Network
Configure proxies and custom certificates.
OpenCode supports standard proxy environment variables and custom certificates for enterprise network environments.
Proxy
OpenCode respects standard proxy environment variables.
# HTTPS proxy (recommended)
export HTTPS_PROXY=https://proxy.example.com:8080
# HTTP proxy (if HTTPS is unavailable)
export HTTP_PROXY=http://proxy.example.com:8080
# Bypass proxy for the local server (required)
export NO_PROXY=localhost,127.0.0.1
[!CAUTION] The TUI communicates with a local HTTP server. You must bypass the proxy for this connection to prevent routing loops.
You can configure the server’s port and hostname using CLI flags.
Authenticate
If the proxy requires basic authentication, include the credentials in the URL:
export HTTPS_PROXY=http://username:password@proxy.example.com:8080
[!CAUTION] Avoid hardcoding passwords. Use environment variables or secure credential storage.
For proxies requiring advanced authentication like NTLM or Kerberos, consider using an LLM Gateway that supports those methods.
Custom certificates
If your organization uses custom CAs for HTTPS connections, configure OpenCode to trust them:
# Custom CA certificate setup
export NODE_EXTRA_CA_CERTS=/path/to/ca-cert.pem
This applies to both proxy connections and direct API access.
Enterprise network considerations
Firewall Configuration
Make sure the following domains are allowed in your firewall/proxy:
opencode.ai- OpenCode servicesanthropic.com- Anthropic APIapi.openai.com- OpenAI APIapi.together.ai- Together AI API- Other LLM provider domains
Offline Installation
For fully offline environments, you can:
- Download installers from GitHub releases
- Install locally with npm or bun
- Configure a proxy for external API access (if necessary)
VPN Configuration
If you use a VPN:
- Make sure the VPN doesn’t interfere with local ports
- Add the required domains to the VPN’s bypass list
- Check whether the VPN modifies DNS settings