GuidesHosting choices

OpenCode on a remote server: open it from your phone or browser

OpenCode 2's background server, opencode pair's one-time links, opening it from a phone over a private network, opencode serve, and OpenCode 1's web command.

October 9, 2026The Everpod team
The short answer

In OpenCode 2 the web interface is always there: a background server for your account serves it on 127.0.0.1:49374, behind a password. To open it from your phone or another computer, either forward that port over SSH, or let the server listen on the machine’s Tailscale address and print a link for its Tailscale name:

opencode service set hostname $(tailscale ip -4)
opencode service set port 4096
opencode service restart
opencode pair --url http://my-server:4096

Each link opencode pair prints works once and expires in five minutes, and signs that browser in for 30 days. The links are plain HTTP, so keep the server on a private network: its own docs suggest 0.0.0.0, which listens on every address the machine has, the public one included. On OpenCode 1 the command is opencode web, and it has no password unless you set OPENCODE_SERVER_PASSWORD.

Which OpenCode you have

OpenCode has two release lines with different commands for this. The install line on opencode.ai now gives you version 2 (@opencode/cli, 2.0.26 on October 8, 2026), and opencode --version prints opencode v2.0.26. Version 1 (opencode-ai, 1.18.35) prints a bare 1.18.35. The two don’t install side by side. Version 2 has no web or attach command: type either and it prints its general help. Version 1 has no pair or service. The rest of this page is version 2 first, then version 1.

OpenCode 2: the background server and pair

The version 2 docs describe the model: “By default, OpenCode discovers or starts one shared background server for your user account. Every local OpenCode client connects to that server, which owns sessions, configuration, integrations, permissions, and tool execution.” The same server serves the web interface, which is “available by default and password protected.” It listens on port 49374, on 127.0.0.1 only, with a password it generates and keeps. opencode service status, stop, start and restart manage it, and opencode service get password prints the password.

You don’t type that password into a browser. opencode pair prints a one-time link instead: “Open a link to connect. Links work once and expire in 5 minutes.” Opening it signs the browser in with a cookie that lasts 30 days, and changing the server’s password signs every browser out. With the server on localhost only, the command also prints the SSH route on standard error:

Over SSH? Forward the port, then open the link on your machine:
ssh -L 49374:127.0.0.1:49374 <host>
If port 49374 is busy locally, forward another port and use it in the link.

To connect from other devices, run `opencode service set hostname 0.0.0.0`.

The forward works from a laptop. For a phone, the second route is simpler: make the server listen on an address your phone can reach and print links for that name. That is the four commands in the short answer. We ran them on October 9, 2026, with OpenCode 2.0.26 on an Ubuntu server joined to a Tailscale network. Bound to the Tailscale address, the server answered there and refused connections on the machine’s public address and on localhost, and pair --url still printed its link. Opened at phone width, a link signed in to OpenCode’s web interface at “Create a session to get started.” Opened a second time, the same link was refused: “This pairing link expired or was already used. Run opencode pair to get a new one.” A browser with no link gets the sign-in screen, and the server’s API answers 401.

Without --url, plain opencode pair on a server listening everywhere prints a link for every address it has, the public one included, which a server behind a firewall won’t answer. It also draws a QR code. That code isn’t a web address: OpenCode’s source says it carries the code and the reachable addresses as JSON for “the OpenCode app”, whose scanner lives in OpenCode’s web app and only opens the camera over HTTPS. OpenCode has no phone app on its download page, so on a phone, open the link in the browser.

Keeping it private

The version 2 server always asks for a password, which is an improvement on version 1. What protects it beyond that is where it listens. The links are http://, the server has no TLS option, and the docs carry no warning about binding to 0.0.0.0; the project’s security policy still describes version 1 and puts the rest on you: “It is the end user’s responsibility to secure the server.” Two ways keep the server off the internet:

Version 2.0.26’s help also lists opencode pair --remote, “Pair through the OpenTunnel remote address”, which no docs page describes. In the source it puts the server on a public HTTPS address with a random name through OpenTunnel, a tunnel run by OpenCode’s makers, whose own README says the address “is not authentication” and that inbound traffic “is temporarily handled by some dummy relay servers running on AWS.” OpenCode’s password and one-time links still stand behind it, but it is a public address. Switch it off with opencode service set remote false.

A terminal on another machine, and serve

To drive the remote server from your laptop’s terminal rather than a browser, point OpenCode at it: opencode --server http://my-server:4096. The docs don’t say how the password travels; the CLI’s source reads it from OPENCODE_PASSWORD and stops with “Server at <url> requires a password; set OPENCODE_PASSWORD” when it is missing.

opencode serve runs the same server in the foreground instead of as the background service, which is what you want under systemd, in Docker, or for a dedicated server: opencode serve --hostname $(tailscale ip -4) --port 4096 prints the address and a generated password unless you set OPENCODE_PASSWORD; inside a container, where the port is published to the host, 0.0.0.0 is the usual hostname, with the same care over what the host lets in. The background service, by contrast, is a detached process OpenCode starts on demand: it outlives the terminal that started it, and the installer adds no system service, so after a reboot it is back when you next run an opencode command. If you never want it, opencode service set disabled true stops it and makes private servers the default; pairing then stops working, since it needs the shared service.

In Docker, mind the tag: the docs’ untagged ghcr.io/anomalyco/opencode pulls latest, which on October 9 was version 1.18.35. Version 2 images have version tags only, such as ghcr.io/anomalyco/opencode:2.0.26. Neither docs set gives a recipe for running the server in a container.

OpenCode 1: web, serve and attach

On version 1, opencode web starts a server and opens the interface in a browser, and opencode serve starts one without the interface. Both listen on 127.0.0.1, port 4096 if it is free. The web page warns: “If OPENCODE_SERVER_PASSWORD is not set, the server will be unsecured. This is fine for local use but should be set for network access.” So for another device:

OPENCODE_SERVER_PASSWORD='a-long-secret' opencode web --hostname $(tailscale ip -4) --port 4096

The username is opencode unless you set OPENCODE_SERVER_USERNAME. --mdns also advertises it as opencode.local on the local network. A terminal elsewhere connects with opencode attach http://my-server:4096 and --password. The same advice about private networks holds, more so, since version 1 starts with no password at all.

Where the server should run

Opening OpenCode from your phone only helps if the machine is on when you reach for it, and a laptop sleeps. A server of your own, on your private network, is the usual answer, and it keeps OpenCode’s work running between visits. Everpod’s developer pod runs OpenCode: a cloud computer that is yours, always on, with your pick of Claude Code, Codex, OpenCode, Pi, Hermes and OpenClaw installed, reached only through your own private network, from $24 a month. It accepts no incoming connections from the open internet: no open ports and no public SSH. A server your agent starts is reachable from your devices and from nowhere else. By default the machine does not start connections to your other devices. The four commands above are how its web interface reaches your phone.

Run OpenCode on an always-on developer pod.

A developer pod is a cloud computer of your own with your pick of Claude Code, Codex, OpenCode, Pi, Hermes and OpenClaw installed, reached only over your own Tailscale network. From $24 a month, built in about ten minutes.