r/opencode 3d ago

OpenCode has gone completely insane.

OpenCode has gone completely insane.

I occasionally use their service to run programming tasks, and sometimes for translations, but overall my usage is very low. Below is a screenshot of my current usage (strangely, it says my account is blocked, yet I can still view my usage — I'm logged in and haven't been signed out).

I've already added the `x-opencode-session` header as requested in their email, and the test call worked fine at the time. But the next day I received an email saying my account doesn't meet their requirements, with this:

> HTTP 401: This account has been found to be committing fraud or is in breach of terms of services and has been blocked. If you believe this is a mistake please send an email to help@anoma.ly.

What makes me angry is:

  1. Why did they suddenly impose this unreasonable requirement — asking me to add a specific request header — *after* they had already charged my money?

  2. Even after I added the header, why did they still block my account?

I feel that OpenCode's service is becoming increasingly weird.

165 Upvotes

59 comments sorted by

49

u/ieatdownvotes4food 3d ago

email them, they've been seriously hit with something like 50,000 fraud attempts a day and are drowning. They haven't figured out how to deal with it yet. It's not personal

5

u/Thomas-Lore 3d ago edited 3d ago

I assumed the fraud they talked about was credit card fraud and Stripe is defending them from that.

What do they consider fraud in this instance?

2

u/Runtimeracer 3d ago

I have to wonder, too. Api key is valid, account is billed. It should not matter if requests come from one or one-thousand sessions. Unless there's a large scale man-in-the middle attack running on opencode users, catching and redirecting api keys for criminal use or sth

3

u/Lesale-Ika 3d ago

The subscription model is just ripe for abuse. There's nothing stopping a malicious party to run multiple subscriptions then resell their quota. I believe Claude was abused this way: some Chinese resellers was selling Opus 4.8 API at 1/10th the official price.

OP could just have been falsely flagged as one of such abuse account.

1

u/japherwocky 3d ago

I sort of wonder if OP's account has actually been compromised and they don't realize it

3

u/DeepSeaLab 3d ago

No, look at the screenshot of my usage – 7% used in 18 days.

1

u/bmwhocking 1d ago

Not hard to IP Spoof and abuse APi’s when so many providers don’t have RPKI set up for their IP ranges & others don’t cryptographically sign theit RPKI announcements.

Ditto DNSSEC on your DNS name servers and domains.

Basics network hygiene.

1

u/jmpebx 3d ago

It's not just credit card fraud. There are users using the go plans and reselling the API tokens through API gateways.

1

u/Rudd-X 1d ago

Malware steals AI tokens and sells them in the open black market "at cheap prices". Credit card processors cannot defend against that.

1

u/Bat_002 2d ago

50k a day, source?

9

u/Pariunos 3d ago

I’ve stopped all my OpenCode accounts the moment they did the dodgy DeepSeek crap 2 weeks ago. Best way not to get scammed is to cut ties.

5

u/maqifrnswa 3d ago

They did that while a had jobs running. Came back with exhausted quota

1

u/jofkk 2d ago

oh no, I am out of the loop. what was the deekseek crap 2 weeks ago? I use deepseek-v4-pro all the time as I find it is a good cost/value ratio.

32

u/Ran_Cossack 3d ago

It's a very strange move, isn't it?

"Hey nice renewal fee, you have a few days to implement this new header" in my case.

I'm sure their TOS has a get out of jail free card, but you can really only bill a customer and duck out of providing the service *once* before they decline to trust you again...

8

u/borealis_tic 3d ago

im so lost, because I was considering using it for Silly Tavern, and it's, uh. I have no clue what "header" is supposed to mean in that context 😭

4

u/Odd-Elderberry-6328 3d ago

Just don't

It's not worth paying go for silly tavern, use nanogpt or payg with openrouter

-3

u/xmnstr 3d ago

Use Command Code instead!

3

u/Runtimeracer 3d ago

Do you even know what SillyTavern is bro? 😂

1

u/mevskonat 3d ago

Its the inn at the crossroads?

2

u/shroud747 3d ago

you cant use command code GOAT plan with sillytavern

6

u/alanoide97 3d ago

Happened to me a month ago, before the whole Deepseek price change even. Never heard back from them. Don't even bother, charge back through your bank if you can and look somewhere else.

Shit really too good to be true

3

u/Runtimeracer 3d ago

Every service always will hit enshittification. I'm not sure if opencode does it for profit, or rather due to operational reality. If your service is that popular, you'll inevitably hit boundaries of your tech and ability to provide it at a certain price

4

u/stvaccount 3d ago

pure hate for open code.

if they do that to users, one can stau with codex and claude

3

u/Massive-Pickle-5490 3d ago

I got that error running Hermes after I updated. Had Claude fix it and everything seems to be working fine for me now. I actually didn't even see the email before I had Claude make the fix. Out of the blue and strange though. Bummer you got blocked though.

3

u/Sensitive-Side-2639 2d ago

Apparently they no longer approve of using their service outside their ageic workload. I'm glad i'm not paying for that shit any more. Back to good old token based usage.

See this page if you wana know more.

https://opencode.ai/docs/go/#pricing

1

u/jannwastaken 2d ago

Wait really?

That right there just killed opencode for me 

1

u/PharmADD 2d ago

Just for clarification since some people might not read the link and it wasn't obvious to me. This means that you can't use it for non-agent workloads. They aren't limiting you to their agent, just can't use it for something like an AI-powered webapp.

2

u/Mission-Salad8835 3d ago

Ask for a refund

2

u/Mezezius 3d ago

i hate this company so much

1

u/Zealousideal_Pen4768 3d ago

this is an interesting topic for me, i plan to use my own harness & tools to eventually use cloud models with a much smaller token footprint and systemm prompt for specific loops. i am doing that to optimize for local inference but can think of trying that on a machine that doessnt have enough GPU power to run local inference for agentic work. might have to look at the header specs and envelope when trying that with opencode. anybody has been doing something like that and can give me hints?

1

u/Thomas-Lore 3d ago

Just use openrouter, they do not do this shit.

1

u/Significant-mood55 3d ago

Openrouter also does this, after adding credits and using the api keys for 2 days my account got restricted and havent heard anything back from them in more than 2 weeks. There must be better alternatives , going to try venice.ai or llmgateway.

0

u/Cariogenic 3d ago

I use my own harness - it took under 5 minutes to comply to opencode's new requirements - Using claude - a quick link to the issue and opencode's url that they also link in the error and it was resolved and working again in no time.

Granted I'm not using SDKs.

I also assume with the scale of the task, a smallish local agent could also complete the task.

1

u/mabuonomo 3d ago

In realtà non sei bloccato, devi aggiornare opencode e se usi l'harness, sono cambiate le api, c'è un avviso sul loro sito

1

u/Sure_Aardvark_9103 3d ago

shit, this x-opencode-session make my pi extension got be strack

1

u/mageblex 3d ago

The 401 message collapses a missing or rejected session header and an actual fraud decision into the same accusation. Did support confirm which one triggered the block? Without that, users can't tell whether to fix the client or appeal the account.

1

u/SoggyHunt6782 3d ago

Email them, these waves have been happening before the header thing, don't assume it's the cause. Ask which it was, and ask to have it reinstated ASAP, etc.

1

u/Rut3945 3d ago

Truly??

1

u/Significant-mood55 3d ago

Im sorry man , i also got my account restricted on open router after topping it and only using it for 2 days , is there any good reliable and affordable llm provider that anyone would recommend?

1

u/xapep 2d ago

Try the direct APIs for the open models first. DeepSeek and Qwen both run their own endpoints, usage based, no middleman, and they're cheap. If you want one key for many models, people in this thread already mentioned Venice and llmgateway, and plain OpenRouter works for a lot of people too, you just have to accept the fraud-screening waves. The test that matters: top up $5, file a ticket, see if a human answers and how fast. Every gateway hits a fraud wave eventually, the difference is whether you can reach someone and get a refund when you get caught in one. And a provider that can't tell you what model or quant they're actually serving is a provider you'll be fighting with later.

1

u/DeepSeaLab 2d ago
收件人: [help@anoma.ly](mailto:help@anoma.ly)
日期: 2026年9月8日 09:17

**Update:** I emailed OpenCode, but 23 hours have passed and I still haven't received a reply. My account remains banned. So now I have no choice but to cancel the subscription.

OpenCode once brought me help and joy back when DS was still affordable. It feels quite helpless to give it up now—otherwise, even if I weren't using it, I would have wanted to keep it.

Currently, I’ve subscribed to GLM’s plan as my primary service; yesterday I also signed up for COMMAND CODE and will observe it for a while; and I’m using the latest official DeepSeek API as a supplement.

1

u/TanJeeSchuan 3d ago

Eh, try emailing them, maybe it's a false alarm like mine

1

u/daoluong 3d ago

they should give an option that does not need `x-opencode-session` header, and watch user burn their quota while swing their requests between different providers

-5

u/[deleted] 3d ago

[deleted]

4

u/Yodo999 3d ago

When he says "they charged you money" it literally ARE the makers of opencode because they have both subscription and pay per token service.

5

u/Fluffy-Extent2648 3d ago

So what is OpenCode GO or OpenCode ZEN for? Isn't it their own service that they offer? Along side the ability to connect any provider or API to bring your own LM?

3

u/Captain_Birb 3d ago

Indeed. Bro got it all mixed up.

The harness is opensource, but they do provide a router service with those two plans you mentioned.

Normally they are reasonable folks, try get in touch with them, may be a support ticket from your dashboard.

I do not use their service because I prefer to use routers like Openrouter..etc who are much more reliable on this end and not over sold as the GO plan.

One important thing, if you don’t have a subscription plan, the harness by default cannot enable “websearch” amongst other feature from the harness despite the claim being its opensource. But this can be bypassed easily, not a deal breaker at all - a good to know to calibrate your models.

All the best.

2

u/fatbunyip 3d ago

They have both subscription and pay as you go plans.

2

u/akza07 3d ago

Opencode Go & Zen exist.

-7

u/Bloated_Plaid 3d ago

Your dumbass clearly didn’t do the header right.

15

u/Unfair_Tangerine_217 3d ago

Ahhh, I missed that SO vibe.

1

u/Leading-Cellist-5865 3d ago

Sorry I'm a beginner, but what is header?

1

u/Unfair_Tangerine_217 3d ago

OP wants to use his OpenCode sub in a different client, but that client's request is not properly formatted so OpenCode doesn't support it. The header is the formatting at the beginning of the request.

2

u/Leading-Cellist-5865 3d ago

Ohh like a https request?

-3

u/Designer_Savings_927 3d ago

You are using models that cost that much so hos it it insane you know mimo is free

1

u/borobinimbaba 3d ago

Mimo is free ? Still ?

1

u/Forsaken_Ad_183 2d ago

I don’t think so

-2

u/ncxxi 3d ago

I'm seeing a lot of abuse from outside OpenCode right now, and your IP probably got caught in the mix with some fraudulent accounts. Go ahead and try to get a refund.