OpenCode memory without a commit or a public link
Move from the laptop to the desktop halfway through a task, and what was settled reaches the desktop in one of two ways: an AGENTS.md committed to Git, or the conversation shared by link. OpenCode’s docs say what the second one costs: "Shared conversations are publicly accessible to anyone with the link." The first is good at what it is for: /init writes an AGENTS.md for the repository, and once it is committed it travels with the code. Past those two, OpenCode itself carries nothing of a session to another machine. It keeps its session data on disk, under ~/.local/share/opencode/ on macOS and Linux, and opencode-supermemory, which its Ecosystem page lists, is a third-party plugin, not part of OpenCode.
OpenCode has no memory tool, and a project’s AGENTS.md serves that one repository and reaches another machine only through a commit. Connect it to Pando and have it keep decisions in your outline, where its next session can read them in any project and on any machine, with no commit and no public link.
Set it up
- Add {"mcp": {"pando": {"type": "remote", "url": "https://pando.ink/mcp"}}} to ~/.config/opencode/opencode.json, OpenCode’s global config.
- OpenCode asks you to sign in the first time it uses pando; to start the sign-in yourself, run opencode mcp auth pando. Approve the sign-in in Pando.
OpenCode handles the OAuth steps itself. Pando answers its first request with a 401 that says where to sign in, OpenCode registers itself by dynamic client registration, which Pando offers, and its callback on 127.0.0.1 is one Pando accepts. It keeps the token in ~/.local/share/opencode/mcp-auth.json. If the sign-in does not finish, connect with a key instead, as further down.
On Windows
OpenCode’s issue #44700, "MCP remote server OAuth fails at token exchange on Windows", was reported on version 1.18.21. Its maintainer’s answer is that the code in question "no longer exists on V2", and V2 has not been released, so the fix is not in the version you install today. On Windows, then, the sign-in may fail at the token exchange, its last step. Connect with a key instead: "oauth": false turns OpenCode’s automatic sign-in off for that server, and the key goes in a header.
What you approve in Pando
The sign-in takes you to Pando, where you log in first if you are not already, and then to its consent page, which offers two levels, “Read and write your outline” or “Read your outline only”. Either way OpenCode starts with your whole outline. A box underneath, ticked by default, gives it a bullet under Home to remember in, and says what that bullet will be called. Untick it and it remembers nowhere until you assign a bullet under Agents and API keys. The token it gets has no expiry and works until you revoke it there. A bullet you protect refuses every change it tries, and a lock stops changes, not reading.
Later, one press holds it to one branch: open that branch, open Agents and API keys in Settings, tap its row under Your agents, and press Let it reach only “…”, the bullet you are in, where the quotes hold that branch’s words. It then reads and writes that branch and everything under it, remembers there, and reaches nothing else in your outline, even if you approved it read only.
With a key instead
On Windows, or to start OpenCode on one branch instead of the whole outline:
- Open Agents and API keys in Settings, give a new agent a handle, untick both “Let it read and write this outline” and “Give it a bullet of its own to remember in”, and choose Create the agent. Copy its key, which begins with pf_ and is shown once.
- Zoom into the branch it may work in, open Agents and API keys again, tap the agent’s row under Your agents, and choose Remember in “…”, the bullet you are in. It then reaches that branch and everything under it, and nothing else.
- Put the key in an environment variable called PANDO_KEY, give opencode.json the entry below instead of the one under Set it up, and do not run opencode mcp auth pando. If Agents and API keys lists a connector OpenCode made, whether its sign-in finished or seemed to fail, revoke its key there, under Keys, because that connector reaches your whole outline.
{
"mcp": {
"pando": {
"type": "remote",
"url": "https://pando.ink/mcp",
"oauth": false,
"headers": { "Authorization": "Bearer {env:PANDO_KEY}" }
}
}
}
Telling it to look
Pando sends instructions when a client connects, among them "Recall BEFORE you assume. Keep decisions and their reasons, not transcripts." OpenCode has put MCP server instructions into its session context since version 1.17.10. In a repository only you work in, you can also add one line to its AGENTS.md: recall from Pando before assuming, and keep decisions and their reasons there. In a shared repository, leave AGENTS.md to the team: OpenCode’s docs say to commit it to Git, which makes it everyone’s file, and a teammate’s agent may have no Pando to recall from.
What each place is for
- AGENTS.md, for the rules of one project that the whole team follows. OpenCode’s docs: "You should commit your project's AGENTS.md file to Git."
- A shared conversation, to show one session to somebody, and only one you are content to make public.
- A branch of your outline, for decisions and their reasons that are yours rather than the repository’s, and have to reach another project, another machine, an agent working outside this repository, or you on your phone.
When AGENTS.md is enough
If what OpenCode should know belongs to one repository, a committed AGENTS.md is enough, and you should use it: it travels with the code, and every agent that reads AGENTS.md reads it too. Rules the repository’s team follows belong there either way, not in your outline. The outline earns its place when a decision is yours rather than the team’s, or has to reach a second project, an agent working outside this repository, or you on your phone. Claude Code, Codex and Cursor connect to the same address, so what OpenCode kept while you worked in one repository is there for Claude Code in the next.
What it costs
Nothing, for 1,000 bullets, with every feature included and no payment card. OpenCode’s FAQ calls OpenCode "100% free to use" and says it comes with free models; a model provider you connect beyond those may charge you.
Deeper
Connect an agent, about two minutes · The twelve tools · Which note apps an agent can reach · Who runs this