Lesson 1 of 6
Set up OpenCode and protect your credentials
Understand the agent, model and app; choose an existing supported connection or manual practice; verify a local file and keep credentials out of published code.
Name the parts: provider, OpenCode, model, app
The harness is OpenCode: it reads files, proposes edits and runs commands you authorize. The model produces suggestions. The provider supplies access to the model. The app is the Task Tracker you will publish; that app never needs an AI key.
Free lessons do not include AI credits. Use an eligible LintLabs key if you already have one, or another supported provider connection you already have. Check its current terms and usage costs first: a chatbot subscription does not necessarily include API access. Do not buy anything just to read or check this lesson.
No model available? Use the manual practice below and study the starter code. Label your evidence accurately: manual practice demonstrates file handling and independent verification, not a successful AI agent run. Later agent-driven exercises require a working provider connection.
Install OpenCode and print a version
Pick one official install path, then confirm the binary:
curl -fsSL https://opencode.ai/install | bash
# or: npm install -g opencode-ai
# macOS/Linux current releases: brew install anomalyco/tap/opencode
opencode --version
On Windows, OpenCode's docs recommend WSL. If opencode is missing after npm, check that the global bin directory is on PATH.
OpenCode is not a browser chatbot. You start it inside the folder it should edit. For this lesson that is a scratch folder, not the Task Tracker yet. Copy the version line into your notes; Lessons 2–6 use this same binary.
Choose your connection without exposing a secret
Use /connect in OpenCode and consult the current provider instructions for supported authentication.
Existing LintLabs access: open AI tokens. If eligible, copy the key and select OpenRouter in OpenCode. No custom API URL is needed. Free lesson access does not unlock a key or grant credits. If it is locked, use another existing supported connection or manual practice.
Another provider: use its supported login or API-key flow. Check current costs and spending limits before a request. Do not assume that a listed model is free.
Never paste a credential into notes, prompts, screenshots, Git or this evidence form. Enter it only in the tool’s authentication flow. Revoke or rotate a leaked key at the account that issued it.
Choose an available model and check the connection
Start OpenCode in a new practice folder. Use /connect, then /models to select a model available to your account. Names, access and pricing change; consult the current provider information instead of guessing a model ID.
For an eligible LintLabs key, select built-in OpenRouter. Run opencode auth list to inspect configured provider names. This proves configuration only: a successful response is the connection check.
Keep credentials in the agent tool’s authentication store, outside the project. Never share that store or put a key in app code, VITE_* or PUBLIC_* variables. Those public prefixes can expose values to visitors.
Verify one small change, or practice it manually
Create a new scratch folder using your file manager. Open a terminal there and start OpenCode. Ask: Create hello.txt containing one line: ready. Do not modify anything else. Tell me what changed. Inspect the proposed action. After it runs, open the file in a text editor and verify its contents independently. “Done” in a chat is not proof.
No-model practice: create hello.txt yourself, save it, close it and reopen it to check the line ready. Write “manual practice; no model request made.” Return to the agent check when you have a working connection.
Record the path you used and what you actually observed. Do not include credentials. An API key must never appear in published JavaScript, browser storage, a URL, screenshots, VITE_*, PUBLIC_*, or lesson evidence. Anyone with a bearer key may be able to spend its account’s credits.