Originally published on my blog. This is an adapted version of the deployment guide.
A coding agent is easier to use across devices when the workspace lives on one host. The phone or laptop opens the browser UI; the host keeps the repository, runs tools, and connects to the model provider.
That host can be a desktop, a homelab machine, or a VPS. You do not need a public domain to begin. The choices that matter are how clients reach the service, how access is authenticated, and what happens when the launching terminal closes.
Start with the workspace and authentication
Enter the project directory before starting OpenCode. For a service behind a reverse proxy on the same host:
cd /path/to/your/workspace
export OPENCODE_SERVER_PASSWORD='replace-with-a-strong-password'
opencode web --hostname 127.0.0.1 --port 8080
The default authentication username is opencode. opencode web includes the browser interface; opencode serve runs the headless API service. See the official Web documentation for the current flags.
Treat access to this UI as access to the host's development tools. Use a dedicated workspace and account with only the permissions the agent needs. Keep the password out of committed configuration and screenshots.
Choose a connection path
Private access: Keep the service on a private network. A LAN connection works for devices on that network; Tailscale is another way to connect authorized devices without exposing the IDE directly to the public internet. If you bind to 0.0.0.0, remember that it listens on every interface: restrict reachability with the host firewall and keep authentication enabled. Plain HTTP on a LAN is not encrypted by itself.
A VPS with a domain: Keep OpenCode on loopback and put an HTTPS reverse proxy in front. For example, a Caddy site can be as small as:
ide.example.com {
reverse_proxy 127.0.0.1:8080
}
The domain must point to the server and the necessary ports must be reachable. Caddy can manage HTTPS certificates and proxy WebSocket connections; see its reverse-proxy documentation.
A reverse proxy does not automatically provide application authentication. Confirm that an unauthenticated visitor cannot enter the OpenCode workspace. With Nginx, check WebSocket upgrades and long-running streamed responses rather than testing only whether the initial page loads. The full article includes an Nginx example.
Keep the host process running
A remote host helps only while its service stays alive. On Linux, systemd can restart OpenCode after a process failure and start it after a reboot. My guide includes an example service with a dedicated working directory and a protected environment file for the password.
Use the actual installed binary path and service user. Check service logs and test a restart before relying on it for longer tasks. Closing a client browser and shutting down the host are different events; the host must remain awake and connected.
Select the model separately
Hosting OpenCode's workspace does not mean the model runs locally. The original guide uses Muse Spark 1.3 Contributor Free through OpenCode Zen as one example. Zen currently lists this as a limited-time free model, and its Contributor terms permit Meta to use prompts and completions for future model training. Review the current Zen pricing and privacy terms before using it, and keep confidential code and secrets out of that endpoint.
The deployment pattern also works with a provider appropriate to your data requirements. In my follow-up experiment, inference runs on an RTX 3090 with Qwen3.8-27B and llama.cpp.
Check the whole path
Before handing it a long task, verify these steps from the intended client device:
- Authentication blocks unauthenticated access.
- The expected project and model are selected.
- A harmless file-read request succeeds.
- Tool calls and live output work through the chosen network path.
- The host service survives the terminal disconnects and restarts you expect.
The benefit is one workspace that I can reach from different screens. The phone becomes a way to check progress or send a follow-up; execution remains on the host.
Top comments (0)