks answerable during run and kept parallel rejections from stopping the other branches (#52146).

Providers and sign-in#

The larger cluster this release is ChatGPT sign-in. Signing in through ChatGPT now registers a separate token-sharing OAuth method, and OpenCode uses those tokens for OpenAI requests (#52147). Around it: a usage-limit dialog (#52153), in-app token-sharing guidance (#52160), and session errors that now explain ChatGPT token-sharing failures (#52158). A later commit aligned the flow with OpenAI's updated partner guide (#52162).[1]

Provider errors surface more of what the provider returned. When a response carries no message OpenCode recognizes, it now shows the error body (#51978), reads messages from common body layouts (#52014), and preserves the provider response body in session errors (#52136).[2] Reasoning handling was corrected per provider: Bedrock Claude thinking blocks bind by default with redacted reasoning finalized at block end (#51959, #51999), Mistral thinking metadata is deferred until the block ends (#52008), and Workers AI thinking is turned off through the chat template (#52017). Explicit caching was enabled on more message-protocol routes (#51981).[3]

Local storage and interface#

Database files are now restricted to their owner, so they are no longer group- or world-readable (#52150).[4]

On the interface side, the new-session menu lists recently closed tabs so a tab can be reopened, a session's moved notice renders as a timeline divider (#52009), and diff word highlights were calmed with @pierre/diffs 1.5.1 (#51236).

What this tells us#

ChatGPT sign-in puts OpenCode 2 next to Codex CLI and Claude Code, which let subscribers authenticate with their plan rather than a metered API key. OpenCode reaches the same place by requesting a token-sharing scope during ChatGPT OAuth and using those tokens for OpenAI models, with this release adding error copy for token-sharing failures.

The service command and the option to disable it show the shape of OpenCode 2's architecture: a background server that the terminal client and desktop app attach to. That server-backed model is a different footprint from the single-process runs of Claude Code, Codex CLI, and Gemini CLI, and the owner-only restriction on its databases hardens the files it leaves on disk.

The rest of the range is provider correctness: surfacing raw error bodies when a message is not recognized, and fitting reasoning-block handling to Bedrock, Mistral, and Workers AI. That is the same catalog-breadth maintenance the 1.x line carries, now against the v2 provider plugins.

All trademarks and software referenced belong to their respective owners.


Sources#

  1. ChatGPT token sharing and sign-in: #52147, #52153, #52160, #52158, #52162
  2. Provider error bodies: #51978, #52014, #52136
  3. Reasoning and caching: #51959, #51999, #52008, #52017, #51981
  4. Owner-only databases: #52150

Previous OpenCode 2 analysis: v2.0.19 (September 29, 2026)

All 3 OpenCode 2 analyses: OpenCode 2 Version Tracker · Official OpenCode 2 changelog