← Pando

OpenCode memory without a commit or a public link

OpenCode and Pando, for memory across projects and machines.

Move from the laptop to the desktop halfway through a task, and what was settled reaches the desktop in one of two ways: an AGENTS.md committed to Git, or the conversation shared by link. OpenCode’s docs say what the second one costs: "Shared conversations are publicly accessible to anyone with the link." The first is good at what it is for: /init writes an AGENTS.md for the repository, and once it is committed it travels with the code. Past those two, OpenCode itself carries nothing of a session to another machine. It keeps its session data on disk, under ~/.local/share/opencode/ on macOS and Linux, and opencode-supermemory, which its Ecosystem page lists, is a third-party plugin, not part of OpenCode.

OpenCode has no memory tool, and a project’s AGENTS.md serves that one repository and reaches another machine only through a commit. Connect it to Pando and have it keep decisions in your outline, where its next session can read them in any project and on any machine, with no commit and no public link.

Set it up

  1. Add {"mcp": {"pando": {"type": "remote", "url": "https://pando.ink/mcp"}}} to ~/.config/opencode/opencode.json, OpenCode’s global config.
  2. OpenCode asks you to sign in the first time it uses pando; to start the sign-in yourself, run opencode mcp auth pando. Approve the sign-in in Pando.

OpenCode handles the OAuth steps itself. Pando answers its first request with a 401 that says where to sign in, OpenCode registers itself by dynamic client registration, which Pando offers, and its callback on 127.0.0.1 is one Pando accepts. It keeps the token in ~/.local/share/opencode/mcp-auth.json. If the sign-in does not finish, connect with a key instead, as further down.

On Windows

OpenCode’s issue #44700, "MCP remote server OAuth fails at token exchange on Windows", was reported on version 1.18.21. Its maintainer’s answer is that the code in question "no longer exists on V2", and V2 has not been released, so the fix is not in the version you install today. On Windows, then, the sign-in may fail at the token exchange, its last step. Connect with a key instead: "oauth": false turns OpenCode’s automatic sign-in off for that server, and the key goes in a header.

What you approve in Pando

The sign-in takes you to Pando, where you log in first if you are not already, and then to its consent page, which offers two levels, “Read and write your outline” or “Read your outline only”. Either way OpenCode starts with your whole outline. A box underneath, ticked by default, gives it a bullet under Home to remember in, and says what that bullet will be called. Untick it and it remembers nowhere until you assign a bullet under Agents and API keys. The token it gets has no expiry and works until you revoke it there. A bullet you protect refuses every change it tries, and a lock stops changes, not reading.

Later, one press holds it to one branch: open that branch, open Agents and API keys in Settings, tap its row under Your agents, and press Let it reach only “…”, the bullet you are in, where the quotes hold that branch’s words. It then reads and writes that branch and everything under it, remembers there, and reaches nothing else in your outline, even if you approved it read only.

With a key instead

On Windows, or to start OpenCode on one branch instead of the whole outline:

{
  "mcp": {
    "pando": {
      "type": "remote",
      "url": "https://pando.ink/mcp",
      "oauth": false,
      "headers": { "Authorization": "Bearer {env:PANDO_KEY}" }
    }
  }
}

Telling it to look

Pando sends instructions when a client connects, among them "Recall BEFORE you assume. Keep decisions and their reasons, not transcripts." OpenCode has put MCP server instructions into its session context since version 1.17.10. In a repository only you work in, you can also add one line to its AGENTS.md: recall from Pando before assuming, and keep decisions and their reasons there. In a shared repository, leave AGENTS.md to the team: OpenCode’s docs say to commit it to Git, which makes it everyone’s file, and a teammate’s agent may have no Pando to recall from.

What each place is for

When AGENTS.md is enough

If what OpenCode should know belongs to one repository, a committed AGENTS.md is enough, and you should use it: it travels with the code, and every agent that reads AGENTS.md reads it too. Rules the repository’s team follows belong there either way, not in your outline. The outline earns its place when a decision is yours rather than the team’s, or has to reach a second project, an agent working outside this repository, or you on your phone. Claude Code, Codex and Cursor connect to the same address, so what OpenCode kept while you worked in one repository is there for Claude Code in the next.

What it costs

Nothing, for 1,000 bullets, with every feature included and no payment card. OpenCode’s FAQ calls OpenCode "100% free to use" and says it comes with free models; a model provider you connect beyond those may charge you.

Deeper

Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this