OpenCode v1.18.33: redacted debug output, Cloudflare Gateway timeouts, and Gemini thinking defaults#
Published by Alex Sorokoletov
Part of the OpenCode Version Tracker series. | OpenCode on GitHub | Releases
Coming from v1.18.32, OpenCode v1.18.33 is a bugfix release: debug configuration output now redacts credentials and sensitive headers, Cloudflare AI Gateway models honor provider response and stream timeouts, MCP browser launch failures are reported when the launcher exits immediately, and Gemini thinking defaults and effort options match the supported controls across model generations.[1]
No environment variables or experimental config keys changed in this release. The four bugfixes below are the whole of v1.18.33.
The fixes#
| Fix | What It Does |
|---|---|
| Debug config redaction | Debug configuration output redacts credentials and sensitive headers, so a shared debug dump no longer leaks provider keys or auth headers. |
| Cloudflare AI Gateway timeouts | Models served through Cloudflare AI Gateway honor the configured provider response and stream timeouts instead of ignoring them. |
| MCP browser launch reporting | When an MCP browser launcher exits immediately, the failure is surfaced instead of leaving the launch silently broken. |
| Gemini thinking controls | Gemini thinking defaults and effort options match the controls each model generation actually supports, so effort settings apply correctly across Gemini versions. |
The debug redaction fix is the one worth acting on. Anyone who pastes OpenCode's debug configuration into a bug report or a support thread was previously at risk of exposing provider keys and auth headers in that output; v1.18.33 masks them before they reach the terminal.
Timeouts configured for a provider now carry through Cloudflare AI Gateway, so a slow or stalled response fails on the schedule the config sets rather than hanging past it.
On the catalog side, the hosted Zen provider's documented model list picked up Claude Opus 5.5 and the GPT-6 Sol and GPT-6 Luna options.[1] OpenCode reads its wider model catalog from the models.dev entries it fetches at runtime, so most model names move without a code change.[2]
What this tells us#
v1.18.33 is a maintenance point release, and its shape is typical of OpenCode's near-daily cadence: a small batch of provider-path corrections between larger feature windows. Three of the four fixes land in the model-provider layer (Cloudflare AI Gateway, Gemini, MCP).
That layer is where a fully multi-provider harness pays its upkeep. Closed terminal agents like Claude Code, Codex CLI, and Gemini CLI each ride a single vendor's models, so a gateway timeout or a per-generation Gemini effort control is not their problem to solve. OpenCode carries the whole matrix, so a timeout that a gateway swallowed or a thinking option a model generation rejects becomes a shipped fix rather than an upstream detail.
The debug redaction change is the standout for a broader audience. Masking credentials in diagnostic output is a privacy correction that matters the moment a user shares a config dump to get help, and it applies regardless of which provider they run.
Sources#
- OpenCode releases and changelog, v1.18.33 release notes
- models.dev catalog
All trademarks and software referenced belong to their respective owners.
Previous OpenCode analysis: v1.18.32 (September 26, 2026)
All 4 OpenCode analyses: OpenCode Version Tracker · Official OpenCode changelog