Repository navigation
v0.1.0
First release of opencode-keycloak-auth — an OpenCode auth plugin that logs in to Keycloak via OAuth2/OIDC and feeds short-lived, auto-refreshed access tokens to an OpenAI-compatible AgentGateway provider.
Features
- Authorization Code + PKCE (S256) with localhost auto-capture and a paste-the-code fallback
- Device Authorization Grant fallback, auto-selected on headless / SSH / container hosts
- Automatic token refresh near expiry (<30s), persisted via OpenCode's native store
- Public client, no secret stored; zero runtime dependencies (offline / air-gap friendly)
Install (offline / vendored)
Download opencode-keycloak-auth-0.1.0.tgz from the assets below, then:
```bash
npm install ./opencode-keycloak-auth-0.1.0.tgz
```
See the README for the Keycloak client setup and the `opencode.json` provider snippet.
Assets
- `opencode-keycloak-auth-0.1.0.tgz` — prebuilt npm package (ESM `dist/` + type declarations)