OpenCode 2 v2.0.26: Google Vertex via gcloud, hardened remote access#

Published by

Part of the OpenCode 2 Version Tracker series. | OpenCode on GitHub | OpenCode 2 docs

OpenCode 2 v2.0.26 follows v2.0.25 with three user-facing changes: Google Vertex now authenticates through your local gcloud Application Default Credentials instead of an API key, remote access moves to a randomly generated secret subdomain, and clicking a wrapped link in the terminal transcript opens it from any row.

Google Vertex through gcloud credentials#

A new Google Cloud credential path lets OpenCode reach Vertex without an API key (#53798). It reads the same files gcloud writes: the active configuration under ~/.config/gcloud (or %APPDATA%\gcloud on Windows, or CLOUDSDK_CONFIG when set) for project IDs, and application_default_credentials.json for Application Default Credentials. The lookup is local only, reading project IDs off disk without contacting Google, and it reports how many projects it found in your gcloud configuration. The v2 docs describe the same flow: Vertex uses Application Default Credentials and needs a project set before its models become available, configured with gcloud auth application-default login.[1]

Remote access on a secret subdomain#

OpenCode 2 can expose its background service over a tunnel, enabled with opencode pair --remote or opencode service set remote true. This release serves that access on a randomly generated subdomain (#53962). The route is eight random bytes rendered as hex, and it is treated as sensitive as the service password: opencode service get redacts it. Tunnel hostnames appear in public certificate logs, so a random route keeps the service address unguessable even when the hostname is visible.[2]

Terminal and change tracking#

In the terminal, clicking a link now works across wrapped rows. Each rendered cell stores the full URL, so a click on any row of a link that spans multiple lines opens it in the browser (#53903). Two more terminal fixes land: low-verbosity summaries stay in place when you toggle verbosity (#52357), and the home footer is kept off the hint row on short terminals (#53891).[3]

Change tracking got faster. Untracked-file diffs are now batched instead of spawning one git process per file (#53449), tree-diff selections are batched on every platform (#53956), and snapshot capture was sped up and hardened (#51996). These touch the snapshot subsystem that records file changes for each turn.[4]

New environment variable#

VariableWhat It Does
OPENCODE_RELEASE_NOTESRead by the publish pipeline. When set, its text becomes the CHANGELOG.md entry for the tag being released (#53964).

Release-notes tooling lands: the publish script writes reviewed notes into CHANGELOG.md for each tag (#53964), leading with a highlights section (#53969). The file currently carries only a header and no entries yet.[5]

What this tells us#

Vertex through gcloud Application Default Credentials puts OpenCode 2 alongside Gemini CLI and Claude Code, which both authenticate to Vertex from ADC rather than a pasted key. For a developer already signed into gcloud, the provider becomes available with no extra secret to store.

The remote-access change is part of OpenCode 2's server-backed shape. A background service holds the session, and the terminal client, desktop app, and web interface attach to it; pair --remote extends that attach point across a tunnel. Serving it on a secret, redacted subdomain hardens an address that would otherwise be reachable by anyone who reads the tunnel hostname out of certificate logs. That footprint differs from the single-process runs of Claude Code, Codex CLI, and Gemini CLI.

The CHANGELOG.md work is a visible shift. OpenCode 2's v2 tags have carried no release notes, and this release adds the pipeline that writes them. Alongside the batched-diff and snapshot speedups, the range reads as infrastructure under the harness rather than new agent behavior.

This analysis is based on publicly available open-source code and release metadata, conducted for educational and research purposes. All trademarks and software referenced belong to their respective owners.


Sources#

  1. Google Vertex via gcloud credentials: #53798; OpenCode 2 providers docs
  2. Remote access subdomain: #53962
  3. Terminal fixes: #53903, #52357, #53891
  4. Change tracking: #53449, #53956, #51996
  5. Release notes tooling: #53964, #53969

Previous OpenCode 2 analysis: v2.0.25 (October 8, 2026)

All 9 OpenCode 2 analyses: OpenCode 2 Version Tracker · Official OpenCode 2 changelog