Open source
OpenCode on your phone, on a server you own
OpenCode already ships a server and a web UI, and community apps build on them. What they leave to you is getting a port from your server to your phone safely. Maude does that part without opening one.
Quick answer
OpenCode has no mobile app of its own. The usual routes are opencode web in a phone browser or a community app pointed at opencode serve, which both mean exposing a port over your LAN, Tailscale or a tunnel. Maude installs a pinned OpenCode on your server over SSH and connects through an outbound, end-to-end encrypted relay, so no port is opened. It runs 24/7 with your own model keys or a ChatGPT or Copilot sign-in.
OpenCode is an open-source (MIT) coding agent that works with almost any model provider. It's popular with people who don't want to be tied to one vendor's subscription. It's also built to be driven remotely: opencode serve runs a headless HTTP API, and opencode web adds a browser UI on top. So the question isn't whether you can reach it from a phone, but how you do it safely and keep it running.
Ways to use OpenCode from a phone
| Route | How it reaches the phone | Good for |
|---|---|---|
opencode web in a mobile browser | Bind to 0.0.0.0 (or use --mdns) and open the network address | Quick use on the same Wi-Fi, nothing to install on the phone |
| Community apps such as OpenCode Mobile | Point the app at opencode serve over LAN, Tailscale, a tunnel, a reverse proxy or an SSH port forward | A native client that's free and open source, if you're comfortable with the networking |
| SSH app plus tmux | SSH into the server and attach to the terminal UI | Full control, no extra software, but a terminal UI on a soft keyboard |
| Maude | The server dials out to an end-to-end encrypted relay; no inbound port | A server that runs 24/7 next to your other agents, with approvals and git |
The first two are good options and cost nothing. OpenCode Mobile is a community project that says plainly it isn't affiliated with OpenCode. If you only use OpenCode at home on one network, opencode web may be all you need. Maude is aimed at OpenCode on a remote server that has to keep going while you're away, alongside other agents such as Claude Code and Codex. Our roundup of coding agent phone apps compares the wider field.
Security: don't expose 4096 to the internet
opencode serve listens on 127.0.0.1:4096 by default, and opencode web picks a random local port. That's a safe default. The trouble starts when you widen it to reach a phone. In OpenCode's own words: "If OPENCODE_SERVER_PASSWORD is not set, the server will be unsecured." An open OpenCode API is an open shell on that machine, because the agent can run commands.
If you go the self-wired route:
- Always set
OPENCODE_SERVER_PASSWORD. It turns on HTTP basic auth for bothserveandweb. - Prefer a private network such as Tailscale over a public tunnel, and never bind
0.0.0.0on a VPS with a public IP and no firewall. - If you must use a public tunnel, put authentication in front of it too.
Maude avoids the question. OpenCode stays local to the server, Maude's daemon talks to it over stdio using the Agent Client Protocol, and the daemon reaches your phone by dialling out to Maude's relay. Traffic is end-to-end encrypted with a key per server, so the relay only sees ciphertext. SSH is the fallback. Our tmux, mosh and Tailscale guide covers the do-it-yourself networking in more depth.
Running OpenCode on a VPS 24/7
OpenCode itself is light. Your project's builds and tests decide how much server you need, and our VPS guide for coding agents covers sizing. With Maude the setup is:
- Add the server in the app by address, by pasting an
ssh …command, or by scanning the QR code fromcurl -fsSL https://maude.pilotdev.fr/setup | sh. Any Linux or macOS machine, x86-64 or ARM. - The app deploys its daemon over SSH. The daemon installs OpenCode at a pinned, tested version, checksum-verified against the release, including builds for Alpine (musl) and for older CPUs without AVX2. It keeps OpenCode updated.
- Sign in a provider from the phone (next section) and start a session in a project directory, optionally in its own git worktree.
From then on, sessions run on the server whether or not the app is open. When OpenCode asks for permission to run something, the request shows up as a card in the chat, inline in the inbox, and as a push notification with Allow and Deny. OpenCode's two primary agents map to Maude's mode chip: Build (default, full tools) and Plan (a restricted agent for analysis that asks before any edit or command). /compact works, and each session has Files, Git (diff review, commit, push, pull requests through gh) and a real terminal.
Models and keys
OpenCode's strength is that it isn't tied to one model vendor. In Maude you can sign it in from the phone in any of these ways:
- ChatGPT Plus/Pro, through OpenCode's headless device-code login.
- GitHub Copilot, through GitHub's device flow.
- An Anthropic or OpenRouter API key, pasted into the app and stored by OpenCode on the server.
Providers you've already set up on the server with opencode auth login are detected and used too. OpenCode's own gateways are another option. OpenCode Zen is pay-as-you-go access to models the OpenCode team has tested, and it includes some free models for a limited time. OpenCode Go is a subscription to popular open coding models, $10 a month, with Go Plus at $40 for higher limits. Pick the model per session from the chip above the input. Maude doesn't include any model usage.
For how OpenCode compares with the vendor agents on price and behaviour, see Claude Code vs Codex vs OpenCode. A session can also be handed to another agent while idle. The new agent gets a brief with the plan, files touched, git state and recent conversation, and switching back resumes OpenCode's own session.
OpenCode at home on one network: opencode web with a password is free and enough. A comfortable native client and you're happy to run Tailscale: try a community app. OpenCode on a remote server that runs 24/7, with no port to secure and other agents in the same inbox: that's what Maude is for.
Frequently asked questions
Is there an official OpenCode mobile app?
Can I use opencode web on my phone safely?
OPENCODE_SERVER_PASSWORD so basic auth is on, and don't expose it on a public IP. Without the password OpenCode warns that the server is unsecured, and anyone who reaches it can make the agent run commands.What models can OpenCode use?
Does OpenCode need a subscription?
What changed
- — Page published. OpenCode licence, server defaults, password guidance and Go/Zen pricing checked against opencode.ai docs on this date.